Skip to content

@nestarc/rbac ​

Classes ​

InMemoryRbacStorage ​

Defined in: src/adapters/in-memory-rbac.storage.ts:172

Additive 0.2.x capability for indexed role-id lookups. Implement this on custom adapters before the legacy full-list fallback is removed in 0.3 or later.

Implements ​

Constructors ​

Constructor ​
ts
new InMemoryRbacStorage(): InMemoryRbacStorage;
Returns ​

InMemoryRbacStorage

Properties ​

mutationResults ​
ts
readonly mutationResults: RbacStorageMutationCapability;

Defined in: src/adapters/in-memory-rbac.storage.ts:178

Additive 0.2.x capability for outcome-aware writes. Custom adapters that omit it use the deprecated result-less best-effort event fallback.

Implementation of ​

RbacStorage.mutationResults

Methods ​

assignRole() ​
ts
assignRole(input): Promise<RbacRoleBinding>;

Defined in: src/adapters/in-memory-rbac.storage.ts:410

Parameters ​
ParameterType
inputAssignRoleStorageInput
Returns ​

Promise<RbacRoleBinding>

Implementation of ​

RbacStorage.assignRole

deleteRole() ​
ts
deleteRole(input): Promise<void>;

Defined in: src/adapters/in-memory-rbac.storage.ts:369

Parameters ​
ParameterType
inputDeleteRoleInput
Returns ​

Promise<void>

Implementation of ​

RbacStorage.deleteRole

findRole() ​
ts
findRole(input): Promise<RbacRole | null>;

Defined in: src/adapters/in-memory-rbac.storage.ts:264

Parameters ​
ParameterType
inputFindRoleInput
Returns ​

Promise<RbacRole | null>

Implementation of ​

RbacStorage.findRole

findRoleById() ​
ts
findRoleById(input): Promise<RbacRole | null>;

Defined in: src/adapters/in-memory-rbac.storage.ts:274

Optional indexed lookup used by strict assignment validation. Adapters that omit it retain the deprecated 0.2.x listRoles({}) compatibility fallback.

Parameters ​
ParameterType
inputFindRoleByIdInput
Returns ​

Promise<RbacRole | null>

Implementation of ​

RbacStorageRoleLookupCapability.findRoleById

grantPermission() ​
ts
grantPermission(input): Promise<void>;

Defined in: src/adapters/in-memory-rbac.storage.ts:381

Parameters ​
ParameterType
inputGrantPermissionInput
Returns ​

Promise<void>

Implementation of ​

RbacStorage.grantPermission

listBindings() ​
ts
listBindings(input): Promise<RbacRoleBinding[]>;

Defined in: src/adapters/in-memory-rbac.storage.ts:479

Parameters ​
ParameterType
inputListBindingsInput
Returns ​

Promise<RbacRoleBinding[]>

Implementation of ​

RbacStorage.listBindings

listEffectivePermissions() ​
ts
listEffectivePermissions(input): Promise<RbacEffectivePermission[]>;

Defined in: src/adapters/in-memory-rbac.storage.ts:498

Parameters ​
ParameterType
inputListEffectiveRolesInput
Returns ​

Promise<RbacEffectivePermission[]>

Implementation of ​

RbacStorage.listEffectivePermissions

listEffectiveRoles() ​
ts
listEffectiveRoles(input): Promise<RbacEffectiveRole[]>;

Defined in: src/adapters/in-memory-rbac.storage.ts:494

Parameters ​
ParameterType
inputListEffectiveRolesInput
Returns ​

Promise<RbacEffectiveRole[]>

Implementation of ​

RbacStorage.listEffectiveRoles

listRolePermissions() ​
ts
listRolePermissions(input): Promise<string[]>;

Defined in: src/adapters/in-memory-rbac.storage.ts:405

Parameters ​
ParameterType
inputListRolePermissionsInput
Returns ​

Promise<string[]>

Implementation of ​

RbacStorage.listRolePermissions

listRoles() ​
ts
listRoles(input): Promise<RbacRole[]>;

Defined in: src/adapters/in-memory-rbac.storage.ts:281

Parameters ​
ParameterType
inputListRolesInput
Returns ​

Promise<RbacRole[]>

Implementation of ​

RbacStorage.listRoles

revokePermission() ​
ts
revokePermission(input): Promise<void>;

Defined in: src/adapters/in-memory-rbac.storage.ts:394

Parameters ​
ParameterType
inputRevokePermissionInput
Returns ​

Promise<void>

Implementation of ​

RbacStorage.revokePermission

revokeRole() ​
ts
revokeRole(input): Promise<void>;

Defined in: src/adapters/in-memory-rbac.storage.ts:469

Parameters ​
ParameterType
inputRevokeRoleInput
Returns ​

Promise<void>

Implementation of ​

RbacStorage.revokeRole

upsertRole() ​
ts
upsertRole(input): Promise<RbacRole>;

Defined in: src/adapters/in-memory-rbac.storage.ts:291

Parameters ​
ParameterType
inputUpsertRoleInput
Returns ​

Promise<RbacRole>

Implementation of ​

RbacStorage.upsertRole


NoopRbacAuditLogger ​

Defined in: src/audit/noop-rbac-audit.logger.ts:3

Implements ​

Constructors ​

Constructor ​
ts
new NoopRbacAuditLogger(): NoopRbacAuditLogger;
Returns ​

NoopRbacAuditLogger

Methods ​

log() ​
ts
log(event): void;

Defined in: src/audit/noop-rbac-audit.logger.ts:4

Parameters ​
ParameterType
eventRbacAuditEvent
Returns ​

void

Implementation of ​

RbacAuditLogger.log


RbacBindingNotFoundError ​

Defined in: src/errors/rbac.error.ts:97

Deprecated ​

No package operation throws this error. It remains constructible and HTTP-mappable until a separate breaking release.

Extends ​

Constructors ​

Constructor ​
ts
new RbacBindingNotFoundError(details?, options?): RbacBindingNotFoundError;

Defined in: src/errors/rbac.error.ts:98

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacBindingNotFoundError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacConfigError ​

Defined in: src/errors/rbac.error.ts:38

Extends ​

Constructors ​

Constructor ​
ts
new RbacConfigError(details?, options?): RbacConfigError;

Defined in: src/errors/rbac.error.ts:39

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacConfigError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacError ​

Defined in: src/errors/rbac.error.ts:21

Extends ​

  • Error

Extended by ​

Constructors ​

Constructor ​
ts
new RbacError(
   message,
   code,
   status?,
   options?): RbacError;

Defined in: src/errors/rbac.error.ts:22

Parameters ​
ParameterType
messagestring
codeRbacErrorCode
status?number
options?RbacErrorOptions
Returns ​

RbacError

Overrides ​
ts
Error.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​
ts
Error.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​
ts
Error.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​
ts
Error.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​
ts
Error.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​
ts
Error.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​
ts
Error.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​
ts
Error.prepareStackTrace

RbacGuard ​

Defined in: src/rbac.guard.ts:20

Nest HTTP authorization guard. Other transports should call RbacService from their adapter.

Implements ​

  • CanActivate

Constructors ​

Constructor ​
ts
new RbacGuard(
   reflector,
   rbac,
   options,
   moduleRef): RbacGuard;

Defined in: src/rbac.guard.ts:25

Parameters ​
ParameterType
reflectorReflector
rbacRbacService
optionsRbacModuleOptions
moduleRefModuleRef
Returns ​

RbacGuard

Methods ​

canActivate() ​
ts
canActivate(context): Promise<boolean>;

Defined in: src/rbac.guard.ts:41

Parameters ​
ParameterTypeDescription
contextExecutionContextCurrent execution context. Provides access to details about the current request pipeline.
Returns ​

Promise<boolean>

Value indicating whether or not the current request is allowed to proceed.

