JA
ベータ版の翻訳

@core / rbac

1.0.1 ▾
認証済みMIT
GitHub

@core/auth 上のロールと権限:ワイルドカード、本人限定ルール、権限昇格を防ぐ付与

コード10 ファイルコンテキスト約 615 トークンスキャン合格

.genpmignore 適用後に組み込まれる正確なツリーです。固定先:

src/lib/rbac/adapters/hono.ts読み取り専用 · decbadd
// Adaptador Hono: `requirePermission('posts:publish')` después de `sessionMiddleware` de @core/auth.
import type { MiddlewareHandler } from 'hono';
import type { AuthVariables } from '../../auth/adapters/hono.ts';
import { can, type Grants, getGrants } from '../index.ts';

export type RbacVariables = AuthVariables & { grants: Grants | null };

/** 401 sin usuario, 403 sin permiso. Deja `c.get('grants')` para comprobaciones `:own` dentro del handler. */
export function requirePermission(permission: string): MiddlewareHandler<{ Variables: RbacVariables }> {
  return async (c, next) => {
    const user = c.get('user');
    if (!user) return c.json({ error: 'unauthorized' }, 401);
    const g = await getGrants(user.id);
    c.set('grants', g);
    if (!(await can(g, permission))) return c.json({ error: 'forbidden' }, 403);
    await next();
  };
}

@core/rbac を報告

パッケージを報告するには GitHub でログインしてください。

GitHub で続ける