Skip to content

Permissions

Access follows EmDash’s plugin permissions. In a default EmDash install, Admins have plugins:manage and Editors have plugins:read.

Action Admin (plugins:manage) Editor (plugins:read)
Open Header & Footer Code in admin ✅ ✅
See the snippet list (name, placement, priority, on/off, targeting) ✅ ✅
See snippet code ✅ ❌
Create, edit, duplicate, delete ✅ ❌
Turn a snippet on or off ✅ ❌
Use the kill switch ✅ ❌
View the change log ✅ ❌

For Editors, the create, edit, toggle, duplicate, delete and kill-switch controls are hidden, and the change log tab isn’t shown.

The UI isn’t the only check. Each plugin API route declares the permission it needs, and EmDash enforces it on the server:

Route Permission
snippets/list plugins:read
snippets/get, snippets/save, snippets/toggle, snippets/duplicate, snippets/delete plugins:manage
killswitch/set, changelog/list plugins:manage
  • A write request from an Editor is rejected with HTTP 403.
  • For callers without plugins:manage, snippets/list leaves code out of the response. It isn’t just hidden in the browser.

The end-to-end tests cover both.