Kaizen
Browse modulesAccessaccess/serverClasses

Abstract Class: BaseAccessService

Defined in: server/access/base-access-service.ts:33

Shared base for the access services. Holds deps, exposes the resolved actorId, and wraps work in a repository transaction (so nested service calls share one tx via TransactionManager). Mirrors BaseRulesService.

Extended by

Constructors

Constructor

new BaseAccessService(deps: AccessFeatureDeps): BaseAccessService;

Defined in: server/access/base-access-service.ts:36

Parameters

ParameterType
depsAccessFeatureDeps

Returns

BaseAccessService

Properties

deps

protected readonly deps: AccessFeatureDeps;

Defined in: server/access/base-access-service.ts:34

Accessors

actorId

Get Signature

get protected actorId(): string | null;

Defined in: server/access/base-access-service.ts:40

Returns

string | null

Methods

coarsePermissionsForActor()

protected coarsePermissionsForActor(
   actor: {
  id: string;
  type: SubjectType;
}, 
   scope: GrantScope, 
   now?: Date
): Promise<CoarseActorAuthority>;

Defined in: server/access/base-access-service.ts:117

H3: derive an actor's UNCONDITIONALLY-held authority for a target scope — the delegable set for both GrantService.create's CreateGrantGuard and RoleService.createVersion's CreateVersionGuard. Only grants the actor holds with NO selector and NO condition contribute, mirroring hasCoarsePermission: a narrowly-held permission must not be re-delegable (as a grant) or re-addable (to a role) unconstrained. Effective-date validity is honored. Shared here (not duplicated per service) so the two escalation guards can never drift on what "coarsely held" means.

Derived over scopeChain(scope), so a platform admin can delegate inside an organization without mode: "system" (which would skip every escalation guard). The chain is derived here, never accepted as a parameter — see scopeChain.

scopeKeys reports PROVENANCE: which scopes actually backed the actor. That is what GrantService's self-org cap reads instead of a caller-asserted actorOrganizationId, making it server-derived and unspoofable.

Parameters

ParameterType
actor{ id: string; type: SubjectType; }
actor.idstring
actor.typeSubjectType
scopeGrantScope
nowDate

Returns

Promise<CoarseActorAuthority>


loadActiveGrants()

protected loadActiveGrants(
   repos: AccessRepositories, 
   subject: Subject, 
   scopes: GrantScope[]
): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}[]>;

Defined in: server/access/base-access-service.ts:70

Security-critical lookup: load a subject's active grants across a set of scopes, expanding org-group membership for non-group subjects. The single source of truth for "which grants apply to this subject right now" — every caller (snapshot compilation, coarse-permission derivation) funnels here so the scopeKey derivation and group-expansion rule can never drift between call sites.

Queried one scope at a time rather than with a single scopeKey IN (…): group expansion is a PER-SCOPE rule, not a property of the subject. It runs only for an organization-scoped lookup AND a non-group subject — a group subject's grants are read directly (it has no "groups" of its own to expand), and platform scope has no org-group notion, so a group's platform-scoped grant must NOT reach its members through an org-scoped chain. Flattening the chain into one query with a unioned groupIds would silently widen exactly that.

Must be called inside a repos.transaction(...) so the membership reads and the grant reads share one transaction.

Parameters

ParameterType
reposAccessRepositories
subjectSubject
scopesGrantScope[]

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }[]>


transaction()

protected transaction<T>(fn: (deps: AccessFeatureDeps) => Promise<T>): Promise<T>;

Defined in: server/access/base-access-service.ts:44

Type Parameters

Type Parameter
T

Parameters

ParameterType
fn(deps: AccessFeatureDeps) => Promise<T>

Returns

Promise<T>

On this page