basalt / permissions/src / AccessGrant
Type Alias: AccessGrant
> AccessGrant = { permission: string; scope: string; source: "direct"; } | { permission: string; role: string; scope: string; source: "role"; } | { expiresAt: number; id: string; permission: string; scope: string; source: "temporary"; } | { expiresAt?: number; fromUserId: string; id: string; permission: string; scope: string; source: "delegation"; } | { permission: "*"; source: "super-admin"; }
Defined in: permissions/src/index.ts:950
One permission in an AccessReport and where it comes from. scope is where the grant lives — the tenant id or GLOBAL_SCOPE.
Union Members
Type Literal
{ permission: string; scope: string; source: "direct"; }
Type Literal
{ permission: string; role: string; scope: string; source: "role"; }
Type Literal
{ expiresAt: number; id: string; permission: string; scope: string; source: "temporary"; }
A time-boxed grant (grantTemporarily()); inert after expiresAt (epoch ms).
Type Literal
{ expiresAt?: number; fromUserId: string; id: string; permission: string; scope: string; source: "delegation"; }
Lent by fromUserId (delegate()), already narrowed to what the delegator holds. expiresAt is the earlier of the delegation's deadline and that of the delegator's temporary grant it rests on; absent when open-ended.
Type Literal
{ permission: "*"; source: "super-admin"; }
The superAdmin bypass: every check passes.