Skip to content

basalt / permissions/src / GateOptions

Interface: GateOptions ​

Defined in: permissions/src/index.ts:343

Properties ​

allowGlobalWrites? ​

> optional allowGlobalWrites?: boolean

Defined in: permissions/src/index.ts:419

Let a write with no explicit scope land in GLOBAL_SCOPE when no tenant is in the context, even though tenancy is active. Default false: in a multi-tenant app such a write throws ScopeRequiredError instead — an unresolved tenant must not turn a tenant-admin call into a platform-wide grant. Passing GLOBAL_SCOPE explicitly always works. Single-tenant apps (no tenancy) are unaffected either way.


delegations? ​

> optional delegations?: DelegationStore

Defined in: permissions/src/index.ts:357

Optional store enabling delegate() — one user acting with another's authority.


hooks? ​

> optional hooks?: HookBus

Defined in: permissions/src/index.ts:382

Hook bus to emit permission:* events on (denials, role and grant changes) — permissionsPlugin wires the app's bus, which auditPlugin captures by default.


inheritGlobalRolePermissions? ​

> optional inheritGlobalRolePermissions?: boolean | readonly string[]

Defined in: permissions/src/index.ts:410

Resolve a tenant-held role's permissions from its global definition (grantToRole(role, perms, GLOBAL_SCOPE)) too — still granting only in the tenant where the role is held. Default false (the historic same-scope lookup).

true applies to every role name; a list restricts it to those names. Prefer the list whenever tenants can assign roles themselves: with true, a tenant admin who can assign an arbitrary role name (say, a global platform-admin) gets that role's global permission set inside their tenant.


now? ​

> optional now?: () => number

Defined in: permissions/src/index.ts:359

Injectable clock (tests). Default Date.now.

Returns ​

number


onMissingPolicy? ​

> optional onMissingPolicy?: "error" | "rbac"

Defined in: permissions/src/index.ts:367

What to do when can() is given a resource but no policy check matches resource:action. 'error' (default) throws MissingPolicyError — passing a resource is an explicit ABAC intent, and silently answering from RBAC means the ownership rule never runs. 'rbac' restores the historic fall-through for apps that pass resources opportunistically.


policies? ​

> optional policies?: Policy<never>[]

Defined in: permissions/src/index.ts:353


readLegacyGlobalScope? ​

> optional readLegacyGlobalScope?: boolean

Defined in: permissions/src/index.ts:376

Also read grants stored under the historic global scope 'global' (LEGACY_GLOBAL_SCOPE) as global. Default false. A transition aid only: while it is on, anything that writes grants under a tenant id of 'global' (e.g. teams mirroring a membership) writes global grants — so reserve that tenant id in your tenant registry, then migrate the rows to GLOBAL_SCOPE and turn this off.


roleCatalog? ​

> optional roleCatalog?: Readonly<Record<string, readonly string[]>>

Defined in: permissions/src/index.ts:397

Code-defined role → permissions catalogue, valid in every scope: a role held in a scope grants its catalogue permissions in that scope (never elsewhere), in addition to whatever the store grants the role there.

ts
roleCatalog: { owner: ['*'], admin: ['projects:*', 'members:invite'], member: ['projects:read'] }

Pairs with @basaltkit/teams, which assigns roles per tenant (assignRole(user, role, tenantId)): the tenant owner gets '*' in their tenant without copying the catalogue into every tenant. Snapshotted at construction; malformed entries throw a TypeError.


scope? ​

> optional scope?: () => string

Defined in: permissions/src/index.ts:352

Current scope. Default: ctx().tenant.id, falling back to GLOBAL_SCOPE.

Returns ​

string


store ​

> store: AccessStore

Defined in: permissions/src/index.ts:344


superAdmin? ​

> optional superAdmin?: (user) => boolean | Promise<boolean>

Defined in: permissions/src/index.ts:350

Short-circuits every check — Laravel's Gate::before. Also consulted when a listing (tools/list) asks which meta.can routes a caller could pass, so keep it free of side effects.

Parameters ​

user ​

PolicyUser

Returns ​

boolean | Promise<boolean>


temporaryGrants? ​

> optional temporaryGrants?: TemporaryGrantStore

Defined in: permissions/src/index.ts:355

Optional store enabling time-boxed grants via grantTemporarily().


tenancyActive? ​

> optional tenancyActive?: () => boolean

Defined in: permissions/src/index.ts:426

Whether the app is multi-tenant. permissionsPlugin wires this to the 'tenancy:active' marker tenancyPlugin registers; a Gate built by hand defaults to false (single-tenant). Only decides whether a scope-less write outside a tenant fails closed (see allowGlobalWrites).

Returns ​

boolean

Released under the MIT License.