@nestarc/rbac
Classes
InMemoryRbacStorage
Defined in: src/adapters/in-memory-rbac.storage.ts:172
Additive 0.2.x capability for indexed role-id lookups. Implement this on custom adapters before the legacy full-list fallback is removed in 0.3 or later.
Implements
Constructors
Constructor
new InMemoryRbacStorage(): InMemoryRbacStorage;Returns
Properties
mutationResults
readonly mutationResults: RbacStorageMutationCapability;Defined in: src/adapters/in-memory-rbac.storage.ts:178
Additive 0.2.x capability for outcome-aware writes. Custom adapters that omit it use the deprecated result-less best-effort event fallback.
Implementation of
Methods
assignRole()
assignRole(input): Promise<RbacRoleBinding>;Defined in: src/adapters/in-memory-rbac.storage.ts:410
Parameters
| Parameter | Type |
|---|---|
input | AssignRoleStorageInput |
Returns
Promise<RbacRoleBinding>
Implementation of
deleteRole()
deleteRole(input): Promise<void>;Defined in: src/adapters/in-memory-rbac.storage.ts:369
Parameters
| Parameter | Type |
|---|---|
input | DeleteRoleInput |
Returns
Promise<void>
Implementation of
findRole()
findRole(input): Promise<RbacRole | null>;Defined in: src/adapters/in-memory-rbac.storage.ts:264
Parameters
| Parameter | Type |
|---|---|
input | FindRoleInput |
Returns
Promise<RbacRole | null>
Implementation of
findRoleById()
findRoleById(input): Promise<RbacRole | null>;Defined in: src/adapters/in-memory-rbac.storage.ts:274
Optional indexed lookup used by strict assignment validation. Adapters that omit it retain the deprecated 0.2.x listRoles({}) compatibility fallback.
Parameters
| Parameter | Type |
|---|---|
input | FindRoleByIdInput |
Returns
Promise<RbacRole | null>
Implementation of
RbacStorageRoleLookupCapability.findRoleById
grantPermission()
grantPermission(input): Promise<void>;Defined in: src/adapters/in-memory-rbac.storage.ts:381
Parameters
| Parameter | Type |
|---|---|
input | GrantPermissionInput |
Returns
Promise<void>
Implementation of
listBindings()
listBindings(input): Promise<RbacRoleBinding[]>;Defined in: src/adapters/in-memory-rbac.storage.ts:479
Parameters
| Parameter | Type |
|---|---|
input | ListBindingsInput |
Returns
Promise<RbacRoleBinding[]>
Implementation of
listEffectivePermissions()
listEffectivePermissions(input): Promise<RbacEffectivePermission[]>;Defined in: src/adapters/in-memory-rbac.storage.ts:498
Parameters
| Parameter | Type |
|---|---|
input | ListEffectiveRolesInput |
Returns
Promise<RbacEffectivePermission[]>
Implementation of
RbacStorage.listEffectivePermissions
listEffectiveRoles()
listEffectiveRoles(input): Promise<RbacEffectiveRole[]>;Defined in: src/adapters/in-memory-rbac.storage.ts:494
Parameters
| Parameter | Type |
|---|---|
input | ListEffectiveRolesInput |
Returns
Promise<RbacEffectiveRole[]>
Implementation of
RbacStorage.listEffectiveRoles
listRolePermissions()
listRolePermissions(input): Promise<string[]>;Defined in: src/adapters/in-memory-rbac.storage.ts:405
Parameters
| Parameter | Type |
|---|---|
input | ListRolePermissionsInput |
Returns
Promise<string[]>
Implementation of
RbacStorage.listRolePermissions
listRoles()
listRoles(input): Promise<RbacRole[]>;Defined in: src/adapters/in-memory-rbac.storage.ts:281
Parameters
| Parameter | Type |
|---|---|
input | ListRolesInput |
Returns
Promise<RbacRole[]>
Implementation of
revokePermission()
revokePermission(input): Promise<void>;Defined in: src/adapters/in-memory-rbac.storage.ts:394
Parameters
| Parameter | Type |
|---|---|
input | RevokePermissionInput |
Returns
Promise<void>
Implementation of
revokeRole()
revokeRole(input): Promise<void>;Defined in: src/adapters/in-memory-rbac.storage.ts:469
Parameters
| Parameter | Type |
|---|---|
input | RevokeRoleInput |
Returns
Promise<void>
Implementation of
upsertRole()
upsertRole(input): Promise<RbacRole>;Defined in: src/adapters/in-memory-rbac.storage.ts:291
Parameters
| Parameter | Type |
|---|---|
input | UpsertRoleInput |
Returns
Promise<RbacRole>
Implementation of
NoopRbacAuditLogger
Defined in: src/audit/noop-rbac-audit.logger.ts:3
Implements
Constructors
Constructor
new NoopRbacAuditLogger(): NoopRbacAuditLogger;Returns
Methods
log()
log(event): void;Defined in: src/audit/noop-rbac-audit.logger.ts:4
Parameters
| Parameter | Type |
|---|---|
event | RbacAuditEvent |
Returns
void
Implementation of
RbacBindingNotFoundError
Defined in: src/errors/rbac.error.ts:97
Deprecated
No package operation throws this error. It remains constructible and HTTP-mappable until a separate breaking release.
Extends
Constructors
Constructor
new RbacBindingNotFoundError(details?, options?): RbacBindingNotFoundError;Defined in: src/errors/rbac.error.ts:98
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacConfigError
Defined in: src/errors/rbac.error.ts:38
Extends
Constructors
Constructor
new RbacConfigError(details?, options?): RbacConfigError;Defined in: src/errors/rbac.error.ts:39
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacError
Defined in: src/errors/rbac.error.ts:21
Extends
Error
Extended by
RbacConfigErrorRbacSubjectMissingErrorRbacTenantMissingErrorRbacResourceMissingErrorRbacPermissionDeniedErrorRbacRoleNotFoundErrorRbacPermissionNotFoundErrorRbacBindingNotFoundErrorRbacStorageError
Constructors
Constructor
new RbacError(
message,
code,
status?,
options?): RbacError;Defined in: src/errors/rbac.error.ts:22
Parameters
| Parameter | Type |
|---|---|
message | string |
code | RbacErrorCode |
status? | number |
options? | RbacErrorOptions |
Returns
Overrides
Error.constructorProperties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
Error.causecode
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
Error.messagename
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Error.namestack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
Error.stackstackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Error.stackTraceLimitstatus?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
Error.captureStackTraceprepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Error.prepareStackTraceRbacGuard
Defined in: src/rbac.guard.ts:20
Nest HTTP authorization guard. Other transports should call RbacService from their adapter.
Implements
CanActivate
Constructors
Constructor
new RbacGuard(
reflector,
rbac,
options,
moduleRef): RbacGuard;Defined in: src/rbac.guard.ts:25
Parameters
| Parameter | Type |
|---|---|
reflector | Reflector |
rbac | RbacService |
options | RbacModuleOptions |
moduleRef | ModuleRef |
Returns
Methods
canActivate()
canActivate(context): Promise<boolean>;Defined in: src/rbac.guard.ts:41
Parameters
| Parameter | Type | Description |
|---|---|---|
context | ExecutionContext | Current execution context. Provides access to details about the current request pipeline. |
Returns
Promise<boolean>
Value indicating whether or not the current request is allowed to proceed.