Implementation of ​
ts
CanActivate.canActivate

RbacModule ​

Defined in: src/rbac.module.ts:16

Constructors ​

Constructor ​
ts
new RbacModule(): RbacModule;
Returns ​

RbacModule

Methods ​

forRoot() ​
ts
static forRoot(options): DynamicModule;

Defined in: src/rbac.module.ts:17

Parameters ​
ParameterType
optionsRbacModuleOptions
Returns ​

DynamicModule

forRootAsync() ​
ts
static forRootAsync(options): DynamicModule;

Defined in: src/rbac.module.ts:30

Parameters ​
ParameterType
optionsRbacModuleAsyncOptions
Returns ​

DynamicModule


RbacPermissionDeniedError ​

Defined in: src/errors/rbac.error.ts:65

Extends ​

Constructors ​

Constructor ​
ts
new RbacPermissionDeniedError(details?, options?): RbacPermissionDeniedError;

Defined in: src/errors/rbac.error.ts:66

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacPermissionDeniedError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacPermissionNotFoundError ​

Defined in: src/errors/rbac.error.ts:84

Deprecated ​

No package operation throws this error. It remains constructible and HTTP-mappable until a separate breaking release.

Extends ​

Constructors ​

Constructor ​
ts
new RbacPermissionNotFoundError(details?, options?): RbacPermissionNotFoundError;

Defined in: src/errors/rbac.error.ts:85

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacPermissionNotFoundError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacResourceMissingError ​

Defined in: src/errors/rbac.error.ts:59

Extends ​

Constructors ​

Constructor ​
ts
new RbacResourceMissingError(details?, options?): RbacResourceMissingError;

Defined in: src/errors/rbac.error.ts:60

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacResourceMissingError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacRoleNotFoundError ​

Defined in: src/errors/rbac.error.ts:74

Extends ​

Constructors ​

Constructor ​
ts
new RbacRoleNotFoundError(details?, options?): RbacRoleNotFoundError;

Defined in: src/errors/rbac.error.ts:75

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacRoleNotFoundError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacService ​

Defined in: src/rbac.service.ts:52

Constructors ​

Constructor ​
ts
new RbacService(options): RbacService;

Defined in: src/rbac.service.ts:57

Parameters ​
ParameterType
optionsRbacModuleOptions
Returns ​

RbacService

Methods ​

assertCan() ​
ts
assertCan(input): Promise<void>;

Defined in: src/rbac.service.ts:98

Parameters ​
ParameterType
inputRbacCanInput
Returns ​

Promise<void>

assignRole() ​
ts
assignRole(input): Promise<RbacRoleBinding>;

Defined in: src/rbac.service.ts:244

Parameters ​
ParameterType
inputAssignRoleInput
Returns ​

Promise<RbacRoleBinding>

can() ​
ts
can(input): Promise<RbacServiceDecision>;

Defined in: src/rbac.service.ts:63

Parameters ​
ParameterType
inputRbacCanInput
Returns ​

Promise<RbacServiceDecision>

createRole() ​
ts
createRole(input): Promise<RbacRole>;

Defined in: src/rbac.service.ts:106

Parameters ​
ParameterType
inputCreateRoleInput
Returns ​

Promise<RbacRole>

deleteRole() ​
ts
deleteRole(input): Promise<void>;

Defined in: src/rbac.service.ts:171

Parameters ​
ParameterType
inputDeleteRoleInput
Returns ​

Promise<void>

grantPermission() ​
ts
grantPermission(input): Promise<void>;

Defined in: src/rbac.service.ts:190

Parameters ​
ParameterType
inputGrantPermissionInput
Returns ​

Promise<void>

listBindings() ​
ts
listBindings(input): Promise<RbacRoleBinding[]>;

Defined in: src/rbac.service.ts:335

Parameters ​
ParameterType
inputListBindingsInput
Returns ​

Promise<RbacRoleBinding[]>

listPermissions() ​
ts
listPermissions(input): Promise<string[]>;

Defined in: src/rbac.service.ts:329

Parameters ​
ParameterType
inputListPermissionsInput
Returns ​

Promise<string[]>

listRoles() ​
ts
listRoles(input): Promise<RbacRole[]>;

Defined in: src/rbac.service.ts:322

Parameters ​
ParameterType
inputListRolesInput
Returns ​

Promise<RbacRole[]>

revokePermission() ​
ts
revokePermission(input): Promise<void>;

Defined in: src/rbac.service.ts:217

Parameters ​
ParameterType
inputRevokePermissionInput
Returns ​

Promise<void>

revokeRole() ​
ts
revokeRole(input): Promise<void>;

Defined in: src/rbac.service.ts:299

Parameters ​
ParameterType
inputRevokeRoleInput
Returns ​

Promise<void>

updateRole() ​
ts
updateRole(input): Promise<RbacRole>;

Defined in: src/rbac.service.ts:139

Parameters ​
ParameterType
inputUpdateRoleInput
Returns ​

Promise<RbacRole>


RbacStorageError ​

Defined in: src/errors/rbac.error.ts:103

Extends ​

Constructors ​

Constructor ​
ts
new RbacStorageError(details?, options?): RbacStorageError;

Defined in: src/errors/rbac.error.ts:104

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacStorageError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacSubjectMissingError ​

Defined in: src/errors/rbac.error.ts:47

Extends ​

Constructors ​

Constructor ​
ts
new RbacSubjectMissingError(details?, options?): RbacSubjectMissingError;

Defined in: src/errors/rbac.error.ts:48

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacSubjectMissingError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace


RbacTenantMissingError ​

Defined in: src/errors/rbac.error.ts:53

Extends ​

Constructors ​

Constructor ​
ts
new RbacTenantMissingError(details?, options?): RbacTenantMissingError;

Defined in: src/errors/rbac.error.ts:54

Parameters ​
ParameterType
details?Record<string, unknown>
options?RbacErrorCauseOptions
Returns ​

RbacTenantMissingError

Overrides ​

RbacError.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​

RbacError.cause

code ​
ts
readonly code: RbacErrorCode;

Defined in: src/errors/rbac.error.ts:24

Inherited from ​

RbacError.code

details? ​
ts
readonly optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:35

Inherited from ​

RbacError.details

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​

RbacError.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​

RbacError.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​

RbacError.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​

RbacError.stackTraceLimit

status? ​
ts
readonly optional status?: number;

Defined in: src/errors/rbac.error.ts:25

Inherited from ​

RbacError.status

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​

RbacError.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​

RbacError.prepareStackTrace

Interfaces ​

AssignRoleBaseInput ​

Defined in: src/interfaces/binding.ts:17

Extended by ​

Properties ​

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/interfaces/binding.ts:21

metadata? ​
ts
optional metadata?: Record<string, unknown>;

Defined in: src/interfaces/binding.ts:22

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/binding.ts:20

subject ​
ts
subject: RbacSubject;

Defined in: src/interfaces/binding.ts:19

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/binding.ts:18


AssignRoleStorageInput ​

Defined in: src/interfaces/binding.ts:37

Extends ​

Properties ​

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/interfaces/binding.ts:21

Inherited from ​

AssignRoleBaseInput.expiresAt

metadata? ​
ts
optional metadata?: Record<string, unknown>;

Defined in: src/interfaces/binding.ts:22

Inherited from ​

AssignRoleBaseInput.metadata

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/binding.ts:20

Inherited from ​

AssignRoleBaseInput.resource

roleId ​
ts
roleId: string;

Defined in: src/interfaces/binding.ts:38

subject ​
ts
subject: RbacSubject;

Defined in: src/interfaces/binding.ts:19

Inherited from ​

AssignRoleBaseInput.subject

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/binding.ts:18

Inherited from ​

AssignRoleBaseInput.tenantId


CreateRoleInput ​

Defined in: src/interfaces/role.ts:11

Properties ​

description? ​
ts
optional description?: string;

Defined in: src/interfaces/role.ts:15

isSystem? ​
ts
optional isSystem?: boolean;

