Skip to content

basalt / permissions/src / accessRoutes

Function: accessRoutes() ​

> accessRoutes(options?): BasaltRoute[]

Defined in: permissions/src/index.ts:1069

GET /me/access — the roles and permissions of whoever is asking.

/auth/me answers who you are; nothing answered what you may do. So every frontend that hides a menu by permission wrote the same twenty lines: read the roles, read the direct grants, read each role's grants, merge, dedupe.

Not a security surface — the server decides on every request regardless. This exists so the interface stops offering doors that return 403, and stops hiding doors that would have opened: the answer is Gate.describeAccess — current-scope AND global grants, live temporary grants and delegations (each marked with its source and expiry), and the superAdmin bypass.

Pair it with @basaltkit/permissions/match, which carries the same wildcard rule and imports nothing, so the browser applies the server's rule instead of a copy that drifts from it.

ts
fastifyPlugin({ routes: [...accessRoutes(), ...myRoutes] })

Parameters ​

options? ​

path? ​

string

store? ​

AccessStore

Returns ​

BasaltRoute[]

Released under the MIT License.