Implementation of
CanActivate.canActivateRbacModule
Defined in: src/rbac.module.ts:16
Constructors
Constructor
new RbacModule(): RbacModule;Returns
Methods
forRoot()
static forRoot(options): DynamicModule;Defined in: src/rbac.module.ts:17
Parameters
| Parameter | Type |
|---|---|
options | RbacModuleOptions |
Returns
DynamicModule
forRootAsync()
static forRootAsync(options): DynamicModule;Defined in: src/rbac.module.ts:30
Parameters
| Parameter | Type |
|---|---|
options | RbacModuleAsyncOptions |
Returns
DynamicModule
RbacPermissionDeniedError
Defined in: src/errors/rbac.error.ts:65
Extends
Constructors
Constructor
new RbacPermissionDeniedError(details?, options?): RbacPermissionDeniedError;Defined in: src/errors/rbac.error.ts:66
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacPermissionNotFoundError
Defined in: src/errors/rbac.error.ts:84
Deprecated
No package operation throws this error. It remains constructible and HTTP-mappable until a separate breaking release.
Extends
Constructors
Constructor
new RbacPermissionNotFoundError(details?, options?): RbacPermissionNotFoundError;Defined in: src/errors/rbac.error.ts:85
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacResourceMissingError
Defined in: src/errors/rbac.error.ts:59
Extends
Constructors
Constructor
new RbacResourceMissingError(details?, options?): RbacResourceMissingError;Defined in: src/errors/rbac.error.ts:60
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacRoleNotFoundError
Defined in: src/errors/rbac.error.ts:74
Extends
Constructors
Constructor
new RbacRoleNotFoundError(details?, options?): RbacRoleNotFoundError;Defined in: src/errors/rbac.error.ts:75
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacService
Defined in: src/rbac.service.ts:52
Constructors
Constructor
new RbacService(options): RbacService;Defined in: src/rbac.service.ts:57
Parameters
| Parameter | Type |
|---|---|
options | RbacModuleOptions |
Returns
Methods
assertCan()
assertCan(input): Promise<void>;Defined in: src/rbac.service.ts:98
Parameters
| Parameter | Type |
|---|---|
input | RbacCanInput |
Returns
Promise<void>
assignRole()
assignRole(input): Promise<RbacRoleBinding>;Defined in: src/rbac.service.ts:244
Parameters
| Parameter | Type |
|---|---|
input | AssignRoleInput |
Returns
Promise<RbacRoleBinding>
can()
can(input): Promise<RbacServiceDecision>;Defined in: src/rbac.service.ts:63
Parameters
| Parameter | Type |
|---|---|
input | RbacCanInput |
Returns
Promise<RbacServiceDecision>
createRole()
createRole(input): Promise<RbacRole>;Defined in: src/rbac.service.ts:106
Parameters
| Parameter | Type |
|---|---|
input | CreateRoleInput |
Returns
Promise<RbacRole>
deleteRole()
deleteRole(input): Promise<void>;Defined in: src/rbac.service.ts:171
Parameters
| Parameter | Type |
|---|---|
input | DeleteRoleInput |
Returns
Promise<void>
grantPermission()
grantPermission(input): Promise<void>;Defined in: src/rbac.service.ts:190
Parameters
| Parameter | Type |
|---|---|
input | GrantPermissionInput |
Returns
Promise<void>
listBindings()
listBindings(input): Promise<RbacRoleBinding[]>;Defined in: src/rbac.service.ts:335
Parameters
| Parameter | Type |
|---|---|
input | ListBindingsInput |
Returns
Promise<RbacRoleBinding[]>
listPermissions()
listPermissions(input): Promise<string[]>;Defined in: src/rbac.service.ts:329
Parameters
| Parameter | Type |
|---|---|
input | ListPermissionsInput |
Returns
Promise<string[]>
listRoles()
listRoles(input): Promise<RbacRole[]>;Defined in: src/rbac.service.ts:322
Parameters
| Parameter | Type |
|---|---|
input | ListRolesInput |
Returns
Promise<RbacRole[]>
revokePermission()
revokePermission(input): Promise<void>;Defined in: src/rbac.service.ts:217
Parameters
| Parameter | Type |
|---|---|
input | RevokePermissionInput |
Returns
Promise<void>
revokeRole()
revokeRole(input): Promise<void>;Defined in: src/rbac.service.ts:299
Parameters
| Parameter | Type |
|---|---|
input | RevokeRoleInput |
Returns
Promise<void>
updateRole()
updateRole(input): Promise<RbacRole>;Defined in: src/rbac.service.ts:139
Parameters
| Parameter | Type |
|---|---|
input | UpdateRoleInput |
Returns
Promise<RbacRole>
RbacStorageError
Defined in: src/errors/rbac.error.ts:103
Extends
Constructors
Constructor
new RbacStorageError(details?, options?): RbacStorageError;Defined in: src/errors/rbac.error.ts:104
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacSubjectMissingError
Defined in: src/errors/rbac.error.ts:47
Extends
Constructors
Constructor
new RbacSubjectMissingError(details?, options?): RbacSubjectMissingError;Defined in: src/errors/rbac.error.ts:48
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
RbacTenantMissingError
Defined in: src/errors/rbac.error.ts:53
Extends
Constructors
Constructor
new RbacTenantMissingError(details?, options?): RbacTenantMissingError;Defined in: src/errors/rbac.error.ts:54
Parameters
| Parameter | Type |
|---|---|
details? | Record<string, unknown> |
options? | RbacErrorCauseOptions |
Returns
Overrides
Properties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
code
readonly code: RbacErrorCode;Defined in: src/errors/rbac.error.ts:24
Inherited from
details?
readonly optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:35
Inherited from
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
name
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
stack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
stackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
status?
readonly optional status?: number;Defined in: src/errors/rbac.error.ts:25
Inherited from
Methods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Interfaces
AssignRoleBaseInput
Defined in: src/interfaces/binding.ts:17
Extended by
Properties
expiresAt?
optional expiresAt?: Date | null;Defined in: src/interfaces/binding.ts:21
metadata?
optional metadata?: Record<string, unknown>;Defined in: src/interfaces/binding.ts:22
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/binding.ts:20
subject
subject: RbacSubject;Defined in: src/interfaces/binding.ts:19
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/binding.ts:18
AssignRoleStorageInput
Defined in: src/interfaces/binding.ts:37
Extends
Properties
expiresAt?
optional expiresAt?: Date | null;Defined in: src/interfaces/binding.ts:21
Inherited from
metadata?
optional metadata?: Record<string, unknown>;Defined in: src/interfaces/binding.ts:22
Inherited from
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/binding.ts:20
Inherited from
roleId
roleId: string;Defined in: src/interfaces/binding.ts:38
subject
subject: RbacSubject;Defined in: src/interfaces/binding.ts:19
Inherited from
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/binding.ts:18
Inherited from
CreateRoleInput
Defined in: src/interfaces/role.ts:11
Properties
description?
optional description?: string;Defined in: src/interfaces/role.ts:15
isSystem?
optional isSystem?: boolean;Defined in: src/interfaces/role.ts:16
key
key: string;Defined in: src/interfaces/role.ts:13
name?