Defined in: src/interfaces/role.ts:16

key ​
ts
key: string;

Defined in: src/interfaces/role.ts:13

name? ​
ts
optional name?: string;

Defined in: src/interfaces/role.ts:14

permissions ​
ts
permissions: string[];

Defined in: src/interfaces/role.ts:17

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/role.ts:12


DefineRbacPermissionsOptions ​

Defined in: src/permissions/define-rbac-permissions.ts:9

Properties ​

validateDuplicates? ​
ts
optional validateDuplicates?: boolean;

Defined in: src/permissions/define-rbac-permissions.ts:10


DeleteRoleInput ​

Defined in: src/interfaces/role.ts:30

Properties ​

roleId ​
ts
roleId: string;

Defined in: src/interfaces/role.ts:31


FindRoleByIdInput ​

Defined in: src/interfaces/role.ts:43

Properties ​

roleId ​
ts
roleId: string;

Defined in: src/interfaces/role.ts:44


FindRoleInput ​

Defined in: src/interfaces/role.ts:38

Properties ​

key ​
ts
key: string;

Defined in: src/interfaces/role.ts:40

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/role.ts:39


GrantPermissionInput ​

Defined in: src/interfaces/permission.ts:1

Properties ​

permission ​
ts
permission: string;

Defined in: src/interfaces/permission.ts:3

roleId ​
ts
roleId: string;

Defined in: src/interfaces/permission.ts:2


ListBindingsInput ​

Defined in: src/interfaces/binding.ts:48

Properties ​

subject ​
ts
subject: RbacSubject;

Defined in: src/interfaces/binding.ts:50

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/binding.ts:49


ListEffectiveRolesInput ​

Defined in: src/interfaces/storage.ts:25

Properties ​

now? ​
ts
optional now?: Date;

Defined in: src/interfaces/storage.ts:29

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/storage.ts:28

subject ​
ts
subject: RbacSubject;

Defined in: src/interfaces/storage.ts:26

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/storage.ts:27


ListPermissionsInput ​

Defined in: src/interfaces/permission.ts:11

Properties ​

roleId ​
ts
roleId: string;

Defined in: src/interfaces/permission.ts:12


ListRolePermissionsInput ​

Defined in: src/interfaces/permission.ts:15

Properties ​

roleId ​
ts
roleId: string;

Defined in: src/interfaces/permission.ts:16


ListRolesInput ​

Defined in: src/interfaces/role.ts:34

Properties ​

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/role.ts:35


RbacAuditEvent ​

Defined in: src/interfaces/audit.ts:1

Properties ​

metadata? ​
ts
optional metadata?: Record<string, unknown>;

Defined in: src/interfaces/audit.ts:15

subjectId? ​
ts
optional subjectId?: string;

Defined in: src/interfaces/audit.ts:14

subjectType? ​
ts
optional subjectType?: string;

Defined in: src/interfaces/audit.ts:13

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/audit.ts:12

type ​
ts
type:
  | "rbac.role.created"
  | "rbac.role.updated"
  | "rbac.role.deleted"
  | "rbac.permission.granted"
  | "rbac.permission.revoked"
  | "rbac.role.assigned"
  | "rbac.role.revoked"
  | "rbac.permission.allowed"
  | "rbac.permission.denied";

Defined in: src/interfaces/audit.ts:2


RbacAuditLogger ​

Defined in: src/interfaces/audit.ts:18

Methods ​

log() ​
ts
log(event): void | Promise<void>;

Defined in: src/interfaces/audit.ts:19

Parameters ​
ParameterType
eventRbacAuditEvent
Returns ​

void | Promise<void>


RbacCanBaseInput ​

Defined in: src/interfaces/decision.ts:7

Properties ​

now? ​
ts
optional now?: Date;

Defined in: src/interfaces/decision.ts:12

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/decision.ts:11

subject? ​
ts
optional subject?: RbacSubject;

Defined in: src/interfaces/decision.ts:8

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/decision.ts:9

tenantMode? ​
ts
optional tenantMode?: RbacTenantMode;

Defined in: src/interfaces/decision.ts:10


RbacDecision ​

Defined in: src/interfaces/decision.ts:45

Compatibility envelope for decisions created by applications, tests, or older package versions. RbacService.can() returns the narrower RbacServiceDecision contract.

Properties ​

allowed ​
ts
allowed: boolean;

Defined in: src/interfaces/decision.ts:46

details? ​
ts
optional details?: RbacDecisionDetails;

Defined in: src/interfaces/decision.ts:57

matchedPermissions? ​
ts
optional matchedPermissions?: string[];

Defined in: src/interfaces/decision.ts:55

matchedRoleKeys? ​
ts
optional matchedRoleKeys?: string[];

Defined in: src/interfaces/decision.ts:54

mode? ​
ts
optional mode?: RbacRequirementMode;

Defined in: src/interfaces/decision.ts:53

permission? ​
ts
optional permission?: string;

Defined in: src/interfaces/decision.ts:50

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/decision.ts:51

reason ​
ts
reason: RbacDecisionReason;

Defined in: src/interfaces/decision.ts:47

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/decision.ts:56

roleKey? ​
ts
optional roleKey?: string;

Defined in: src/interfaces/decision.ts:52

subject? ​
ts
optional subject?: RbacSubject;

Defined in: src/interfaces/decision.ts:48

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/decision.ts:49


RbacDecisionDetails ​

Defined in: src/interfaces/decision.ts:66

Properties ​

evaluationPath? ​
ts
optional evaluationPath?: RbacEvaluationStep[];

Defined in: src/interfaces/decision.ts:70

matched? ​
ts
optional matched?: RbacDecisionMatchDetails;

Defined in: src/interfaces/decision.ts:68

missing? ​
ts
optional missing?: RbacDecisionMissingDetails;

Defined in: src/interfaces/decision.ts:69

requirement? ​
ts
optional requirement?: RbacDecisionRequirementDetails;

Defined in: src/interfaces/decision.ts:67

safeMessage? ​
ts
optional safeMessage?: string;

Defined in: src/interfaces/decision.ts:71


RbacDecisionMatchDetails ​

Defined in: src/interfaces/decision.ts:115

Properties ​

bindingIds? ​
ts
optional bindingIds?: string[];

Defined in: src/interfaces/decision.ts:121

Deprecated ​

RbacService has never populated this compatibility field.

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/decision.ts:119

roleIds? ​
ts
optional roleIds?: string[];

Defined in: src/interfaces/decision.ts:117

Deprecated ​

RbacService has never populated this compatibility field.

roleKeys? ​
ts
optional roleKeys?: string[];

Defined in: src/interfaces/decision.ts:118


RbacDecisionMissingDetails ​

Defined in: src/interfaces/decision.ts:124

Properties ​

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/decision.ts:129

resource? ​
ts
optional resource?: boolean;

Defined in: src/interfaces/decision.ts:128

Deprecated ​

RbacService reports resource failures before creating a decision.

roleKeys? ​
ts
optional roleKeys?: string[];

Defined in: src/interfaces/decision.ts:130

subject? ​
ts
optional subject?: boolean;

Defined in: src/interfaces/decision.ts:125

tenant? ​
ts
optional tenant?: boolean;

Defined in: src/interfaces/decision.ts:126


RbacDecisionRequirementDetails ​

Defined in: src/interfaces/decision.ts:108

Properties ​

mode? ​
ts
optional mode?: RbacRequirementMode;

Defined in: src/interfaces/decision.ts:112

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/decision.ts:110

roleKeys? ​
ts
optional roleKeys?: string[];

Defined in: src/interfaces/decision.ts:111

type ​
ts
type: "permission" | "role";

Defined in: src/interfaces/decision.ts:109


RbacEffectivePermission ​

Defined in: src/interfaces/storage.ts:47

Extends ​

Properties ​

bindingId ​
ts
bindingId: string;

Defined in: src/interfaces/storage.ts:37

Inherited from ​

RbacEffectiveRole.bindingId

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/interfaces/storage.ts:44

The record remains active when expiresAt is exactly equal to the query now.

