finds.dev← search

// the find

palkan/action_policy

★ 1,561 · Ruby · MIT · updated Sep 2026

Authorization framework for Ruby/Rails applications

Action Policy is a Pundit-style authorization framework for Ruby and Rails, built around per-resource policy classes with explicit predicate methods. It's aimed at teams outgrowing ad-hoc `if current_user.admin?` checks scattered through controllers and views who want a structured, testable authorization layer.

Caching and memoization are first-class (policy/cache.rb, cached_apply.rb) so repeated authorize! calls on the same object in a request don't re-run rules — something Pundit leaves entirely to you. Pre-checks let you define cross-cutting rules (e.g. 'admins can do anything') once instead of repeating them in every action method. Failure reasons are structured and i18n-backed (policy/reasons.rb), so you can surface a real message like 'you must be the owner' instead of a generic 403. It also works outside Rails and ships RSpec/Minitest matchers and generators, so adoption isn't an all-or-nothing Rails commitment.

The feature surface (namespaces, aliases, custom lookup chains, scoping matchers) is considerably larger than Pundit's, and a team just wanting simple boolean checks will pay a real learning-curve tax for capabilities they may never use. Scope matchers ship only for ActiveRecord and ActionController::Params out of the box — anyone on Sequel, Mongoid, or a non-AR ORM has to write their own matcher before scoping works at all. Six gemfiles spanning Rails 6 through 8 plus JRuby signal a nontrivial compatibility matrix to keep green, and it's effectively a single-maintainer project (palkan/Evil Martians), so bus factor is worth weighing for anything mission-critical.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →