basalt / permissions/src / PermissionsPluginOptions
Type Alias: PermissionsPluginOptions
> PermissionsPluginOptions = GateOptions & object
Defined in: permissions/src/index.ts:1107
Type Declaration
audiences?
> optional audiences?: Record<string, AudienceRule>
Surfaces, keyed by name. Omit it and nothing changes.
A caller holding at least one role no rule names is unconfined and reaches everything their permissions allow. A caller whose every role is confined may reach only routes whose meta.audience one of their rules allows — and a route that declares no audience is reachable by none of them.
That default is the point. The obvious design is to mark the internal routes, and it fails the first time somebody adds a route without thinking about portals: the leak this exists to prevent was exactly that, an authenticated client receiving 200 on an internal listing. Marking the small, deliberate surface a restricted role may reach is a list somebody maintains; marking every route they may not is a list somebody forgets.
resourceNotFound?
> optional resourceNotFound?: CanResourceNotFound
What the meta.can guard answers when a resource requirement's loader finds nothing (null/undefined): 'not-found' (default) throws ResourceNotFoundError (404); 'deny' refuses like a failed check (403 PERMISSION_DENIED, audited), so a caller cannot probe which ids exist. A requirement's own notFound overrides it.