Skip to content

Introduce ActionPolicy authorization adapter - #8708

Open
amkisko wants to merge 10 commits into
activeadmin:masterfrom
amkisko:patch/action-policy-adapter
Open

amkisko wants to merge 10 commits into
activeadmin:masterfrom
amkisko:patch/action-policy-adapter

Conversation

@amkisko

@amkisko amkisko commented May 2, 2025

Copy link
Copy Markdown

This PR introduces a new ActiveAdmin::ActionPolicyAdapter to enable integration with the Action Policy authorization framework. The adapter implements both #authorized? and #scope_collection methods, mapping ActiveAdmin’s internal permissions to Action Policy’s rules and scopes.

ActiveAdmin supports a pluggable authorization system, but out of the box, it only provides adapters for popular frameworks like Pundit and CanCanCan. As more teams adopt Action Policy for its performance, flexibility, and first-class Rails support, it’s increasingly desirable to make ActiveAdmin compatible with it out of the box.

References:

amkisko added 2 commits April 28, 2025 15:45
This commit introduces the ActionPolicy adapter for ActiveAdmin, allowing for flexible authorization management. The ActionPolicy gem is added to the Gemfile, and relevant documentation is updated to guide users on configuring the adapter. Additionally, new policy templates are included to demonstrate usage.

Ref: https://actionpolicy.evilmartians.io
@amkisko

amkisko commented May 2, 2025 •

Copy link
Copy Markdown
Author

@tagliala @javierjulio Hey! Here's better PR for review and discussion.

There is one critical thing to figure out is how to organize test templates as they are intersecting with Pundit. I suggested the option, but really I don't like it at this point, but it should work. Also I could not figure out yet what is missing on my machine for running rspec, tests are not checked.

And sure before merging squashing required (so that you can edit commit message to the preferred format) or I can recreate it again.

@amkisko
amkisko marked this pull request as draft May 2, 2025 09:35

@tagliala tagliala left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hello,

Thanks for this PR.

Also I could not figure out yet what is missing on my machine for running rspec, tests are not checked.

Maybe something related to bundler? I've seen the removal of ruby, so I guess that build native extensions is somehow not working.

Run specs with just CI=1 rake, that will create the test app and proceed with all the specs

First comments:

  1. Rebase from baster
  2. Remove the change in the comment
  3. Please make sure that specs and linters pass locally
313 files inspected, 17 offenses detected, 17 offenses autocorrectable

Comment thread gemfiles/rails_71/Gemfile.lock Outdated

PLATFORMS
arm64-darwin
ruby

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please remove this change

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I saw this one, it was automatically modified by bundler locally.

- Removed platform specification for sqlite3 in multiple Gemfiles.
- Updated action_policy version from 0.7.4 to 0.7.5 in Gemfile.lock across all Rails versions.
- Adjusted Bundler version in Gemfile.lock to 2.7.2.

These changes ensure compatibility and streamline the dependency management.
…anagement

- Added frozen string literal to improve performance.
- Refactored `authorized?` and `scope_collection` methods for better clarity and functionality.
- Improved error handling in `retrieve_policy` to provide more informative messages.
- Updated tests to reflect changes in policy initialization and scoping behavior.
- Added frozen string literal to user policy template for consistency.

These changes enhance the robustness and maintainability of the ActionPolicyAdapter.
- Updated the test for differentiating between `:new` and `:create` abilities to improve clarity.
- Added tests to ensure proper authorization behavior for new post instances.
- Introduced a context to handle cases where the default policy does not exist, ensuring appropriate error handling.

These changes enhance the robustness of the ActionPolicyAdapter tests and improve error management.
@amkisko
amkisko marked this pull request as ready for review December 18, 2025 13:06
amkisko added 4 commits March 4, 2026 14:50
This bug was quite invisible and affected all scopes as normally non-administrator users do not have access to ActiveAdmin and the area assumed to be safe.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants