Files
Guarzo 94157c880e review: scope the JSON:API policy criterion and tighten access_list
Document that `json_api do` -- not `routes do` -- is the criterion that makes
a resource API-reachable, and list which resources that covers. Mark
AccessList.map_access_lists as `public? false`, and drop the stale
'Session Authentication' paragraph from the API modernization post.
2026-08-08 17:05:42 -04:00
..