* Add check_authorization for before update and eventually destroy runs * Update permitted parameters