basalt / permissions/src / accessRoutes
Function: accessRoutes()
> accessRoutes(options?): BasaltRoute[]
Defined in: permissions/src/index.ts:1069
GET /me/access — the roles and permissions of whoever is asking.
/auth/me answers who you are; nothing answered what you may do. So every frontend that hides a menu by permission wrote the same twenty lines: read the roles, read the direct grants, read each role's grants, merge, dedupe.
Not a security surface — the server decides on every request regardless. This exists so the interface stops offering doors that return 403, and stops hiding doors that would have opened: the answer is Gate.describeAccess — current-scope AND global grants, live temporary grants and delegations (each marked with its source and expiry), and the superAdmin bypass.
Pair it with @basaltkit/permissions/match, which carries the same wildcard rule and imports nothing, so the browser applies the server's rule instead of a copy that drifts from it.
fastifyPlugin({ routes: [...accessRoutes(), ...myRoutes] })Parameters
options?
path?
string