optional name?: string;Defined in: src/interfaces/role.ts:14
permissions
permissions: string[];Defined in: src/interfaces/role.ts:17
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/role.ts:12
DefineRbacPermissionsOptions
Defined in: src/permissions/define-rbac-permissions.ts:9
Properties
validateDuplicates?
optional validateDuplicates?: boolean;Defined in: src/permissions/define-rbac-permissions.ts:10
DeleteRoleInput
Defined in: src/interfaces/role.ts:30
Properties
roleId
roleId: string;Defined in: src/interfaces/role.ts:31
FindRoleByIdInput
Defined in: src/interfaces/role.ts:43
Properties
roleId
roleId: string;Defined in: src/interfaces/role.ts:44
FindRoleInput
Defined in: src/interfaces/role.ts:38
Properties
key
key: string;Defined in: src/interfaces/role.ts:40
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/role.ts:39
GrantPermissionInput
Defined in: src/interfaces/permission.ts:1
Properties
permission
permission: string;Defined in: src/interfaces/permission.ts:3
roleId
roleId: string;Defined in: src/interfaces/permission.ts:2
ListBindingsInput
Defined in: src/interfaces/binding.ts:48
Properties
subject
subject: RbacSubject;Defined in: src/interfaces/binding.ts:50
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/binding.ts:49
ListEffectiveRolesInput
Defined in: src/interfaces/storage.ts:25
Properties
now?
optional now?: Date;Defined in: src/interfaces/storage.ts:29
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/storage.ts:28
subject
subject: RbacSubject;Defined in: src/interfaces/storage.ts:26
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/storage.ts:27
ListPermissionsInput
Defined in: src/interfaces/permission.ts:11
Properties
roleId
roleId: string;Defined in: src/interfaces/permission.ts:12
ListRolePermissionsInput
Defined in: src/interfaces/permission.ts:15
Properties
roleId
roleId: string;Defined in: src/interfaces/permission.ts:16
ListRolesInput
Defined in: src/interfaces/role.ts:34
Properties
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/role.ts:35
RbacAuditEvent
Defined in: src/interfaces/audit.ts:1
Properties
metadata?
optional metadata?: Record<string, unknown>;Defined in: src/interfaces/audit.ts:15
subjectId?
optional subjectId?: string;Defined in: src/interfaces/audit.ts:14
subjectType?
optional subjectType?: string;Defined in: src/interfaces/audit.ts:13
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/audit.ts:12
type
type:
| "rbac.role.created"
| "rbac.role.updated"
| "rbac.role.deleted"
| "rbac.permission.granted"
| "rbac.permission.revoked"
| "rbac.role.assigned"
| "rbac.role.revoked"
| "rbac.permission.allowed"
| "rbac.permission.denied";Defined in: src/interfaces/audit.ts:2
RbacAuditLogger
Defined in: src/interfaces/audit.ts:18
Methods
log()
log(event): void | Promise<void>;Defined in: src/interfaces/audit.ts:19
Parameters
| Parameter | Type |
|---|---|
event | RbacAuditEvent |
Returns
void | Promise<void>
RbacCanBaseInput
Defined in: src/interfaces/decision.ts:7
Properties
now?
optional now?: Date;Defined in: src/interfaces/decision.ts:12
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/decision.ts:11
subject?
optional subject?: RbacSubject;Defined in: src/interfaces/decision.ts:8
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/decision.ts:9
tenantMode?
optional tenantMode?: RbacTenantMode;Defined in: src/interfaces/decision.ts:10
RbacDecision
Defined in: src/interfaces/decision.ts:45
Compatibility envelope for decisions created by applications, tests, or older package versions. RbacService.can() returns the narrower RbacServiceDecision contract.
Properties
allowed
allowed: boolean;Defined in: src/interfaces/decision.ts:46
details?
optional details?: RbacDecisionDetails;Defined in: src/interfaces/decision.ts:57
matchedPermissions?
optional matchedPermissions?: string[];Defined in: src/interfaces/decision.ts:55
matchedRoleKeys?
optional matchedRoleKeys?: string[];Defined in: src/interfaces/decision.ts:54
mode?
optional mode?: RbacRequirementMode;Defined in: src/interfaces/decision.ts:53
permission?
optional permission?: string;Defined in: src/interfaces/decision.ts:50
permissions?
optional permissions?: string[];Defined in: src/interfaces/decision.ts:51
reason
reason: RbacDecisionReason;Defined in: src/interfaces/decision.ts:47
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/decision.ts:56
roleKey?
optional roleKey?: string;Defined in: src/interfaces/decision.ts:52
subject?
optional subject?: RbacSubject;Defined in: src/interfaces/decision.ts:48
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/decision.ts:49
RbacDecisionDetails
Defined in: src/interfaces/decision.ts:66
Properties
evaluationPath?
optional evaluationPath?: RbacEvaluationStep[];Defined in: src/interfaces/decision.ts:70
matched?
optional matched?: RbacDecisionMatchDetails;Defined in: src/interfaces/decision.ts:68
missing?
optional missing?: RbacDecisionMissingDetails;Defined in: src/interfaces/decision.ts:69
requirement?
optional requirement?: RbacDecisionRequirementDetails;Defined in: src/interfaces/decision.ts:67
safeMessage?
optional safeMessage?: string;Defined in: src/interfaces/decision.ts:71
RbacDecisionMatchDetails
Defined in: src/interfaces/decision.ts:115
Properties
bindingIds?
optional bindingIds?: string[];Defined in: src/interfaces/decision.ts:121
Deprecated
RbacService has never populated this compatibility field.
permissions?
optional permissions?: string[];Defined in: src/interfaces/decision.ts:119
roleIds?
optional roleIds?: string[];Defined in: src/interfaces/decision.ts:117
Deprecated
RbacService has never populated this compatibility field.
roleKeys?
optional roleKeys?: string[];Defined in: src/interfaces/decision.ts:118
RbacDecisionMissingDetails
Defined in: src/interfaces/decision.ts:124
Properties
permissions?
optional permissions?: string[];Defined in: src/interfaces/decision.ts:129
resource?
optional resource?: boolean;Defined in: src/interfaces/decision.ts:128
Deprecated
RbacService reports resource failures before creating a decision.
roleKeys?
optional roleKeys?: string[];Defined in: src/interfaces/decision.ts:130
subject?
optional subject?: boolean;Defined in: src/interfaces/decision.ts:125
tenant?
optional tenant?: boolean;Defined in: src/interfaces/decision.ts:126
RbacDecisionRequirementDetails
Defined in: src/interfaces/decision.ts:108
Properties
mode?
optional mode?: RbacRequirementMode;Defined in: src/interfaces/decision.ts:112
permissions?
optional permissions?: string[];Defined in: src/interfaces/decision.ts:110
roleKeys?
optional roleKeys?: string[];Defined in: src/interfaces/decision.ts:111
type
type: "permission" | "role";Defined in: src/interfaces/decision.ts:109
RbacEffectivePermission
Defined in: src/interfaces/storage.ts:47
Extends
Properties
bindingId
bindingId: string;Defined in: src/interfaces/storage.ts:37
Inherited from
expiresAt?
optional expiresAt?: Date | null;Defined in: src/interfaces/storage.ts:44
The record remains active when expiresAt is exactly equal to the query now.
