func (UserResource) AllowDelete(res kit.Resource, obj kit.Model, user kit.User) bool { if user == nil { return false } if obj.(kit.UserModel).GetUserId() == user.GetId() { return true } return user.HasRole("admin") || user.HasPermission(res.Collection()+".delete") }
func (hooks UserResourceHooks) AllowUpdate(res kit.Resource, obj kit.Model, old kit.Model, user kit.User) bool { if user == nil { return false } if user.HasRole("admin") || user.HasPermission("users.update") { return true } return obj.GetId() == user.GetId() }
func (AdminResource) AllowDelete(res kit.Resource, obj kit.Model, user kit.User) bool { return user != nil && (user.HasRole("admin") || user.HasPermission(res.Collection()+".delete")) }