jlrdw1 year agoLevel 75ReplyReport SpamDo it the other way: If the method requires say role2, check if that's one of the logged in users roles. If so they CAN do it. However with an API you should be looking at token abilities. Also you refer to roles, would a regular web app be better suited for you needs here? Like Reply 1 like
MezoZK OP 1 year agoLevel 1ReplyReport Spam@jlrdw It's a role based mobile app. I think I'll go with token abilities. Thank you very much. Like Reply 1 like