Inherited from
permission
permission: string;Defined in: src/interfaces/storage.ts:48
resourceId?
optional resourceId?: string | null;Defined in: src/interfaces/storage.ts:42
Inherited from
resourceType?
optional resourceType?: string | null;Defined in: src/interfaces/storage.ts:41
Resource scope is either an absent pair or two populated strings.
Inherited from
RbacEffectiveRole.resourceType
roleId
roleId: string;Defined in: src/interfaces/storage.ts:36
Inherited from
roleKey
roleKey: string;Defined in: src/interfaces/storage.ts:35
Inherited from
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/storage.ts:39
null and undefined both identify a global effective record.
Inherited from
RbacEffectiveRole
Defined in: src/interfaces/storage.ts:34
Extended by
Properties
bindingId
bindingId: string;Defined in: src/interfaces/storage.ts:37
expiresAt?
optional expiresAt?: Date | null;Defined in: src/interfaces/storage.ts:44
The record remains active when expiresAt is exactly equal to the query now.
resourceId?
optional resourceId?: string | null;Defined in: src/interfaces/storage.ts:42
resourceType?
optional resourceType?: string | null;Defined in: src/interfaces/storage.ts:41
Resource scope is either an absent pair or two populated strings.
roleId
roleId: string;Defined in: src/interfaces/storage.ts:36
roleKey
roleKey: string;Defined in: src/interfaces/storage.ts:35
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/storage.ts:39
null and undefined both identify a global effective record.
RbacErrorCauseOptions
Defined in: src/errors/rbac.error.ts:17
Properties
cause?
optional cause?: unknown;Defined in: src/errors/rbac.error.ts:18
RbacErrorOptions
Defined in: src/errors/rbac.error.ts:12
Properties
cause?
optional cause?: unknown;Defined in: src/errors/rbac.error.ts:14
details?
optional details?: Record<string, unknown>;Defined in: src/errors/rbac.error.ts:13
RbacEvaluationStep
Defined in: src/interfaces/decision.ts:133
Properties
code
code:
| "subject_missing"
| "tenant_missing"
| "tenant_conflict"
| "resource_missing"
| "resource_mismatch"
| "roles_loaded"
| "permissions_loaded"
| "permission_matched"
| "permission_missing"
| "role_matched"
| "role_missing"
| "storage_error";Defined in: src/interfaces/decision.ts:134
outcome
outcome: "allow" | "deny" | "skip" | "info";Defined in: src/interfaces/decision.ts:147
RbacModuleAsyncOptions
Defined in: src/interfaces/module-options.ts:69
Properties
imports?
optional imports?: (
| Type<any>
| DynamicModule
| Promise<DynamicModule>
| ForwardReference<any>)[];Defined in: src/interfaces/module-options.ts:70
inject?
optional inject?: (InjectionToken | OptionalFactoryDependency)[];Defined in: src/interfaces/module-options.ts:71
useFactory
useFactory: (...args) =>
| RbacModuleOptions
| Promise<RbacModuleOptions>;Defined in: src/interfaces/module-options.ts:72
Parameters
| Parameter | Type |
|---|---|
...args | any[] |
Returns
| RbacModuleOptions | Promise<RbacModuleOptions>
RbacModuleOptions
Defined in: src/interfaces/module-options.ts:45
Properties
auditLogger?
optional auditLogger?: RbacAuditLogger;Defined in: src/interfaces/module-options.ts:49
changePublisher?
optional changePublisher?: RbacPolicyChangePublisher;Defined in: src/interfaces/module-options.ts:65
logAllowedDecisions?
optional logAllowedDecisions?: boolean;Defined in: src/interfaces/module-options.ts:63
now?
optional now?: () => Date;Defined in: src/interfaces/module-options.ts:66
Returns
Date
requireMetadata?
optional requireMetadata?: boolean;Defined in: src/interfaces/module-options.ts:50
storage
storage: RbacStorage;Defined in: src/interfaces/module-options.ts:46
storageErrors?
optional storageErrors?: "deny" | "throw";Defined in: src/interfaces/module-options.ts:62
subjectResolver?
optional subjectResolver?: RbacSubjectResolver;Defined in: src/interfaces/module-options.ts:47
tenant?
optional tenant?: {
allowGlobalRolesInTenant?: boolean;
requiredByDefault?: boolean;
resolverMode?: RbacTenantResolverMode;
};Defined in: src/interfaces/module-options.ts:51
allowGlobalRolesInTenant?
optional allowGlobalRolesInTenant?: boolean;requiredByDefault?
optional requiredByDefault?: boolean;resolverMode?
optional resolverMode?: RbacTenantResolverMode;Controls whether a configured tenantResolver is authoritative. legacy-fallback preserves the pre-0.2.2 default-first behavior and is deprecated.
tenantResolver?
optional tenantResolver?: RbacTenantResolver;Defined in: src/interfaces/module-options.ts:48
writeValidation?
optional writeValidation?: RbacWriteValidationOptions;Defined in: src/interfaces/module-options.ts:64
RbacMutationResult
Defined in: src/interfaces/storage.ts:55
Type Parameters
| Type Parameter | Default type |
|---|---|
T | undefined |
Properties
outcome
outcome: RbacMutationOutcome;Defined in: src/interfaces/storage.ts:56
reason?
optional reason?: RbacMutationConflictReason;Defined in: src/interfaces/storage.ts:58
value?
optional value?: T;Defined in: src/interfaces/storage.ts:57
RbacPermissionMetadata
Defined in: src/permissions/define-rbac-permissions.ts:3
Properties
description?
optional description?: string;Defined in: src/permissions/define-rbac-permissions.ts:4
owner?
optional owner?: string;Defined in: src/permissions/define-rbac-permissions.ts:5
risk?
optional risk?: string;Defined in: src/permissions/define-rbac-permissions.ts:6
RbacPolicyChangeEvent
Defined in: src/interfaces/module-options.ts:28
Properties
bindingId?
optional bindingId?: string;Defined in: src/interfaces/module-options.ts:37
metadata?
optional metadata?: Record<string, unknown>;Defined in: src/interfaces/module-options.ts:38
occurredAt
occurredAt: Date;Defined in: src/interfaces/module-options.ts:30
permissions?
optional permissions?: string[];Defined in: src/interfaces/module-options.ts:35
resource?
optional resource?: RbacResourceRef;Defined in: src/interfaces/module-options.ts:36
roleId?
optional roleId?: string;Defined in: src/interfaces/module-options.ts:33
roleKey?
optional roleKey?: string;Defined in: src/interfaces/module-options.ts:34
subject?
optional subject?: Pick<RbacSubject, "type" | "id">;Defined in: src/interfaces/module-options.ts:32
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/module-options.ts:31
type
type: RbacPolicyChangeEventType;Defined in: src/interfaces/module-options.ts:29
RbacPolicyChangePublisher
Defined in: src/interfaces/module-options.ts:41
Methods
publish()
publish(event): void | Promise<void>;Defined in: src/interfaces/module-options.ts:42
Parameters
| Parameter | Type |
|---|---|
event | RbacPolicyChangeEvent |
Returns
void | Promise<void>
RbacRequirementOptions
Defined in: src/interfaces/requirements.ts:31
Properties
mode?
optional mode?: RbacRequirementMode;Defined in: src/interfaces/requirements.ts:32
reason?
optional reason?: string;Defined in: src/interfaces/requirements.ts:45
Deprecated
Stored in decorator metadata for compatibility but never read, returned in a decision, or written to RBAC audit events. Use application-owned metadata for human-readable policy labels.
resource?
optional resource?:
| RbacBuiltInResourceDeclaration
| RbacResourceResolverFn
| RbacResourceResolverToken
| RbacResourceResolverTokenRef;Defined in: src/interfaces/requirements.ts:34
tenant?
optional tenant?: "required" | "optional" | "none";Defined in: src/interfaces/requirements.ts:33
RbacResourceRef
Defined in: src/interfaces/resource.ts:3
Properties
id
id: string;Defined in: src/interfaces/resource.ts:5
type
type: string;Defined in: src/interfaces/resource.ts:4
RbacResourceResolver
Defined in: src/interfaces/resource.ts:9
Injectable resource resolver used by the HTTP-only RbacGuard pipeline in 0.2.x.
