Yes that is why I think you need to redirect users with “user” role to some route they are allowed to access. If it is an API, redirect to some allowed route that serves the appropriate data that the API client know what to do with. The halt plug will assure that the request won’t go anywhere further through the restricted route pipeline after the redirection.
To sum up, they accessed the route but they are immediately redirected before getting any restricted data. In the other hand, Users with “admin” role won’t be redirected and will access the restricted data.


















