Class: GrantRepository
Defined in: server/access/grant-repository.ts:44
CRUD over RbacGrants. Grants are allow-only in v1; binds to role identity
(not a frozen version). The (scopeKey, subjectType, subjectId, roleId, grantFingerprint) unique constraint blocks exact duplicates while allowing
the same role with different selectors.
Extends
CrudRepository<PrismaClient,RbacGrants,CreateInput,Partial<{conditionLogic:Prisma.InputJsonValue;selector:Prisma.InputJsonValue; }>,string,Tx<PrismaClient>>
Constructors
Constructor
new GrantRepository(prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>, options?: RepositoryOptions): GrantRepository;Defined in: server/persistence/base-repository.ts:68
Parameters
| Parameter | Type |
|---|---|
prismaClient | PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs> |
options | RepositoryOptions |
Returns
GrantRepository
Inherited from
Properties
ENTITY_TYPE?
protected readonly optional ENTITY_TYPE?: string;Defined in: server/persistence/base-repository.ts:61
Set ENTITY_TYPE in child repositories to enable automatic activity
logging. When set, create/update/delete operations auto-log unless
silenced with .silent. Requires an activity model on the consumer's
Prisma schema.
Inherited from
logger?
protected readonly optional logger?: Logger;Defined in: server/persistence/base-repository.ts:64
Inherited from
prismaClient
protected prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>;Defined in: server/persistence/base-repository.ts:69
Inherited from
Accessors
actorId
Get Signature
get protected actorId(): string | null | undefined;Defined in: server/persistence/base-repository.ts:76
Returns
string | null | undefined
Inherited from
auditCreate
Get Signature
get protected auditCreate(): {
createdBy: string | null | undefined;
updatedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:90
Returns
{
createdBy: string | null | undefined;
updatedBy: string | null | undefined;
}createdBy
createdBy: string | null | undefined = actorId;updatedBy
updatedBy: string | null | undefined = actorId;Inherited from
auditDelete
Get Signature
get protected auditDelete(): {
deletedAt: Date;
deletedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:99
Returns
{
deletedAt: Date;
deletedBy: string | null | undefined;
}deletedAt
deletedAt: Date;deletedBy
deletedBy: string | null | undefined;Inherited from
auditUpdate
Get Signature
get protected auditUpdate(): {
updatedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:95
Returns
{
updatedBy: string | null | undefined;
}updatedBy
updatedBy: string | null | undefined;Inherited from
silent
Get Signature
get silent(): this;Defined in: server/persistence/base-repository.ts:115
Suppress activity logging for the next mutation call. One-shot: the flag is consumed by the next create/update/delete.
Example
await repo.silent.update(id, data); // no activity logged
await repo.update(id, data); // activity logged normallyReturns
this
Inherited from
tx
Get Signature
get protected tx(): TTx;Defined in: server/persistence/base-repository.ts:86
The current Prisma handle: the active transaction if one is running on this async context, otherwise the raw client.
Returns
TTx
Inherited from
Methods
_count()
protected _count(): Promise<number>;Defined in: server/access/grant-repository.ts:70
Returns
Promise<number>
Overrides
_create()
protected _create(input: CreateInput): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/access/grant-repository.ts:91
Parameters
| Parameter | Type |
|---|---|
input | CreateInput |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Overrides
_exists()
protected _exists(id: string): Promise<boolean>;Defined in: server/access/grant-repository.ts:63
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<boolean>
Overrides
_findById()
protected _findById(id: string): Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>;Defined in: server/access/grant-repository.ts:59
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>
Overrides
_findMany()
protected _findMany(pagination: {
page: number;
pageSize: number;
}): Promise<{
items: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[];
total: number;
}>;Defined in: server/access/grant-repository.ts:74
Parameters
| Parameter | Type |
|---|---|
pagination | { page: number; pageSize: number; } |
pagination.page | number |
pagination.pageSize | number |
Returns
Promise<{
items: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[];
total: number;
}>
Overrides
_hardDelete()
protected _hardDelete(id: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/access/grant-repository.ts:132
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Overrides
_softDelete()
protected _softDelete(id: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/access/grant-repository.ts:128
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Overrides
_update()
protected _update(id: string, patch: Partial<{
conditionLogic: Prisma.InputJsonValue;
selector: Prisma.InputJsonValue;
}>): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/access/grant-repository.ts:118
Parameters
| Parameter | Type |
|---|---|
id | string |
patch | Partial<{ conditionLogic: Prisma.InputJsonValue; selector: Prisma.InputJsonValue; }> |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Overrides
afterCreate()
protected afterCreate(entity: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}, _input: CreateInput): Promise<void>;Defined in: server/persistence/base-repository.ts:316
Parameters
| Parameter | Type |
|---|---|
entity | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } |
entity.conditionLogic | JsonValue |
entity.createdAt | Date |
