{"result":{"depiction_url":null,"edges":{"in_module":{"objects":[{"created":"2026-09-09T13:48:11Z","object_id":{"id":335,"is_a":["text","documentation","reference","module"],"name":"doc_core","title":"Zotonic Core","uri":"https:\/\/zotonic.com\/id\/335"},"seq":1}],"predicate":{"id":333,"is_a":["meta","predicate"],"name":"in_module","title":{"_type":"trans","tr":{"en":"In module"}},"uri":"https:\/\/zotonic.com\/id\/in_module"}},"subject":{"objects":[{"created":"2026-09-09T13:48:11Z","object_id":{"id":2555,"is_a":["categorization","keyword","keyword_information_type"],"name":"zotonic_topic_reference","title":"Reference","uri":"https:\/\/zotonic.com\/id\/2555"},"seq":1},{"created":"2026-09-09T13:48:11Z","object_id":{"id":2564,"is_a":["categorization","keyword","keyword_audience"],"name":"zotonic_topic_backend_developer","title":"Backend developer","uri":"https:\/\/zotonic.com\/id\/2564"},"seq":2},{"created":"2026-09-09T13:48:11Z","object_id":{"id":2592,"is_a":["categorization","keyword","keyword_domain"],"name":"zotonic_topic_authorization_and_access_control","title":"Authorization and access control","uri":"https:\/\/zotonic.com\/id\/2592"},"seq":3},{"created":"2026-09-09T13:48:11Z","object_id":{"id":2625,"is_a":["categorization","keyword","keyword_architecture"],"name":"zotonic_topic_model","title":"Model","uri":"https:\/\/zotonic.com\/id\/2625"},"seq":4},{"created":"2026-09-09T13:48:11Z","object_id":{"id":2653,"is_a":["categorization","keyword","keyword_task"],"name":"zotonic_topic_authorize","title":"Authorize","uri":"https:\/\/zotonic.com\/id\/2653"},"seq":5}],"predicate":{"id":308,"is_a":["meta","predicate"],"name":"subject","title":{"_type":"trans","tr":{"en":"Keyword"}},"uri":"http:\/\/purl.org\/dc\/elements\/1.1\/subject"}}},"id":1797,"is_a":["text","documentation","reference","model"],"links":[{"rel":"self","target":"https:\/\/zotonic.com\/.zotonic\/websub\/topic\/1797"},{"rel":"hub","target":"https:\/\/zotonic.com\/.zotonic\/websub"}],"medium":null,"medium_url":null,"name":"doc_model_model_acl","page_url":{"en":"https:\/\/zotonic.com\/docs\/1797\/acl","x-default":"https:\/\/zotonic.com\/docs\/1797\/acl"},"preview_url":null,"resource":{"version":3998,"pivot_location_lat":null,"title":"acl","is_authoritative":true,"body":"<p>The m_acl model gives access the id of the currently logged in user, and provides a mechanism to do basic access\ncontrol checks.<\/p>\n<p>The following m_acl model properties are available in templates:<\/p>\n<table class=\"table\"><thead><tr><th>Property<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>user<\/td><td>Returns the current user id. If not logged in, this returns <code>undefined<\/code>.<\/td><\/tr><tr><td>is_admin<\/td><td>Check if the current user is alllowed to access the admin. Internally, this checks the <code>use, mod_admin_config<\/code> ACL.<\/td><\/tr><tr><td>use, admin, view, delete, update, insert, link<\/td><td>These properties are shortcuts to check if the current user is allowed to do some action.<\/td><\/tr><tr><td>is_allowed<\/td><td>Perform custom ACL checks which are different from the ones mentioned.<\/td><\/tr><tr><td>authenticated<\/td><td>Used before the other ACL checks to check if a <em>typical<\/em> user is allowed to perform some actions. Example: <code>m.acl.authenticated.insert.article<\/code> If a user is logged on the that user&#39;s permissions are used.<\/td><\/tr><tr><td>auth_service<\/td><td>Service used to authenticate the user.<\/td><\/tr><tr><td>auth_service_uid<\/td><td>Service user identification used to authenticate the user.<\/td><\/tr><\/tbody><\/table>\n<p>This example prints a greeting to the currently logged in user, if logged in:<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-django\">{% if m.acl.user %}\n    Hello, {{ m.rsc[m.acl.user].title }}!\n{% else %}\n    Not logged in yet\n{% endif %}\n<\/code><\/pre>\n<p>This example checks if the user can access the admin pages:<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-django\">{% if m.acl.is_admin %} You are an admin {% endif %}\n<\/code><\/pre>\n<p>This example performs a custom check:<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-django\">{% if m.acl.is_allowed.use.mod_admin_config %}\n    User has rights to edit the admin config\n{% endif %}\n<\/code><\/pre>\n<p>And to check if a resource is editable:<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-django\">{% if m.acl.is_allowed.update[id] %}\n   User can edit the resource with id {{ id }}\n{% endif %}\n<\/code><\/pre>\n<p>A short hand for the above is (assuming id is an integer):<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-django\">{% if id.is_editable %}\n   User can edit the resource with id {{ id }}\n{% endif %}\n<\/code><\/pre>\n<h2>Available Model API Paths<\/h2>\n<table class=\"table\"><thead><tr><th>Method<\/th><th>Path pattern<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><code>get<\/code><\/td><td><code>\/user\/...