Inherited from ​

RbacEffectiveRole.expiresAt

permission ​
ts
permission: string;

Defined in: src/interfaces/storage.ts:48

resourceId? ​
ts
optional resourceId?: string | null;

Defined in: src/interfaces/storage.ts:42

Inherited from ​

RbacEffectiveRole.resourceId

resourceType? ​
ts
optional resourceType?: string | null;

Defined in: src/interfaces/storage.ts:41

Resource scope is either an absent pair or two populated strings.

Inherited from ​

RbacEffectiveRole.resourceType

roleId ​
ts
roleId: string;

Defined in: src/interfaces/storage.ts:36

Inherited from ​

RbacEffectiveRole.roleId

roleKey ​
ts
roleKey: string;

Defined in: src/interfaces/storage.ts:35

Inherited from ​

RbacEffectiveRole.roleKey

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/storage.ts:39

null and undefined both identify a global effective record.

Inherited from ​

RbacEffectiveRole.tenantId


RbacEffectiveRole ​

Defined in: src/interfaces/storage.ts:34

Extended by ​

Properties ​

bindingId ​
ts
bindingId: string;

Defined in: src/interfaces/storage.ts:37

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/interfaces/storage.ts:44

The record remains active when expiresAt is exactly equal to the query now.

resourceId? ​
ts
optional resourceId?: string | null;

Defined in: src/interfaces/storage.ts:42

resourceType? ​
ts
optional resourceType?: string | null;

Defined in: src/interfaces/storage.ts:41

Resource scope is either an absent pair or two populated strings.

roleId ​
ts
roleId: string;

Defined in: src/interfaces/storage.ts:36

roleKey ​
ts
roleKey: string;

Defined in: src/interfaces/storage.ts:35

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/storage.ts:39

null and undefined both identify a global effective record.


RbacErrorCauseOptions ​

Defined in: src/errors/rbac.error.ts:17

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: src/errors/rbac.error.ts:18


RbacErrorOptions ​

Defined in: src/errors/rbac.error.ts:12

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: src/errors/rbac.error.ts:14

details? ​
ts
optional details?: Record<string, unknown>;

Defined in: src/errors/rbac.error.ts:13


RbacEvaluationStep ​

Defined in: src/interfaces/decision.ts:133

Properties ​

code ​
ts
code:
  | "subject_missing"
  | "tenant_missing"
  | "tenant_conflict"
  | "resource_missing"
  | "resource_mismatch"
  | "roles_loaded"
  | "permissions_loaded"
  | "permission_matched"
  | "permission_missing"
  | "role_matched"
  | "role_missing"
  | "storage_error";

Defined in: src/interfaces/decision.ts:134

outcome ​
ts
outcome: "allow" | "deny" | "skip" | "info";

Defined in: src/interfaces/decision.ts:147


RbacModuleAsyncOptions ​

Defined in: src/interfaces/module-options.ts:69

Properties ​

imports? ​
ts
optional imports?: (
  | Type<any>
  | DynamicModule
  | Promise<DynamicModule>
  | ForwardReference<any>)[];

Defined in: src/interfaces/module-options.ts:70

inject? ​
ts
optional inject?: (InjectionToken | OptionalFactoryDependency)[];

Defined in: src/interfaces/module-options.ts:71

useFactory ​
ts
useFactory: (...args) =>
  | RbacModuleOptions
| Promise<RbacModuleOptions>;

Defined in: src/interfaces/module-options.ts:72

Parameters ​
ParameterType
...argsany[]
Returns ​

| RbacModuleOptions | Promise<RbacModuleOptions>


RbacModuleOptions ​

Defined in: src/interfaces/module-options.ts:45

Properties ​

auditLogger? ​
ts
optional auditLogger?: RbacAuditLogger;

Defined in: src/interfaces/module-options.ts:49

changePublisher? ​
ts
optional changePublisher?: RbacPolicyChangePublisher;

Defined in: src/interfaces/module-options.ts:65

logAllowedDecisions? ​
ts
optional logAllowedDecisions?: boolean;

Defined in: src/interfaces/module-options.ts:63

now? ​
ts
optional now?: () => Date;

Defined in: src/interfaces/module-options.ts:66

Returns ​

Date

requireMetadata? ​
ts
optional requireMetadata?: boolean;

Defined in: src/interfaces/module-options.ts:50

storage ​
ts
storage: RbacStorage;

Defined in: src/interfaces/module-options.ts:46

storageErrors? ​
ts
optional storageErrors?: "deny" | "throw";

Defined in: src/interfaces/module-options.ts:62

subjectResolver? ​
ts
optional subjectResolver?: RbacSubjectResolver;

Defined in: src/interfaces/module-options.ts:47

tenant? ​
ts
optional tenant?: {
  allowGlobalRolesInTenant?: boolean;
  requiredByDefault?: boolean;
  resolverMode?: RbacTenantResolverMode;
};

Defined in: src/interfaces/module-options.ts:51

allowGlobalRolesInTenant? ​
ts
optional allowGlobalRolesInTenant?: boolean;
requiredByDefault? ​
ts
optional requiredByDefault?: boolean;
resolverMode? ​
ts
optional resolverMode?: RbacTenantResolverMode;

Controls whether a configured tenantResolver is authoritative. legacy-fallback preserves the pre-0.2.2 default-first behavior and is deprecated.

tenantResolver? ​
ts
optional tenantResolver?: RbacTenantResolver;

Defined in: src/interfaces/module-options.ts:48

writeValidation? ​
ts
optional writeValidation?: RbacWriteValidationOptions;

Defined in: src/interfaces/module-options.ts:64


RbacMutationResult ​

Defined in: src/interfaces/storage.ts:55

Type Parameters ​

Type ParameterDefault type
Tundefined

Properties ​

outcome ​
ts
outcome: RbacMutationOutcome;

Defined in: src/interfaces/storage.ts:56

reason? ​
ts
optional reason?: RbacMutationConflictReason;

Defined in: src/interfaces/storage.ts:58

value? ​
ts
optional value?: T;

Defined in: src/interfaces/storage.ts:57


RbacPermissionMetadata ​

Defined in: src/permissions/define-rbac-permissions.ts:3

Properties ​

description? ​
ts
optional description?: string;

Defined in: src/permissions/define-rbac-permissions.ts:4

owner? ​
ts
optional owner?: string;

Defined in: src/permissions/define-rbac-permissions.ts:5

risk? ​
ts
optional risk?: string;

Defined in: src/permissions/define-rbac-permissions.ts:6


RbacPolicyChangeEvent ​

Defined in: src/interfaces/module-options.ts:28

Properties ​

bindingId? ​
ts
optional bindingId?: string;

Defined in: src/interfaces/module-options.ts:37

metadata? ​
ts
optional metadata?: Record<string, unknown>;

Defined in: src/interfaces/module-options.ts:38

occurredAt ​
ts
occurredAt: Date;

Defined in: src/interfaces/module-options.ts:30

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/module-options.ts:35

resource? ​
ts
optional resource?: RbacResourceRef;

Defined in: src/interfaces/module-options.ts:36

roleId? ​
ts
optional roleId?: string;

Defined in: src/interfaces/module-options.ts:33

roleKey? ​
ts
optional roleKey?: string;

Defined in: src/interfaces/module-options.ts:34

subject? ​
ts
optional subject?: Pick<RbacSubject, "type" | "id">;

Defined in: src/interfaces/module-options.ts:32

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/module-options.ts:31

type ​
ts
type: RbacPolicyChangeEventType;

Defined in: src/interfaces/module-options.ts:29


RbacPolicyChangePublisher ​

Defined in: src/interfaces/module-options.ts:41

Methods ​

publish() ​
ts
publish(event): void | Promise<void>;

