Skip to content

buildAbility

buildAbility(rules, principal?): AppAbility

Defined in: packages/pipeline-casl/src/helpers/ability.ts:29

Builds the ability for one caller. Every direct rule precedes every inverted rule (stable within each group), so a deny from any source wins over an allow. Placeholders resolve against principal; a missing attribute throws.

readonly (string | Capability)[]

CaslPrincipal

AppAbility

For a malformed capability or an allow rule with an empty fields list.

const ability = buildAbility(
['User|read|{"department":"${user.department}"}', '!User|read|*|email'],
{ id: 'u-1', department: 'engineering' },
);