<\/code><\/td><td>Return the current ACL user id from the request context.<\/td><\/tr><tr><td><code>get<\/code><\/td><td>`\/auth_service<\/td><td>Service used to authenticate the user.<\/td><\/tr><tr><td><code>get<\/code><\/td><td>`\/auth_service_uid<\/td><td>Service user identification used to authenticate the user.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/sudo_user\/...<\/code><\/td><td>Return the current sudo user id from the request context.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/is_admin\/...<\/code><\/td><td>Return whether the current user has admin rights.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/is_admin_editable\/...<\/code><\/td><td>Return whether admin users are editable in the current ACL setup.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/is_read_only\/...<\/code><\/td><td>Return whether the current ACL mode is read-only.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/is_allowed\/link\/+subject\/+predicate\/+object\/...<\/code><\/td><td>Check ACL permission for creating\/using a link triple (<code>+subject<\/code>, <code>+predicate<\/code>, <code>+object<\/code>).<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/is_allowed\/+action\/+object\/...<\/code><\/td><td>Check ACL permission for action <code>+action<\/code> on object <code>+object<\/code>.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/authenticated\/+action\/+object\/...<\/code><\/td><td>Check permission as an authenticated user under default ACL assumptions.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/authenticated\/is_allowed\/+action\/+object\/...<\/code><\/td><td>Alias of the authenticated permission check for action <code>+action<\/code> on <code>+object<\/code>.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/anonymous\/+action\/+object\/...<\/code><\/td><td>Check permission as an anonymous user under default ACL assumptions.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/anonymous\/is_allowed\/+action\/+object\/...<\/code><\/td><td>Alias of the anonymous permission check for action <code>+action<\/code> on <code>+object<\/code>.<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/link\/+subject\/+predicate\/+object\/...<\/code><\/td><td>Legacy shortcut for link permission check (same as <code>\/is_allowed\/link\/...<\/code>).<\/td><\/tr><tr><td><code>get<\/code><\/td><td><code>\/+action\/+object\/...<\/code><\/td><td>Shorthand permission check for action <code>+action<\/code> on <code>+object<\/code> (same logic as <code>\/is_allowed\/...<\/code>).<\/td><\/tr><\/tbody><\/table>\n<p><code>\/+name<\/code> marks a variable path segment. A trailing <code>\/...<\/code> means extra path segments are accepted for further lookups.<\/p>","slug":"acl","is_protected":false,"visible_for":0,"tz":"UTC","language":["en"],"doc_source_hash":"fd9aaa36d0b1f86acf3df677b1a396b774c00b96c997518b4672ff96e0638a12","is_featured":false,"content_group_id":{"id":2551,"is_a":["meta","content_group"],"name":"content_group_imported_docs","title":"Imported documentation","uri":"https:\/\/zotonic.com\/id\/content_group_imported_docs"},"category_id":{"id":322,"is_a":["meta","category"],"name":"model","title":"Models","uri":"https:\/\/test.zotonic.com\/id\/322"},"doc_source_path":"apps\/zotonic_core\/src\/models\/m_acl.erl","publication_start":"2023-06-24T08:17:52Z","github_url":"https:\/\/github.com\/zotonic\/zotonic\/blob\/master\/apps\/zotonic_core\/src\/models\/m_acl.erl","pivot_location_lng":null,"doc_source_kind":"model","name":"doc_model_model_acl","is_unfindable":false,"is_published":true,"pivot_geocode":null,"created":"2020-05-30T05:47:36Z","uri":null,"doc_status":"current","is_dependent":false,"erlang_app":"zotonic_core","publication_end":"9999-06-01T00:00:00Z","modifier_id":{"id":1,"is_a":["person"],"name":"administrator","title":"Site Administrator","uri":"https:\/\/zotonic.com\/id\/1"},"privacy":0,"doc_source_commit":"66cb145eae7002b184e7d8c4c7bba5e53e8248e5\n","erlang_module":"m_acl","creator_id":{"id":336,"is_a":["person","robot"],"name":"gitbot","title":"Git","uri":"https:\/\/zotonic.com\/id\/336"},"modified":"2026-10-02T12:40:35Z","title_slug":"acl"},"uri":"https:\/\/zotonic.com\/id\/1797","uri_template":"https:\/\/zotonic.com\/id\/:id","websub":{"hub":"https:\/\/zotonic.com\/.zotonic\/websub","topic":"https:\/\/zotonic.com\/.zotonic\/websub\/topic\/1797"}},"status":"ok"}