Methods
resolve()
resolve(context):
| RbacResourceRef
| Promise<RbacResourceRef | undefined>
| undefined;Defined in: src/interfaces/resource.ts:10
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
Returns
| RbacResourceRef | Promise<RbacResourceRef | undefined> | undefined
RbacResourceResolverTokenRef
Defined in: src/interfaces/resource.ts:17
Properties
resolverToken
resolverToken: RbacResourceResolverToken;Defined in: src/interfaces/resource.ts:18
RbacRole
Defined in: src/interfaces/role.ts:1
Properties
description?
optional description?: string;Defined in: src/interfaces/role.ts:5
id
id: string;Defined in: src/interfaces/role.ts:2
isSystem?
optional isSystem?: boolean;Defined in: src/interfaces/role.ts:7
key
key: string;Defined in: src/interfaces/role.ts:3
name?
optional name?: string;Defined in: src/interfaces/role.ts:4
permissions
permissions: string[];Defined in: src/interfaces/role.ts:8
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/role.ts:6
RbacRoleBinding
Defined in: src/interfaces/binding.ts:4
Properties
expiresAt?
optional expiresAt?: Date | null;Defined in: src/interfaces/binding.ts:12
id
id: string;Defined in: src/interfaces/binding.ts:5
metadata?
optional metadata?: Record<string, unknown>;Defined in: src/interfaces/binding.ts:14
resourceId?
optional resourceId?: string | null;Defined in: src/interfaces/binding.ts:11
resourceType?
optional resourceType?: string | null;Defined in: src/interfaces/binding.ts:10
revokedAt?
optional revokedAt?: Date | null;Defined in: src/interfaces/binding.ts:13
roleId
roleId: string;Defined in: src/interfaces/binding.ts:9
subjectId
subjectId: string;Defined in: src/interfaces/binding.ts:8
subjectType
subjectType: string;Defined in: src/interfaces/binding.ts:7
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/binding.ts:6
RbacServiceDecisionDetails
Defined in: src/interfaces/decision.ts:75
Details that are always attached to decisions produced by RbacService.can().
Extends
Omit<RbacDecisionDetails,"requirement"|"matched"|"missing"|"evaluationPath"|"safeMessage">
Properties
evaluationPath
evaluationPath: RbacServiceEvaluationStep[];Defined in: src/interfaces/decision.ts:82
matched?
optional matched?: RbacServiceDecisionMatchDetails;Defined in: src/interfaces/decision.ts:80
missing?
optional missing?: RbacServiceDecisionMissingDetails;Defined in: src/interfaces/decision.ts:81
requirement?
optional requirement?: RbacServiceDecisionRequirementDetails;Defined in: src/interfaces/decision.ts:79
safeMessage
safeMessage: RbacServiceDecisionReason;Defined in: src/interfaces/decision.ts:83
RbacServiceDecisionMatchDetails
Defined in: src/interfaces/decision.ts:97
Properties
permissions?
optional permissions?: string[];Defined in: src/interfaces/decision.ts:99
roleKeys
roleKeys: string[];Defined in: src/interfaces/decision.ts:98
RbacStorage
Defined in: src/interfaces/storage.ts:83
Properties
findRoleById?
readonly optional findRoleById?: (input) => Promise<RbacRole | null>;Defined in: src/interfaces/storage.ts:93
Optional indexed lookup used by strict assignment validation. Adapters that omit it retain the deprecated 0.2.x listRoles({}) compatibility fallback.
Parameters
| Parameter | Type |
|---|---|
input | FindRoleByIdInput |
Returns
Promise<RbacRole | null>
mutationResults?
readonly optional mutationResults?: RbacStorageMutationCapability;Defined in: src/interfaces/storage.ts:88
Additive 0.2.x capability for outcome-aware writes. Custom adapters that omit it use the deprecated result-less best-effort event fallback.
Methods
assignRole()
assignRole(input): Promise<RbacRoleBinding>;Defined in: src/interfaces/storage.ts:101
Parameters
| Parameter | Type |
|---|---|
input | AssignRoleStorageInput |
Returns
Promise<RbacRoleBinding>
deleteRole()
deleteRole(input): Promise<void>;Defined in: src/interfaces/storage.ts:97
Parameters
| Parameter | Type |
|---|---|
input | DeleteRoleInput |
Returns
Promise<void>
findRole()
findRole(input): Promise<RbacRole | null>;Defined in: src/interfaces/storage.ts:94
Parameters
| Parameter | Type |
|---|---|
input | FindRoleInput |
Returns
Promise<RbacRole | null>
grantPermission()
grantPermission(input): Promise<void>;Defined in: src/interfaces/storage.ts:98
Parameters
| Parameter | Type |
|---|---|
input | GrantPermissionInput |
Returns
Promise<void>
listBindings()
listBindings(input): Promise<RbacRoleBinding[]>;Defined in: src/interfaces/storage.ts:103
Parameters
| Parameter | Type |
|---|---|
input | ListBindingsInput |
Returns
Promise<RbacRoleBinding[]>
listEffectivePermissions()
listEffectivePermissions(input): Promise<RbacEffectivePermission[]>;Defined in: src/interfaces/storage.ts:105
Parameters
| Parameter | Type |
|---|---|
input | ListEffectiveRolesInput |
Returns
Promise<RbacEffectivePermission[]>
listEffectiveRoles()
listEffectiveRoles(input): Promise<RbacEffectiveRole[]>;Defined in: src/interfaces/storage.ts:104
Parameters
| Parameter | Type |
|---|---|
input | ListEffectiveRolesInput |
Returns
Promise<RbacEffectiveRole[]>
listRolePermissions()
listRolePermissions(input): Promise<string[]>;Defined in: src/interfaces/storage.ts:100
Parameters
| Parameter | Type |
|---|---|
input | ListRolePermissionsInput |
Returns
Promise<string[]>
listRoles()
listRoles(input): Promise<RbacRole[]>;Defined in: src/interfaces/storage.ts:95
Parameters
| Parameter | Type |
|---|---|
input | ListRolesInput |
Returns
Promise<RbacRole[]>
revokePermission()
revokePermission(input): Promise<void>;Defined in: src/interfaces/storage.ts:99
Parameters
| Parameter | Type |
|---|---|
input | RevokePermissionInput |
Returns
Promise<void>
revokeRole()
revokeRole(input): Promise<void>;Defined in: src/interfaces/storage.ts:102
Parameters
| Parameter | Type |
|---|---|
input | RevokeRoleInput |
Returns
Promise<void>
upsertRole()
upsertRole(input): Promise<RbacRole>;Defined in: src/interfaces/storage.ts:96
Parameters
| Parameter | Type |
|---|---|
input | UpsertRoleInput |
Returns
Promise<RbacRole>
RbacStorageMutationCapability
Defined in: src/interfaces/storage.ts:65
Optional mutation-result protocol used to distinguish committed changes from idempotent no-ops without changing the legacy RbacStorage method signatures.
