CaslAuthorizer
Αυτό το περιεχόμενο δεν είναι ακόμη διαθέσιμο στη γλώσσα σου.
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:42
Entity- and field-level authorization against the request ability.
Uses the constructor ability, else the ambient ability stored by
CaslBehavior. A missing ability denies.
Example
Section titled “Example”const user = await this.users.findById(command.id);this.authorizer.authorize('update', user, ['username']);user.update(command.changes);
return this.authorizer.project('read', user, { id: user.id, email: user.email });Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new CaslAuthorizer(
ability?):CaslAuthorizer
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:43
Parameters
Section titled “Parameters”ability?
Section titled “ability?”Returns
Section titled “Returns”CaslAuthorizer
Methods
Section titled “Methods”authorize()
Section titled “authorize()”authorize(
action,subject,fields?):void
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:65
Throws UnauthorizedActionException unless action is permitted on
subject and every listed field. Fields use CASL field matching, as in
can.
Parameters
Section titled “Parameters”action
Section titled “action”string
subject
Section titled “subject”string | object
fields?
Section titled “fields?”readonly string[]
Returns
Section titled “Returns”void
can(
action,subject,field?):boolean
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:51
True when action is permitted on subject (and field, when given).
Field checks use CASL field matching, unlike project: a grant of
fields: ['profile'] does not permit 'profile.secret'; grant
'profile.*' or 'profile.**' to cover nested fields.
Parameters
Section titled “Parameters”action
Section titled “action”string
subject
Section titled “subject”string | object
field?
Section titled “field?”string
Returns
Section titled “Returns”boolean
dependsOnEntity()
Section titled “dependsOnEntity()”dependsOnEntity(
action,subject):boolean
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:123
Whether the decision for action on subject depends on the entity’s
attributes: true when a rule for that subject, all or manage carries
conditions, and when no ability is present. A handler that is about to
decide against a cached or otherwise possibly stale entity reads a fresh
one instead.
Parameters
Section titled “Parameters”action
Section titled “action”string
The action about to be checked, such as 'read'.
subject
Section titled “subject”string
The subject type, such as 'User'.
Returns
Section titled “Returns”boolean
Example
Section titled “Example”const refresh = this.authorizer.dependsOnEntity('read', 'User');const user = await this.users.findById(query.id, { refresh });return user && this.authorizer.project('read', user, user.toJSON());project()
Section titled “project()”project<
TCandidate>(action,subject,candidate):Projected<TCandidate>
Defined in: packages/pipeline-casl/src/helpers/authorizer.ts:87
Asserts action on subject, then returns the candidate fields the
ability permits. Conditions use subject, never candidate.
Type Parameters
Section titled “Type Parameters”TCandidate
Section titled “TCandidate”TCandidate extends object
Parameters
Section titled “Parameters”action
Section titled “action”string
subject
Section titled “subject”string | object
candidate
Section titled “candidate”TCandidate
Returns
Section titled “Returns”Projected<TCandidate>