Abstract Class: BaseAccessService
Defined in: server/access/base-access-service.ts:33
Shared base for the access services. Holds deps, exposes the resolved
actorId, and wraps work in a repository transaction (so nested service
calls share one tx via TransactionManager). Mirrors BaseRulesService.
Extended by
Constructors
Constructor
new BaseAccessService(deps: AccessFeatureDeps): BaseAccessService;Defined in: server/access/base-access-service.ts:36
Parameters
| Parameter | Type |
|---|---|
deps | AccessFeatureDeps |
Returns
BaseAccessService
Properties
deps
protected readonly deps: AccessFeatureDeps;Defined in: server/access/base-access-service.ts:34
Accessors
actorId
Get Signature
get protected actorId(): string | null;Defined in: server/access/base-access-service.ts:40
Returns
string | null
Methods
coarsePermissionsForActor()
protected coarsePermissionsForActor(
actor: {
id: string;
type: SubjectType;
},
scope: GrantScope,
now?: Date
): Promise<CoarseActorAuthority>;Defined in: server/access/base-access-service.ts:117
H3: derive an actor's UNCONDITIONALLY-held authority for a target scope —
the delegable set for both GrantService.create's CreateGrantGuard and
RoleService.createVersion's CreateVersionGuard. Only grants the actor
holds with NO selector and NO condition contribute, mirroring
hasCoarsePermission: a narrowly-held permission must not be re-delegable
(as a grant) or re-addable (to a role) unconstrained. Effective-date
validity is honored. Shared here (not duplicated per service) so the two
escalation guards can never drift on what "coarsely held" means.
Derived over scopeChain(scope), so a platform admin can delegate inside
an organization without mode: "system" (which would skip every
escalation guard). The chain is derived here, never accepted as a
parameter — see scopeChain.
scopeKeys reports PROVENANCE: which scopes actually backed the actor.
That is what GrantService's self-org cap reads instead of a
caller-asserted actorOrganizationId, making it server-derived and
unspoofable.
Parameters
| Parameter | Type |
|---|---|
actor | { id: string; type: SubjectType; } |
actor.id | string |
actor.type | SubjectType |
scope | GrantScope |
now | Date |
Returns
Promise<CoarseActorAuthority>
loadActiveGrants()
protected loadActiveGrants(
repos: AccessRepositories,
subject: Subject,
scopes: GrantScope[]
): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>;Defined in: server/access/base-access-service.ts:70
Security-critical lookup: load a subject's active grants across a set of scopes, expanding org-group membership for non-group subjects. The single source of truth for "which grants apply to this subject right now" — every caller (snapshot compilation, coarse-permission derivation) funnels here so the scopeKey derivation and group-expansion rule can never drift between call sites.
Queried one scope at a time rather than with a single scopeKey IN (…):
group expansion is a PER-SCOPE rule, not a property of the subject. It runs
only for an organization-scoped lookup AND a non-group subject — a
group subject's grants are read directly (it has no "groups" of its own to
expand), and platform scope has no org-group notion, so a group's
platform-scoped grant must NOT reach its members through an org-scoped
chain. Flattening the chain into one query with a unioned groupIds would
silently widen exactly that.
Must be called inside a repos.transaction(...) so the membership reads
and the grant reads share one transaction.
Parameters
| Parameter | Type |
|---|---|
repos | AccessRepositories |
subject | Subject |
scopes | GrantScope[] |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>
transaction()
protected transaction<T>(fn: (deps: AccessFeatureDeps) => Promise<T>): Promise<T>;Defined in: server/access/base-access-service.ts:44
Type Parameters
| Type Parameter |
|---|
T |
Parameters
| Parameter | Type |
|---|---|
fn | (deps: AccessFeatureDeps) => Promise<T> |
Returns
Promise<T>