Context functions accepting either ID or struct

Exactly my way of thinking. But I have a feeling that doing authorization in the web layer (as a plug) is a common practice. Personally I prefer my contexts returning :unauthorized and handle that with an action fallback. This makes controllers super thin to the point where testing them becomes questionable.