Defined in: src/interfaces/module-options.ts:42

Parameters ​
ParameterType
eventRbacPolicyChangeEvent
Returns ​

void | Promise<void>


RbacRequirementOptions ​

Defined in: src/interfaces/requirements.ts:31

Properties ​

mode? ​
ts
optional mode?: RbacRequirementMode;

Defined in: src/interfaces/requirements.ts:32

reason? ​
ts
optional reason?: string;

Defined in: src/interfaces/requirements.ts:45

Deprecated ​

Stored in decorator metadata for compatibility but never read, returned in a decision, or written to RBAC audit events. Use application-owned metadata for human-readable policy labels.

resource? ​
ts
optional resource?:
  | RbacBuiltInResourceDeclaration
  | RbacResourceResolverFn
  | RbacResourceResolverToken
  | RbacResourceResolverTokenRef;

Defined in: src/interfaces/requirements.ts:34

tenant? ​
ts
optional tenant?: "required" | "optional" | "none";

Defined in: src/interfaces/requirements.ts:33


RbacResourceRef ​

Defined in: src/interfaces/resource.ts:3

Properties ​

id ​
ts
id: string;

Defined in: src/interfaces/resource.ts:5

type ​
ts
type: string;

Defined in: src/interfaces/resource.ts:4


RbacResourceResolver ​

Defined in: src/interfaces/resource.ts:9

Injectable resource resolver used by the HTTP-only RbacGuard pipeline in 0.2.x.

Methods ​

resolve() ​
ts
resolve(context):
  | RbacResourceRef
  | Promise<RbacResourceRef | undefined>
  | undefined;

Defined in: src/interfaces/resource.ts:10

Parameters ​
ParameterType
contextExecutionContext
Returns ​

| RbacResourceRef | Promise<RbacResourceRef | undefined> | undefined


RbacResourceResolverTokenRef ​

Defined in: src/interfaces/resource.ts:17

Properties ​

resolverToken ​
ts
resolverToken: RbacResourceResolverToken;

Defined in: src/interfaces/resource.ts:18


RbacRole ​

Defined in: src/interfaces/role.ts:1

Properties ​

description? ​
ts
optional description?: string;

Defined in: src/interfaces/role.ts:5

id ​
ts
id: string;

Defined in: src/interfaces/role.ts:2

isSystem? ​
ts
optional isSystem?: boolean;

Defined in: src/interfaces/role.ts:7

key ​
ts
key: string;

Defined in: src/interfaces/role.ts:3

name? ​
ts
optional name?: string;

Defined in: src/interfaces/role.ts:4

permissions ​
ts
permissions: string[];

Defined in: src/interfaces/role.ts:8

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/role.ts:6


RbacRoleBinding ​

Defined in: src/interfaces/binding.ts:4

Properties ​

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/interfaces/binding.ts:12

id ​
ts
id: string;

Defined in: src/interfaces/binding.ts:5

metadata? ​
ts
optional metadata?: Record<string, unknown>;

Defined in: src/interfaces/binding.ts:14

resourceId? ​
ts
optional resourceId?: string | null;

Defined in: src/interfaces/binding.ts:11

resourceType? ​
ts
optional resourceType?: string | null;

Defined in: src/interfaces/binding.ts:10

revokedAt? ​
ts
optional revokedAt?: Date | null;

Defined in: src/interfaces/binding.ts:13

roleId ​
ts
roleId: string;

Defined in: src/interfaces/binding.ts:9

subjectId ​
ts
subjectId: string;

Defined in: src/interfaces/binding.ts:8

subjectType ​
ts
subjectType: string;

Defined in: src/interfaces/binding.ts:7

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/binding.ts:6


RbacServiceDecisionDetails ​

Defined in: src/interfaces/decision.ts:75

Details that are always attached to decisions produced by RbacService.can().

Extends ​

  • Omit<RbacDecisionDetails, "requirement" | "matched" | "missing" | "evaluationPath" | "safeMessage">

Properties ​

evaluationPath ​
ts
evaluationPath: RbacServiceEvaluationStep[];

Defined in: src/interfaces/decision.ts:82

matched? ​
ts
optional matched?: RbacServiceDecisionMatchDetails;

Defined in: src/interfaces/decision.ts:80

missing? ​
ts
optional missing?: RbacServiceDecisionMissingDetails;

Defined in: src/interfaces/decision.ts:81

requirement? ​
ts
optional requirement?: RbacServiceDecisionRequirementDetails;

Defined in: src/interfaces/decision.ts:79

safeMessage ​
ts
safeMessage: RbacServiceDecisionReason;

Defined in: src/interfaces/decision.ts:83


RbacServiceDecisionMatchDetails ​

Defined in: src/interfaces/decision.ts:97

Properties ​

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/decision.ts:99

roleKeys ​
ts
roleKeys: string[];

Defined in: src/interfaces/decision.ts:98


RbacStorage ​

Defined in: src/interfaces/storage.ts:83

Properties ​

findRoleById? ​
ts
readonly optional findRoleById?: (input) => Promise<RbacRole | null>;

Defined in: src/interfaces/storage.ts:93

Optional indexed lookup used by strict assignment validation. Adapters that omit it retain the deprecated 0.2.x listRoles({}) compatibility fallback.

Parameters ​
ParameterType
inputFindRoleByIdInput
Returns ​

Promise<RbacRole | null>

mutationResults? ​
ts
readonly optional mutationResults?: RbacStorageMutationCapability;

Defined in: src/interfaces/storage.ts:88

Additive 0.2.x capability for outcome-aware writes. Custom adapters that omit it use the deprecated result-less best-effort event fallback.

Methods ​

assignRole() ​
ts
assignRole(input): Promise<RbacRoleBinding>;

Defined in: src/interfaces/storage.ts:101

Parameters ​
ParameterType
inputAssignRoleStorageInput
Returns ​

Promise<RbacRoleBinding>

deleteRole() ​
ts
deleteRole(input): Promise<void>;

Defined in: src/interfaces/storage.ts:97

Parameters ​
ParameterType
inputDeleteRoleInput
Returns ​

Promise<void>

findRole() ​
ts
findRole(input): Promise<RbacRole | null>;

Defined in: src/interfaces/storage.ts:94

Parameters ​
ParameterType
inputFindRoleInput
Returns ​

Promise<RbacRole | null>

grantPermission() ​
ts
grantPermission(input): Promise<void>;

Defined in: src/interfaces/storage.ts:98

Parameters ​
ParameterType
inputGrantPermissionInput
Returns ​

Promise<void>

listBindings() ​
ts
listBindings(input): Promise<RbacRoleBinding[]>;

Defined in: src/interfaces/storage.ts:103

Parameters ​
ParameterType
inputListBindingsInput
Returns ​

Promise<RbacRoleBinding[]>

listEffectivePermissions() ​
ts
listEffectivePermissions(input): Promise<RbacEffectivePermission[]>;

Defined in: src/interfaces/storage.ts:105

Parameters ​
ParameterType
inputListEffectiveRolesInput
Returns ​

Promise<RbacEffectivePermission[]>

listEffectiveRoles() ​
ts
listEffectiveRoles(input): Promise<RbacEffectiveRole[]>;

Defined in: src/interfaces/storage.ts:104

Parameters ​
ParameterType
inputListEffectiveRolesInput
Returns ​

Promise<RbacEffectiveRole[]>

listRolePermissions() ​
ts
listRolePermissions(input): Promise<string[]>;

Defined in: src/interfaces/storage.ts:100

Parameters ​
ParameterType
inputListRolePermissionsInput
Returns ​

Promise<string[]>

listRoles() ​
ts
listRoles(input): Promise<RbacRole[]>;

Defined in: src/interfaces/storage.ts:95

Parameters ​
ParameterType
inputListRolesInput
Returns ​

Promise<RbacRole[]>

revokePermission() ​
ts
revokePermission(input): Promise<void>;

Defined in: src/interfaces/storage.ts:99

Parameters ​
ParameterType
inputRevokePermissionInput
Returns ​

Promise<void>

revokeRole() ​
ts
revokeRole(input): Promise<void>;

Defined in: src/interfaces/storage.ts:102

Parameters ​
ParameterType
inputRevokeRoleInput
Returns ​

Promise<void>

upsertRole() ​
ts
upsertRole(input): Promise<RbacRole>;

Defined in: src/interfaces/storage.ts:96

Parameters ​
ParameterType
inputUpsertRoleInput
Returns ​

Promise<RbacRole>


RbacStorageMutationCapability ​

Defined in: src/interfaces/storage.ts:65

Optional mutation-result protocol used to distinguish committed changes from idempotent no-ops without changing the legacy RbacStorage method signatures.