Methods
assignRole()
assignRole(input): Promise<RbacMutationResult<RbacRoleBinding>>;Defined in: src/interfaces/storage.ts:71
Parameters
| Parameter | Type |
|---|---|
input | AssignRoleStorageInput |
Returns
Promise<RbacMutationResult<RbacRoleBinding>>
createRole()
createRole(input): Promise<RbacMutationResult<RbacRole>>;Defined in: src/interfaces/storage.ts:66
Parameters
| Parameter | Type |
|---|---|
input | CreateRoleInput |
Returns
Promise<RbacMutationResult<RbacRole>>
deleteRole()
deleteRole(input): Promise<RbacMutationResult<undefined>>;Defined in: src/interfaces/storage.ts:68
Parameters
| Parameter | Type |
|---|---|
input | DeleteRoleInput |
Returns
Promise<RbacMutationResult<undefined>>
grantPermission()
grantPermission(input): Promise<RbacMutationResult<undefined>>;Defined in: src/interfaces/storage.ts:69
Parameters
| Parameter | Type |
|---|---|
input | GrantPermissionInput |
Returns
Promise<RbacMutationResult<undefined>>
revokePermission()
revokePermission(input): Promise<RbacMutationResult<undefined>>;Defined in: src/interfaces/storage.ts:70
Parameters
| Parameter | Type |
|---|---|
input | RevokePermissionInput |
Returns
Promise<RbacMutationResult<undefined>>
revokeRole()
revokeRole(input): Promise<RbacMutationResult<undefined>>;Defined in: src/interfaces/storage.ts:72
Parameters
| Parameter | Type |
|---|---|
input | RevokeRoleInput |
Returns
Promise<RbacMutationResult<undefined>>
updateRole()
updateRole(input): Promise<RbacMutationResult<RbacRole>>;Defined in: src/interfaces/storage.ts:67
Parameters
| Parameter | Type |
|---|---|
input | UpdateRoleInput |
Returns
Promise<RbacMutationResult<RbacRole>>
RbacStorageRoleLookupCapability
Defined in: src/interfaces/storage.ts:79
Additive 0.2.x capability for indexed role-id lookups. Implement this on custom adapters before the legacy full-list fallback is removed in 0.3 or later.
Methods
findRoleById()
findRoleById(input): Promise<RbacRole | null>;Defined in: src/interfaces/storage.ts:80
Parameters
| Parameter | Type |
|---|---|
input | FindRoleByIdInput |
Returns
Promise<RbacRole | null>
RbacStoredResourceRef
Defined in: src/utils/resource-matcher.ts:3
Properties
resourceId?
optional resourceId?: string | null;Defined in: src/utils/resource-matcher.ts:5
resourceType?
optional resourceType?: string | null;Defined in: src/utils/resource-matcher.ts:4
RbacSubject
Defined in: src/interfaces/subject.ts:3
Properties
attributes?
optional attributes?: Record<string, unknown>;Defined in: src/interfaces/subject.ts:8
displayName?
optional displayName?: string;Defined in: src/interfaces/subject.ts:7
id
id: string;Defined in: src/interfaces/subject.ts:5
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/subject.ts:6
type
type: RbacSubjectType;Defined in: src/interfaces/subject.ts:4
RbacWriteValidationOptions
Defined in: src/interfaces/module-options.ts:8
Properties
rejectGlobalRoleInTenantBinding?
optional rejectGlobalRoleInTenantBinding?: boolean;Defined in: src/interfaces/module-options.ts:11
rejectResourceWithoutTenant?
optional rejectResourceWithoutTenant?: boolean;Defined in: src/interfaces/module-options.ts:10
rejectTenantMismatch?
optional rejectTenantMismatch?: boolean;Defined in: src/interfaces/module-options.ts:9
RevokePermissionInput
Defined in: src/interfaces/permission.ts:6
Properties
permission
permission: string;Defined in: src/interfaces/permission.ts:8
roleId
roleId: string;Defined in: src/interfaces/permission.ts:7
RevokeRoleInput
Defined in: src/interfaces/binding.ts:41
Properties
bindingId
bindingId: string;Defined in: src/interfaces/binding.ts:42
revokedAt?
optional revokedAt?: Date;Defined in: src/interfaces/binding.ts:43
UpdateRoleInput
Defined in: src/interfaces/role.ts:20
Properties
description?
optional description?: string;Defined in: src/interfaces/role.ts:25
isSystem?
optional isSystem?: boolean;Defined in: src/interfaces/role.ts:26
key?
optional key?: string;Defined in: src/interfaces/role.ts:23
name?
optional name?: string;Defined in: src/interfaces/role.ts:24
permissions?
optional permissions?: string[];Defined in: src/interfaces/role.ts:27
roleId
roleId: string;Defined in: src/interfaces/role.ts:21
tenantId?
optional tenantId?: string | null;Defined in: src/interfaces/role.ts:22
Type Aliases
AssignRoleInput
type AssignRoleInput = AssignRoleBaseInput &
| {
roleId: string;
roleKey?: never;
}
| {
roleId?: never;
roleKey: string;
};Defined in: src/interfaces/binding.ts:25
ListBindingsStorageInput
type ListBindingsStorageInput = ListBindingsInput;Defined in: src/interfaces/binding.ts:53
ListEffectivePermissionsInput
type ListEffectivePermissionsInput = ListEffectiveRolesInput;Defined in: src/interfaces/storage.ts:32
RbacBuiltInResourceDeclaration
type RbacBuiltInResourceDeclaration =
| RbacParamResourceDeclaration
| RbacHeaderResourceDeclaration
| RbacQueryResourceDeclaration;Defined in: src/interfaces/requirements.ts:26
RbacCanInput
type RbacCanInput =
| RbacPermissionCanInput
| RbacRoleCanInput;Defined in: src/interfaces/decision.ts:38
RbacDecisionReason
type RbacDecisionReason =
| RbacServiceDecisionReason
| RbacLegacyDecisionReason;Defined in: src/interfaces/decision.ts:192
Compatibility reason union. Prefer RbacServiceDecisionReason when consuming results returned by RbacService.can().
