---
title: 'ARC0019: Contradictory authorization'
editUrl: https://github.com/Cratis/Arc.TypeScript/edit/main/Documentation/code-analysis/ARC0019.md
description: Do not grant and restrict access on the same declaration.
---


## What

A class or method has both `@allowAnonymous()` and `@roles()` or `@authorize()`. Rule: `arc-core/arc0019`.

## Why

Arc rejects conflicting authorization. A class-level restriction overridden by a method-level anonymous declaration is a different, supported case.

## Bad

```ts
@allowAnonymous()
@roles('Admin')
export class Register { handle() {} }
```

## Good

```ts
@roles('Admin')
export class Register { handle() {} }
```