Methods ​

assignRole() ​
ts
assignRole(input): Promise<RbacMutationResult<RbacRoleBinding>>;

Defined in: src/interfaces/storage.ts:71

Parameters ​
ParameterType
inputAssignRoleStorageInput
Returns ​

Promise<RbacMutationResult<RbacRoleBinding>>

createRole() ​
ts
createRole(input): Promise<RbacMutationResult<RbacRole>>;

Defined in: src/interfaces/storage.ts:66

Parameters ​
ParameterType
inputCreateRoleInput
Returns ​

Promise<RbacMutationResult<RbacRole>>

deleteRole() ​
ts
deleteRole(input): Promise<RbacMutationResult<undefined>>;

Defined in: src/interfaces/storage.ts:68

Parameters ​
ParameterType
inputDeleteRoleInput
Returns ​

Promise<RbacMutationResult<undefined>>

grantPermission() ​
ts
grantPermission(input): Promise<RbacMutationResult<undefined>>;

Defined in: src/interfaces/storage.ts:69

Parameters ​
ParameterType
inputGrantPermissionInput
Returns ​

Promise<RbacMutationResult<undefined>>

revokePermission() ​
ts
revokePermission(input): Promise<RbacMutationResult<undefined>>;

Defined in: src/interfaces/storage.ts:70

Parameters ​
ParameterType
inputRevokePermissionInput
Returns ​

Promise<RbacMutationResult<undefined>>

revokeRole() ​
ts
revokeRole(input): Promise<RbacMutationResult<undefined>>;

Defined in: src/interfaces/storage.ts:72

Parameters ​
ParameterType
inputRevokeRoleInput
Returns ​

Promise<RbacMutationResult<undefined>>

updateRole() ​
ts
updateRole(input): Promise<RbacMutationResult<RbacRole>>;

Defined in: src/interfaces/storage.ts:67

Parameters ​
ParameterType
inputUpdateRoleInput
Returns ​

Promise<RbacMutationResult<RbacRole>>


RbacStorageRoleLookupCapability ​

Defined in: src/interfaces/storage.ts:79

Additive 0.2.x capability for indexed role-id lookups. Implement this on custom adapters before the legacy full-list fallback is removed in 0.3 or later.

Methods ​

findRoleById() ​
ts
findRoleById(input): Promise<RbacRole | null>;

Defined in: src/interfaces/storage.ts:80

Parameters ​
ParameterType
inputFindRoleByIdInput
Returns ​

Promise<RbacRole | null>


RbacStoredResourceRef ​

Defined in: src/utils/resource-matcher.ts:3

Properties ​

resourceId? ​
ts
optional resourceId?: string | null;

Defined in: src/utils/resource-matcher.ts:5

resourceType? ​
ts
optional resourceType?: string | null;

Defined in: src/utils/resource-matcher.ts:4


RbacSubject ​

Defined in: src/interfaces/subject.ts:3

Properties ​

attributes? ​
ts
optional attributes?: Record<string, unknown>;

Defined in: src/interfaces/subject.ts:8

displayName? ​
ts
optional displayName?: string;

Defined in: src/interfaces/subject.ts:7

id ​
ts
id: string;

Defined in: src/interfaces/subject.ts:5

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/subject.ts:6

type ​
ts
type: RbacSubjectType;

Defined in: src/interfaces/subject.ts:4


RbacWriteValidationOptions ​

Defined in: src/interfaces/module-options.ts:8

Properties ​

rejectGlobalRoleInTenantBinding? ​
ts
optional rejectGlobalRoleInTenantBinding?: boolean;

Defined in: src/interfaces/module-options.ts:11

rejectResourceWithoutTenant? ​
ts
optional rejectResourceWithoutTenant?: boolean;

Defined in: src/interfaces/module-options.ts:10

rejectTenantMismatch? ​
ts
optional rejectTenantMismatch?: boolean;

Defined in: src/interfaces/module-options.ts:9


RevokePermissionInput ​

Defined in: src/interfaces/permission.ts:6

Properties ​

permission ​
ts
permission: string;

Defined in: src/interfaces/permission.ts:8

roleId ​
ts
roleId: string;

Defined in: src/interfaces/permission.ts:7


RevokeRoleInput ​

Defined in: src/interfaces/binding.ts:41

Properties ​

bindingId ​
ts
bindingId: string;

Defined in: src/interfaces/binding.ts:42

revokedAt? ​
ts
optional revokedAt?: Date;

Defined in: src/interfaces/binding.ts:43


UpdateRoleInput ​

Defined in: src/interfaces/role.ts:20

Properties ​

description? ​
ts
optional description?: string;

Defined in: src/interfaces/role.ts:25

isSystem? ​
ts
optional isSystem?: boolean;

Defined in: src/interfaces/role.ts:26

key? ​
ts
optional key?: string;

Defined in: src/interfaces/role.ts:23

name? ​
ts
optional name?: string;

Defined in: src/interfaces/role.ts:24

permissions? ​
ts
optional permissions?: string[];

Defined in: src/interfaces/role.ts:27

roleId ​
ts
roleId: string;

Defined in: src/interfaces/role.ts:21

tenantId? ​
ts
optional tenantId?: string | null;

Defined in: src/interfaces/role.ts:22

Type Aliases ​

AssignRoleInput ​

ts
type AssignRoleInput = AssignRoleBaseInput &
  | {
  roleId: string;
  roleKey?: never;
}
  | {
  roleId?: never;
  roleKey: string;
};

Defined in: src/interfaces/binding.ts:25


ListBindingsStorageInput ​

ts
type ListBindingsStorageInput = ListBindingsInput;

Defined in: src/interfaces/binding.ts:53


ListEffectivePermissionsInput ​

ts
type ListEffectivePermissionsInput = ListEffectiveRolesInput;

Defined in: src/interfaces/storage.ts:32


RbacBuiltInResourceDeclaration ​

ts
type RbacBuiltInResourceDeclaration =
  | RbacParamResourceDeclaration
  | RbacHeaderResourceDeclaration
  | RbacQueryResourceDeclaration;

Defined in: src/interfaces/requirements.ts:26


RbacCanInput ​

ts
type RbacCanInput =
  | RbacPermissionCanInput
  | RbacRoleCanInput;

Defined in: src/interfaces/decision.ts:38


RbacDecisionReason ​

ts
type RbacDecisionReason =
  | RbacServiceDecisionReason
  | RbacLegacyDecisionReason;

Defined in: src/interfaces/decision.ts:192

Compatibility reason union. Prefer RbacServiceDecisionReason when consuming results returned by RbacService.can().