RbacErrorCode
type RbacErrorCode =
| "RBAC_CONFIG_ERROR"
| "RBAC_SUBJECT_MISSING"
| "RBAC_TENANT_MISSING"
| "RBAC_RESOURCE_MISSING"
| "RBAC_PERMISSION_DENIED"
| "RBAC_ROLE_NOT_FOUND"
| "RBAC_PERMISSION_NOT_FOUND"
| "RBAC_BINDING_NOT_FOUND"
| "RBAC_STORAGE_ERROR";Defined in: src/errors/rbac.error.ts:1
RbacHeaderResourceDeclaration
type RbacHeaderResourceDeclaration = {
idHeader: string;
idParam?: never;
idQuery?: never;
type: string;
};Defined in: src/interfaces/requirements.ts:12
Properties
idHeader
idHeader: string;Defined in: src/interfaces/requirements.ts:14
idParam?
optional idParam?: never;Defined in: src/interfaces/requirements.ts:15
idQuery?
optional idQuery?: never;Defined in: src/interfaces/requirements.ts:16
type
type: string;Defined in: src/interfaces/requirements.ts:13
RbacLegacyDecisionReason
type RbacLegacyDecisionReason =
| "denied_resource_missing"
| "denied_role_expired"
| "denied_resource_mismatch";Defined in: src/interfaces/decision.ts:183
Deprecated
These values were exported by 0.2.x but have no RbacService.can() producer. They remain in the compatibility RbacDecisionReason envelope until a separate breaking release.
RbacMutationConflictReason
type RbacMutationConflictReason = "role_not_found" | "duplicate";Defined in: src/interfaces/storage.ts:53
RbacMutationOutcome
type RbacMutationOutcome = "created" | "updated" | "deleted" | "no-op" | "conflict";Defined in: src/interfaces/storage.ts:51
RbacParamResourceDeclaration
type RbacParamResourceDeclaration = {
idHeader?: never;
idParam: string;
idQuery?: never;
type: string;
};Defined in: src/interfaces/requirements.ts:5
Properties
idHeader?
optional idHeader?: never;Defined in: src/interfaces/requirements.ts:8
idParam
idParam: string;Defined in: src/interfaces/requirements.ts:7
idQuery?
optional idQuery?: never;Defined in: src/interfaces/requirements.ts:9
type
type: string;Defined in: src/interfaces/requirements.ts:6
RbacPermissionCanInput
type RbacPermissionCanInput = RbacCanBaseInput &
| {
mode?: RbacRequirementMode;
permission: string;
permissions?: string[];
roleKey?: never;
}
| {
mode?: RbacRequirementMode;
permission?: undefined;
permissions: string[];
roleKey?: never;
};Defined in: src/interfaces/decision.ts:15
RbacPermissionContract
type RbacPermissionContract<T> = PermissionShape<T> & {
$metadata: PermissionMetadataMap<T>;
$permission: PermissionValueUnion<T>;
$permissions: PermissionValueUnion<T>[];
};Defined in: src/permissions/define-rbac-permissions.ts:45
Type Declaration
| Name | Type | Defined in |
|---|---|---|
$metadata | PermissionMetadataMap<T> | src/permissions/define-rbac-permissions.ts:48 |
$permission | PermissionValueUnion<T> | src/permissions/define-rbac-permissions.ts:46 |
$permissions | PermissionValueUnion<T>[] | src/permissions/define-rbac-permissions.ts:47 |
Type Parameters
| Type Parameter |
|---|
T |
RbacPolicyChangeEventType
type RbacPolicyChangeEventType =
| "role.created"
| "role.updated"
| "role.deleted"
| "permission.granted"
| "permission.revoked"
| "role.assigned"
| "role.revoked";Defined in: src/interfaces/module-options.ts:19
RbacQueryResourceDeclaration
type RbacQueryResourceDeclaration = {
idHeader?: never;
idParam?: never;
idQuery: string;
type: string;
};Defined in: src/interfaces/requirements.ts:19
Properties
idHeader?
optional idHeader?: never;Defined in: src/interfaces/requirements.ts:23
idParam?
optional idParam?: never;Defined in: src/interfaces/requirements.ts:22
idQuery
idQuery: string;Defined in: src/interfaces/requirements.ts:21
type
type: string;Defined in: src/interfaces/requirements.ts:20
RbacRequirement
type RbacRequirement =
| {
kind: "permission";
mode: RbacRequirementMode;
options: RbacRequirementOptions;
permissions: string[];
}
| {
kind: "role";
options: RbacRequirementOptions;
roleKey: string;
};Defined in: src/interfaces/requirements.ts:48
RbacRequirementMode
type RbacRequirementMode = "any" | "all";Defined in: src/interfaces/decision.ts:5
RbacResourceResolverFn
type RbacResourceResolverFn = (context) =>
| Promise<RbacResourceRef | undefined>
| RbacResourceRef
| undefined;Defined in: src/interfaces/resolvers.ts:22
Resolves a resource for the HTTP-only RbacGuard pipeline in 0.2.x.
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
Returns
| Promise<RbacResourceRef | undefined> | RbacResourceRef | undefined
RbacResourceResolverToken
type RbacResourceResolverToken = InjectionToken<RbacResourceResolver>;Defined in: src/interfaces/resource.ts:15
RbacRoleCanInput
type RbacRoleCanInput = RbacCanBaseInput & {
mode?: never;
permission?: never;
permissions?: never;
roleKey: string;
};Defined in: src/interfaces/decision.ts:31
Type Declaration
| Name | Type | Defined in |
|---|---|---|
mode? | never | src/interfaces/decision.ts:35 |
permission? | never | src/interfaces/decision.ts:33 |
permissions? | never | src/interfaces/decision.ts:34 |
roleKey | string | src/interfaces/decision.ts:32 |
RbacServiceDecision
type RbacServiceDecision = Omit<RbacDecision, "reason" | "details"> & {
details: RbacServiceDecisionDetails;
reason: RbacServiceDecisionReason;
};Defined in: src/interfaces/decision.ts:61
A decision produced by RbacService.can().
Type Declaration
| Name | Type | Defined in |
|---|---|---|
details | RbacServiceDecisionDetails | src/interfaces/decision.ts:63 |
reason | RbacServiceDecisionReason | src/interfaces/decision.ts:62 |
RbacServiceDecisionMissingDetails
type RbacServiceDecisionMissingDetails =
| {
subject: true;
}
| {
tenant: true;
}
| {
permissions: string[];
}
| {
roleKeys: string[];
};Defined in: src/interfaces/decision.ts:102
RbacServiceDecisionReason
type RbacServiceDecisionReason =
| "allowed_by_role"
| "allowed_by_role_permission"
| "denied_subject_missing"
| "denied_tenant_missing"
| "denied_tenant_conflict"
| "denied_no_matching_role"
| "denied_no_matching_permission"
| "denied_storage_error";Defined in: src/interfaces/decision.ts:168
Decision reasons that RbacService.can() can currently produce.
RbacServiceDecisionRequirementDetails
type RbacServiceDecisionRequirementDetails =
| {
mode: RbacRequirementMode;
permissions: string[];
type: "permission";
}
| {
roleKeys: string[];
type: "role";
};Defined in: src/interfaces/decision.ts:86
RbacServiceEvaluationStep
type RbacServiceEvaluationStep =
| {
code: "role_matched" | "permission_matched";
outcome: "allow";
}
| {
code: | "subject_missing"
| "tenant_missing"
| "tenant_conflict"
| "permission_missing"
| "role_missing"
| "storage_error";
outcome: "deny";
};Defined in: src/interfaces/decision.ts:151
Evaluation steps that RbacService.can() can currently produce.
