Skip to content

basalt / permissions/src / AccessGrant

Type Alias: AccessGrant ​

> AccessGrant = { permission: string; scope: string; source: "direct"; } | { permission: string; role: string; scope: string; source: "role"; } | { expiresAt: number; id: string; permission: string; scope: string; source: "temporary"; } | { expiresAt?: number; fromUserId: string; id: string; permission: string; scope: string; source: "delegation"; } | { permission: "*"; source: "super-admin"; }

Defined in: permissions/src/index.ts:950

One permission in an AccessReport and where it comes from. scope is where the grant lives — the tenant id or GLOBAL_SCOPE.

Union Members ​

Type Literal ​

{ permission: string; scope: string; source: "direct"; }


Type Literal ​

{ permission: string; role: string; scope: string; source: "role"; }


Type Literal ​

{ expiresAt: number; id: string; permission: string; scope: string; source: "temporary"; }

A time-boxed grant (grantTemporarily()); inert after expiresAt (epoch ms).


Type Literal ​

{ expiresAt?: number; fromUserId: string; id: string; permission: string; scope: string; source: "delegation"; }

Lent by fromUserId (delegate()), already narrowed to what the delegator holds. expiresAt is the earlier of the delegation's deadline and that of the delegator's temporary grant it rests on; absent when open-ended.


Type Literal ​

{ permission: "*"; source: "super-admin"; }

The superAdmin bypass: every check passes.

Released under the MIT License.