RbacErrorCode ​

ts
type RbacErrorCode =
  | "RBAC_CONFIG_ERROR"
  | "RBAC_SUBJECT_MISSING"
  | "RBAC_TENANT_MISSING"
  | "RBAC_RESOURCE_MISSING"
  | "RBAC_PERMISSION_DENIED"
  | "RBAC_ROLE_NOT_FOUND"
  | "RBAC_PERMISSION_NOT_FOUND"
  | "RBAC_BINDING_NOT_FOUND"
  | "RBAC_STORAGE_ERROR";

Defined in: src/errors/rbac.error.ts:1


RbacHeaderResourceDeclaration ​

ts
type RbacHeaderResourceDeclaration = {
  idHeader: string;
  idParam?: never;
  idQuery?: never;
  type: string;
};

Defined in: src/interfaces/requirements.ts:12

Properties ​

idHeader ​
ts
idHeader: string;

Defined in: src/interfaces/requirements.ts:14

idParam? ​
ts
optional idParam?: never;

Defined in: src/interfaces/requirements.ts:15

idQuery? ​
ts
optional idQuery?: never;

Defined in: src/interfaces/requirements.ts:16

type ​
ts
type: string;

Defined in: src/interfaces/requirements.ts:13


RbacLegacyDecisionReason ​

ts
type RbacLegacyDecisionReason =
  | "denied_resource_missing"
  | "denied_role_expired"
  | "denied_resource_mismatch";

Defined in: src/interfaces/decision.ts:183

Deprecated ​

These values were exported by 0.2.x but have no RbacService.can() producer. They remain in the compatibility RbacDecisionReason envelope until a separate breaking release.


RbacMutationConflictReason ​

ts
type RbacMutationConflictReason = "role_not_found" | "duplicate";

Defined in: src/interfaces/storage.ts:53


RbacMutationOutcome ​

ts
type RbacMutationOutcome = "created" | "updated" | "deleted" | "no-op" | "conflict";

Defined in: src/interfaces/storage.ts:51


RbacParamResourceDeclaration ​

ts
type RbacParamResourceDeclaration = {
  idHeader?: never;
  idParam: string;
  idQuery?: never;
  type: string;
};

Defined in: src/interfaces/requirements.ts:5

Properties ​

idHeader? ​
ts
optional idHeader?: never;

Defined in: src/interfaces/requirements.ts:8

idParam ​
ts
idParam: string;

Defined in: src/interfaces/requirements.ts:7

idQuery? ​
ts
optional idQuery?: never;

Defined in: src/interfaces/requirements.ts:9

type ​
ts
type: string;

Defined in: src/interfaces/requirements.ts:6


RbacPermissionCanInput ​

ts
type RbacPermissionCanInput = RbacCanBaseInput &
  | {
  mode?: RbacRequirementMode;
  permission: string;
  permissions?: string[];
  roleKey?: never;
}
  | {
  mode?: RbacRequirementMode;
  permission?: undefined;
  permissions: string[];
  roleKey?: never;
};

Defined in: src/interfaces/decision.ts:15


RbacPermissionContract ​

ts
type RbacPermissionContract<T> = PermissionShape<T> & {
  $metadata: PermissionMetadataMap<T>;
  $permission: PermissionValueUnion<T>;
  $permissions: PermissionValueUnion<T>[];
};

Defined in: src/permissions/define-rbac-permissions.ts:45

Type Declaration ​

NameTypeDefined in
$metadataPermissionMetadataMap<T>src/permissions/define-rbac-permissions.ts:48
$permissionPermissionValueUnion<T>src/permissions/define-rbac-permissions.ts:46
$permissionsPermissionValueUnion<T>[]src/permissions/define-rbac-permissions.ts:47

Type Parameters ​

Type Parameter
T

RbacPolicyChangeEventType ​

ts
type RbacPolicyChangeEventType =
  | "role.created"
  | "role.updated"
  | "role.deleted"
  | "permission.granted"
  | "permission.revoked"
  | "role.assigned"
  | "role.revoked";

Defined in: src/interfaces/module-options.ts:19


RbacQueryResourceDeclaration ​

ts
type RbacQueryResourceDeclaration = {
  idHeader?: never;
  idParam?: never;
  idQuery: string;
  type: string;
};

Defined in: src/interfaces/requirements.ts:19

Properties ​

idHeader? ​
ts
optional idHeader?: never;

Defined in: src/interfaces/requirements.ts:23

idParam? ​
ts
optional idParam?: never;

Defined in: src/interfaces/requirements.ts:22

idQuery ​
ts
idQuery: string;

Defined in: src/interfaces/requirements.ts:21

type ​
ts
type: string;

Defined in: src/interfaces/requirements.ts:20


RbacRequirement ​

ts
type RbacRequirement =
  | {
  kind: "permission";
  mode: RbacRequirementMode;
  options: RbacRequirementOptions;
  permissions: string[];
}
  | {
  kind: "role";
  options: RbacRequirementOptions;
  roleKey: string;
};

Defined in: src/interfaces/requirements.ts:48


RbacRequirementMode ​

ts
type RbacRequirementMode = "any" | "all";

Defined in: src/interfaces/decision.ts:5


RbacResourceResolverFn ​

ts
type RbacResourceResolverFn = (context) =>
  | Promise<RbacResourceRef | undefined>
  | RbacResourceRef
  | undefined;

Defined in: src/interfaces/resolvers.ts:22

Resolves a resource for the HTTP-only RbacGuard pipeline in 0.2.x.

Parameters ​

ParameterType
contextExecutionContext

Returns ​

| Promise<RbacResourceRef | undefined> | RbacResourceRef | undefined


RbacResourceResolverToken ​

ts
type RbacResourceResolverToken = InjectionToken<RbacResourceResolver>;

Defined in: src/interfaces/resource.ts:15


RbacRoleCanInput ​

ts
type RbacRoleCanInput = RbacCanBaseInput & {
  mode?: never;
  permission?: never;
  permissions?: never;
  roleKey: string;
};

Defined in: src/interfaces/decision.ts:31

Type Declaration ​

NameTypeDefined in
mode?neversrc/interfaces/decision.ts:35
permission?neversrc/interfaces/decision.ts:33
permissions?neversrc/interfaces/decision.ts:34
roleKeystringsrc/interfaces/decision.ts:32

RbacServiceDecision ​

ts
type RbacServiceDecision = Omit<RbacDecision, "reason" | "details"> & {
  details: RbacServiceDecisionDetails;
  reason: RbacServiceDecisionReason;
};

Defined in: src/interfaces/decision.ts:61

A decision produced by RbacService.can().

Type Declaration ​

NameTypeDefined in
detailsRbacServiceDecisionDetailssrc/interfaces/decision.ts:63
reasonRbacServiceDecisionReasonsrc/interfaces/decision.ts:62

RbacServiceDecisionMissingDetails ​

ts
type RbacServiceDecisionMissingDetails =
  | {
  subject: true;
}
  | {
  tenant: true;
}
  | {
  permissions: string[];
}
  | {
  roleKeys: string[];
};

Defined in: src/interfaces/decision.ts:102


RbacServiceDecisionReason ​

ts
type RbacServiceDecisionReason =
  | "allowed_by_role"
  | "allowed_by_role_permission"
  | "denied_subject_missing"
  | "denied_tenant_missing"
  | "denied_tenant_conflict"
  | "denied_no_matching_role"
  | "denied_no_matching_permission"
  | "denied_storage_error";

Defined in: src/interfaces/decision.ts:168

Decision reasons that RbacService.can() can currently produce.


RbacServiceDecisionRequirementDetails ​

ts
type RbacServiceDecisionRequirementDetails =
  | {
  mode: RbacRequirementMode;
  permissions: string[];
  type: "permission";
}
  | {
  roleKeys: string[];
  type: "role";
};

Defined in: src/interfaces/decision.ts:86


RbacServiceEvaluationStep ​

ts
type RbacServiceEvaluationStep =
  | {
  code: "role_matched" | "permission_matched";
  outcome: "allow";
}
  | {
  code:   | "subject_missing"
     | "tenant_missing"
     | "tenant_conflict"
     | "permission_missing"
     | "role_missing"
     | "storage_error";
  outcome: "deny";
};

Defined in: src/interfaces/decision.ts:151

Evaluation steps that RbacService.can() can currently produce.


