Skip to content

CaslAuthorizer

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:42

Entity- and field-level authorization against the request ability.

Uses the constructor ability, else the ambient ability stored by CaslBehavior. A missing ability denies.

const user = await this.users.findById(command.id);
this.authorizer.authorize('update', user, ['username']);
user.update(command.changes);
return this.authorizer.project('read', user, { id: user.id, email: user.email });

new CaslAuthorizer(ability?): CaslAuthorizer

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:43

AppAbility

CaslAuthorizer

authorize(action, subject, fields?): void

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:65

Throws UnauthorizedActionException unless action is permitted on subject and every listed field. Fields use CASL field matching, as in can.

string

string | object

readonly string[]

void


can(action, subject, field?): boolean

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:51

True when action is permitted on subject (and field, when given). Field checks use CASL field matching, unlike project: a grant of fields: ['profile'] does not permit 'profile.secret'; grant 'profile.*' or 'profile.**' to cover nested fields.

string

string | object

string

boolean


dependsOnEntity(action, subject): boolean

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:123

Whether the decision for action on subject depends on the entity’s attributes: true when a rule for that subject, all or manage carries conditions, and when no ability is present. A handler that is about to decide against a cached or otherwise possibly stale entity reads a fresh one instead.

string

The action about to be checked, such as 'read'.

string

The subject type, such as 'User'.

boolean

const refresh = this.authorizer.dependsOnEntity('read', 'User');
const user = await this.users.findById(query.id, { refresh });
return user && this.authorizer.project('read', user, user.toJSON());

project<TCandidate>(action, subject, candidate): Projected<TCandidate>

Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:87

Asserts action on subject, then returns the candidate fields the ability permits. Conditions use subject, never candidate.

TCandidate extends object

string

string | object

TCandidate

Projected<TCandidate>