Permissions
Access follows EmDash’s plugin permissions. In a default EmDash install, Admins have
plugins:manage and Editors have plugins:read.
What each role can do
Section titled “What each role can do”| Action | Admin (plugins:manage) |
Editor (plugins:read) |
|---|---|---|
| Open Header & Footer Code in admin | ✅ | ✅ |
| See the snippet list (name, placement, priority, on/off, targeting) | ✅ | ✅ |
| See snippet code | ✅ | ❌ |
| Create, edit, duplicate, delete | ✅ | ❌ |
| Turn a snippet on or off | ✅ | ❌ |
| Use the kill switch | ✅ | ❌ |
| View the change log | ✅ | ❌ |
For Editors, the create, edit, toggle, duplicate, delete and kill-switch controls are hidden, and the change log tab isn’t shown.
How it’s enforced
Section titled “How it’s enforced”The UI isn’t the only check. Each plugin API route declares the permission it needs, and EmDash enforces it on the server:
| Route | Permission |
|---|---|
snippets/list |
plugins:read |
snippets/get, snippets/save, snippets/toggle, snippets/duplicate, snippets/delete |
plugins:manage |
killswitch/set, changelog/list |
plugins:manage |
- A write request from an Editor is rejected with HTTP 403.
- For callers without
plugins:manage,snippets/listleaves code out of the response. It isn’t just hidden in the browser.
The end-to-end tests cover both.
© 2026 Jithin Sebastian ·MIT License ·GitHub