August 2025
Intermediate to advanced
294 pages
6h 59m
English
At the moment, the Artist resource in Tunez is secure—actions that modify data can only be called if a) we pass in a user record as the actor and b) that actor is authorized to run that action. The web UI doesn’t reflect these changes, though. Even when not logged in to the app, we can still see buttons and forms inviting us to create, edit, or delete data.

We can’t actually run the actions, so clicking the buttons and submitting the forms will return an error, but it’s not a good user experience to see them at all. And even if we are logged in and should have access to manage data, we still get an error! ...
Read now
Unlock full access