RbacSubjectResolver
type RbacSubjectResolver = (context) =>
| Promise<RbacSubject | undefined>
| RbacSubject
| undefined;Defined in: src/interfaces/resolvers.ts:10
Resolves a subject for the HTTP-only RbacGuard pipeline in 0.2.x. Receiving an ExecutionContext does not make the complete Guard transport-neutral.
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
Returns
| Promise<RbacSubject | undefined> | RbacSubject | undefined
RbacSubjectType
type RbacSubjectType =
| "user"
| "api_key"
| "service_account"
| string & {
};Defined in: src/interfaces/subject.ts:1
RbacTenantMode
type RbacTenantMode = "required" | "optional" | "none";Defined in: src/interfaces/decision.ts:4
RbacTenantResolver
type RbacTenantResolver = (context, options, subject) =>
| Promise<string | null | undefined>
| string
| null
| undefined;Defined in: src/interfaces/resolvers.ts:15
Resolves a trusted tenant for the HTTP-only RbacGuard pipeline in 0.2.x.
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
options | RbacRequirementOptions |
subject | RbacSubject |
Returns
| Promise<string | null | undefined> | string | null | undefined
RbacTenantResolverMode
type RbacTenantResolverMode = "authoritative" | "legacy-fallback";Defined in: src/interfaces/module-options.ts:14
RevokeRoleStorageInput
type RevokeRoleStorageInput = RevokeRoleInput;Defined in: src/interfaces/binding.ts:46
UpsertRoleInput
type UpsertRoleInput =
| CreateRoleInput
| UpdateRoleInput;Defined in: src/interfaces/role.ts:47
Variables
CurrentRbacSubject
const CurrentRbacSubject: (...dataOrPipes) => ParameterDecorator;Defined in: src/decorators/current-rbac-subject.decorator.ts:7
Reads the subject stored by RbacGuard on the current Nest HTTP request.
Parameters
| Parameter | Type |
|---|---|
...dataOrPipes | unknown[] |
Returns
ParameterDecorator
RBAC_OPTIONS
const RBAC_OPTIONS: typeof RBAC_OPTIONS;Defined in: src/constants.ts:1
RBAC_REQUIREMENTS_METADATA
const RBAC_REQUIREMENTS_METADATA: typeof RBAC_REQUIREMENTS_METADATA;Defined in: src/constants.ts:3
RBAC_SKIP_METADATA
const RBAC_SKIP_METADATA: typeof RBAC_SKIP_METADATA;Defined in: src/constants.ts:4
RBAC_STORAGE
const RBAC_STORAGE: typeof RBAC_STORAGE;Defined in: src/constants.ts:2
RBAC_SUBJECT_REQUEST_KEY
const RBAC_SUBJECT_REQUEST_KEY: "rbacSubject" = 'rbacSubject';Defined in: src/constants.ts:5
RequirePermission
const RequirePermission: (permission, options) => ClassDecorator & MethodDecorator = Can;Defined in: src/decorators/permission.decorator.ts:15
Parameters
| Parameter | Type |
|---|---|
permission | string |
options | RbacRequirementOptions |
Returns
ClassDecorator & MethodDecorator
Functions
assertNonEmptyString()
function assertNonEmptyString(value, name): string;Defined in: src/utils/assertions.ts:1
Parameters
| Parameter | Type |
|---|---|
value | string | null | undefined |
name | string |
Returns
string
Can()
function Can(permission, options?): ClassDecorator & MethodDecorator;Defined in: src/decorators/permission.decorator.ts:4
Parameters
| Parameter | Type |
|---|---|
permission | string |
options | RbacRequirementOptions |
Returns
ClassDecorator & MethodDecorator
createStrictRbacOptions()
function createStrictRbacOptions(options): RbacModuleOptions;Defined in: src/options/strict-rbac-options.ts:3
Parameters
| Parameter | Type |
|---|---|
options | RbacModuleOptions |
Returns
defaultHttpSubjectResolver()
function defaultHttpSubjectResolver(): RbacSubjectResolver;Defined in: src/resolvers/default-http-subject.resolver.ts:111
Returns
defineRbacPermissions()
function defineRbacPermissions<T>(definition, options?): RbacPermissionContract<T>;Defined in: src/permissions/define-rbac-permissions.ts:76
Type Parameters
| Type Parameter |
|---|
T extends PermissionDefinition |
Parameters
| Parameter | Type |
|---|---|
definition | T |
options | DefineRbacPermissionsOptions |
Returns
mapRbacErrorToHttpException()
function mapRbacErrorToHttpException(error):
| InternalServerErrorException
| UnauthorizedException
| ForbiddenException;Defined in: src/errors/http-error.mapper.ts:8
Parameters
| Parameter | Type |
|---|---|
error | RbacError |
Returns
| InternalServerErrorException | UnauthorizedException | ForbiddenException
matchesPermission()
function matchesPermission(granted, required): boolean;Defined in: src/utils/permission-matcher.ts:3
Parameters
| Parameter | Type |
|---|---|
granted | string |
required | string |
Returns
boolean
matchesResource()
function matchesResource(granted, required): boolean;Defined in: src/utils/resource-matcher.ts:21
Parameters
| Parameter | Type |
|---|---|
granted | | RbacResourceRef | RbacStoredResourceRef | undefined |
required | RbacResourceRef | undefined |
Returns
boolean
normalizePermission()
function normalizePermission(permission): string;Defined in: src/utils/normalize.ts:3
Parameters
| Parameter | Type |
|---|---|
permission | string |
Returns
string
normalizePermissions()
function normalizePermissions(permissions): string[];Defined in: src/utils/normalize.ts:11
Parameters
| Parameter | Type |
|---|---|
permissions | string[] |
Returns
string[]
RequirePermissions()
function RequirePermissions(permissions, options?): ClassDecorator & MethodDecorator;Defined in: src/decorators/permission.decorator.ts:17
Parameters
| Parameter | Type |
|---|---|
permissions | readonly string[] |
options | RbacRequirementOptions |
Returns
ClassDecorator & MethodDecorator
RequireRole()
function RequireRole(roleKey, options?): ClassDecorator & MethodDecorator;Defined in: src/decorators/role.decorator.ts:4
Parameters
| Parameter | Type |
|---|---|
roleKey | string |
options | RbacRequirementOptions |
Returns
ClassDecorator & MethodDecorator
resolveHttpResource()
function resolveHttpResource(context, declaration): RbacResourceRef | undefined;Defined in: src/resolvers/default-http-resource.resolver.ts:30
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
declaration | RbacBuiltInResourceDeclaration |
Returns
RbacResourceRef | undefined
resolveHttpTenant()
function resolveHttpTenant(
context,
requirementOptions,
subject): string | null | undefined;Defined in: src/resolvers/default-http-tenant.resolver.ts:41
Parameters
| Parameter | Type |
|---|---|
context | ExecutionContext |
requirementOptions | RbacRequirementOptions |
subject | RbacSubject |
Returns
string | null | undefined
SkipRbac()
function SkipRbac(reason?): CustomDecorator<typeof RBAC_SKIP_METADATA>;Defined in: src/decorators/skip-rbac.decorator.ts:4
Parameters
| Parameter | Type |
|---|---|
reason? | string |
Returns
CustomDecorator<typeof RBAC_SKIP_METADATA>