Exception: OpenLoam::AuthorizationNotPerformedError

Inherits:
Error
  • Object
show all
Defined in:
lib/open_loam/errors.rb

Overview

Raised when a controller action finishes without having authorized anything (see the verify_authorized! guard in the generated base controllers).

Deliberately NOT a NotAuthorizedError: that one means "this person may not", and the base controllers render it as a tidy 403. This means "this code forgot to ask", which is a developer bug that must not be dressed up as a refusal — nothing rescues it, so it surfaces as a 500 in dev and a failure in tests.