RbacSubjectResolver ​

ts
type RbacSubjectResolver = (context) =>
  | Promise<RbacSubject | undefined>
  | RbacSubject
  | undefined;

Defined in: src/interfaces/resolvers.ts:10

Resolves a subject for the HTTP-only RbacGuard pipeline in 0.2.x. Receiving an ExecutionContext does not make the complete Guard transport-neutral.

Parameters ​

ParameterType
contextExecutionContext

Returns ​

| Promise<RbacSubject | undefined> | RbacSubject | undefined


RbacSubjectType ​

ts
type RbacSubjectType =
  | "user"
  | "api_key"
  | "service_account"
  | string & {
};

Defined in: src/interfaces/subject.ts:1


RbacTenantMode ​

ts
type RbacTenantMode = "required" | "optional" | "none";

Defined in: src/interfaces/decision.ts:4


RbacTenantResolver ​

ts
type RbacTenantResolver = (context, options, subject) =>
  | Promise<string | null | undefined>
  | string
  | null
  | undefined;

Defined in: src/interfaces/resolvers.ts:15

Resolves a trusted tenant for the HTTP-only RbacGuard pipeline in 0.2.x.

Parameters ​

ParameterType
contextExecutionContext
optionsRbacRequirementOptions
subjectRbacSubject

Returns ​

| Promise<string | null | undefined> | string | null | undefined


RbacTenantResolverMode ​

ts
type RbacTenantResolverMode = "authoritative" | "legacy-fallback";

Defined in: src/interfaces/module-options.ts:14


RevokeRoleStorageInput ​

ts
type RevokeRoleStorageInput = RevokeRoleInput;

Defined in: src/interfaces/binding.ts:46


UpsertRoleInput ​

ts
type UpsertRoleInput =
  | CreateRoleInput
  | UpdateRoleInput;

Defined in: src/interfaces/role.ts:47

Variables ​

CurrentRbacSubject ​

ts
const CurrentRbacSubject: (...dataOrPipes) => ParameterDecorator;

Defined in: src/decorators/current-rbac-subject.decorator.ts:7

Reads the subject stored by RbacGuard on the current Nest HTTP request.

Parameters ​

ParameterType
...dataOrPipesunknown[]

Returns ​

ParameterDecorator


RBAC_OPTIONS ​

ts
const RBAC_OPTIONS: typeof RBAC_OPTIONS;

Defined in: src/constants.ts:1


RBAC_REQUIREMENTS_METADATA ​

ts
const RBAC_REQUIREMENTS_METADATA: typeof RBAC_REQUIREMENTS_METADATA;

Defined in: src/constants.ts:3


RBAC_SKIP_METADATA ​

ts
const RBAC_SKIP_METADATA: typeof RBAC_SKIP_METADATA;

Defined in: src/constants.ts:4


RBAC_STORAGE ​

ts
const RBAC_STORAGE: typeof RBAC_STORAGE;

Defined in: src/constants.ts:2


RBAC_SUBJECT_REQUEST_KEY ​

ts
const RBAC_SUBJECT_REQUEST_KEY: "rbacSubject" = 'rbacSubject';

Defined in: src/constants.ts:5


RequirePermission ​

ts
const RequirePermission: (permission, options) => ClassDecorator & MethodDecorator = Can;

Defined in: src/decorators/permission.decorator.ts:15

Parameters ​

ParameterType
permissionstring
optionsRbacRequirementOptions

Returns ​

ClassDecorator & MethodDecorator

Functions ​

assertNonEmptyString() ​

ts
function assertNonEmptyString(value, name): string;

Defined in: src/utils/assertions.ts:1

Parameters ​

ParameterType
valuestring | null | undefined
namestring

Returns ​

string


Can() ​

ts
function Can(permission, options?): ClassDecorator & MethodDecorator;

Defined in: src/decorators/permission.decorator.ts:4

Parameters ​

ParameterType
permissionstring
optionsRbacRequirementOptions

Returns ​

ClassDecorator & MethodDecorator


createStrictRbacOptions() ​

ts
function createStrictRbacOptions(options): RbacModuleOptions;

Defined in: src/options/strict-rbac-options.ts:3

Parameters ​

ParameterType
optionsRbacModuleOptions

Returns ​

RbacModuleOptions


defaultHttpSubjectResolver() ​

ts
function defaultHttpSubjectResolver(): RbacSubjectResolver;

Defined in: src/resolvers/default-http-subject.resolver.ts:111

Returns ​

RbacSubjectResolver


defineRbacPermissions() ​

ts
function defineRbacPermissions<T>(definition, options?): RbacPermissionContract<T>;

Defined in: src/permissions/define-rbac-permissions.ts:76

Type Parameters ​

Type Parameter
T extends PermissionDefinition

Parameters ​

ParameterType
definitionT
optionsDefineRbacPermissionsOptions

Returns ​

RbacPermissionContract<T>


mapRbacErrorToHttpException() ​

ts
function mapRbacErrorToHttpException(error):
  | InternalServerErrorException
  | UnauthorizedException
  | ForbiddenException;

Defined in: src/errors/http-error.mapper.ts:8

Parameters ​

ParameterType
errorRbacError

Returns ​

| InternalServerErrorException | UnauthorizedException | ForbiddenException


matchesPermission() ​

ts
function matchesPermission(granted, required): boolean;

Defined in: src/utils/permission-matcher.ts:3

Parameters ​

ParameterType
grantedstring
requiredstring

Returns ​

boolean


matchesResource() ​

ts
function matchesResource(granted, required): boolean;

Defined in: src/utils/resource-matcher.ts:21

Parameters ​

ParameterType
granted| RbacResourceRef | RbacStoredResourceRef | undefined
requiredRbacResourceRef | undefined

Returns ​

boolean


normalizePermission() ​

ts
function normalizePermission(permission): string;

Defined in: src/utils/normalize.ts:3

Parameters ​

ParameterType
permissionstring

Returns ​

string


normalizePermissions() ​

ts
function normalizePermissions(permissions): string[];

Defined in: src/utils/normalize.ts:11

Parameters ​

ParameterType
permissionsstring[]

Returns ​

string[]


RequirePermissions() ​

ts
function RequirePermissions(permissions, options?): ClassDecorator & MethodDecorator;

Defined in: src/decorators/permission.decorator.ts:17

Parameters ​

ParameterType
permissionsreadonly string[]
optionsRbacRequirementOptions

Returns ​

ClassDecorator & MethodDecorator


RequireRole() ​

ts
function RequireRole(roleKey, options?): ClassDecorator & MethodDecorator;

Defined in: src/decorators/role.decorator.ts:4

Parameters ​

ParameterType
roleKeystring
optionsRbacRequirementOptions

Returns ​

ClassDecorator & MethodDecorator


resolveHttpResource() ​

ts
function resolveHttpResource(context, declaration): RbacResourceRef | undefined;

Defined in: src/resolvers/default-http-resource.resolver.ts:30

Parameters ​

ParameterType
contextExecutionContext
declarationRbacBuiltInResourceDeclaration

Returns ​

RbacResourceRef | undefined


resolveHttpTenant() ​

ts
function resolveHttpTenant(
   context,
   requirementOptions,
   subject): string | null | undefined;

Defined in: src/resolvers/default-http-tenant.resolver.ts:41

Parameters ​

ParameterType
contextExecutionContext
requirementOptionsRbacRequirementOptions
subjectRbacSubject

Returns ​

string | null | undefined


SkipRbac() ​

ts
function SkipRbac(reason?): CustomDecorator<typeof RBAC_SKIP_METADATA>;

Defined in: src/decorators/skip-rbac.decorator.ts:4

Parameters ​

ParameterType
reason?string

Returns ​

CustomDecorator<typeof RBAC_SKIP_METADATA>

Released under the MIT License.