entity.createdBy | string | null |
entity.deletedAt | Date | null |
entity.deletedBy | string | null |
entity.effectiveEnd | Date | null |
entity.effectiveStart | Date | null |
entity.grantFingerprint | string |
entity.id | string |
entity.organizationId | string | null |
entity.roleId | string |
entity.scopeKey | string |
entity.scopeType | RbacScopeType |
entity.selector | JsonValue |
entity.subjectId | string |
entity.subjectType | RbacSubjectType |
entity.updatedAt | Date |
entity.updatedBy | string | null |
_input | CreateInput |
Returns
Promise<void>
Inherited from
afterDelete()
protected afterDelete(_entity: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}, id: string): Promise<void>;Defined in: server/persistence/base-repository.ts:390
Parameters
| Parameter | Type |
|---|---|
_entity | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } |
_entity.conditionLogic | JsonValue |
_entity.createdAt | Date |
_entity.createdBy | string | null |
_entity.deletedAt | Date | null |
_entity.deletedBy | string | null |
_entity.effectiveEnd | Date | null |
_entity.effectiveStart | Date | null |
_entity.grantFingerprint | string |
_entity.id | string |
_entity.organizationId | string | null |
_entity.roleId | string |
_entity.scopeKey | string |
_entity.scopeType | RbacScopeType |
_entity.selector | JsonValue |
_entity.subjectId | string |
_entity.subjectType | RbacSubjectType |
_entity.updatedAt | Date |
_entity.updatedBy | string | null |
id | string |
Returns
Promise<void>
Inherited from
afterUpdate()
protected afterUpdate(
_entity: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
},
id: string,
input: Partial<{
conditionLogic: InputJsonValue;
selector: InputJsonValue;
}>
): Promise<void>;Defined in: server/persistence/base-repository.ts:328
Parameters
| Parameter | Type |
|---|---|
_entity | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } |
_entity.conditionLogic | JsonValue |
_entity.createdAt | Date |
_entity.createdBy | string | null |
_entity.deletedAt | Date | null |
_entity.deletedBy | string | null |
_entity.effectiveEnd | Date | null |
_entity.effectiveStart | Date | null |
_entity.grantFingerprint | string |
_entity.id | string |
_entity.organizationId | string | null |
_entity.roleId | string |
_entity.scopeKey | string |
_entity.scopeType | RbacScopeType |
_entity.selector | JsonValue |
_entity.subjectId | string |
_entity.subjectType | RbacSubjectType |
_entity.updatedAt | Date |
_entity.updatedBy | string | null |
id | string |
input | Partial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }> |
Returns
Promise<void>
Inherited from
beforeCreate()
protected beforeCreate(_input: CreateInput): Promise<void>;Defined in: server/persistence/base-repository.ts:315
Parameters
| Parameter | Type |
|---|---|
_input | CreateInput |
Returns
Promise<void>
Inherited from
beforeDelete()
protected beforeDelete(_id: string, _existing: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}): Promise<void>;Defined in: server/persistence/base-repository.ts:388
Parameters
| Parameter | Type |
|---|---|
_id | string |
_existing | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } |
_existing.conditionLogic | JsonValue |
_existing.createdAt | Date |
_existing.createdBy | string | null |
_existing.deletedAt | Date | null |
_existing.deletedBy | string | null |
_existing.effectiveEnd | Date | null |
_existing.effectiveStart | Date | null |
_existing.grantFingerprint | string |
_existing.id | string |
_existing.organizationId | string | null |
_existing.roleId | string |
_existing.scopeKey | string |
_existing.scopeType | RbacScopeType |
_existing.selector | JsonValue |
_existing.subjectId | string |
_existing.subjectType | RbacSubjectType |
_existing.updatedAt | Date |
_existing.updatedBy | string | null |
Returns
Promise<void>
Inherited from
beforeUpdate()
protected beforeUpdate(
_id: string,
_input: Partial<{
conditionLogic: InputJsonValue;
selector: InputJsonValue;
}>,
_existing: {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
): Promise<void>;Defined in: server/persistence/base-repository.ts:323
Parameters
| Parameter | Type |
|---|---|
_id | string |
_input | Partial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }> |
_existing | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } |
_existing.conditionLogic | JsonValue |
_existing.createdAt | Date |
_existing.createdBy | string | null |
_existing.deletedAt | Date | null |
_existing.deletedBy | string | null |
_existing.effectiveEnd | Date | null |
_existing.effectiveStart | Date | null |
_existing.grantFingerprint | string |
_existing.id | string |
_existing.organizationId | string | null |
_existing.roleId | string |
_existing.scopeKey | string |
_existing.scopeType | RbacScopeType |
_existing.selector | JsonValue |
_existing.subjectId | string |
_existing.subjectType | RbacSubjectType |
_existing.updatedAt | Date |
_existing.updatedBy | string | null |
Returns
Promise<void>
Inherited from
consumeSilent()
protected consumeSilent(): boolean;Defined in: server/persistence/base-repository.ts:128
Consume and reset the silent flag. Called by template methods.
Returns
boolean
Inherited from
count()
count(): Promise<number>;Defined in: server/persistence/base-repository.ts:191
Returns
Promise<number>
Inherited from
create()
create(input: CreateInput): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/persistence/base-repository.ts:292
Parameters
| Parameter | Type |
|---|---|
input | CreateInput |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Inherited from
exists()
exists(id: string): Promise<boolean>;Defined in: server/persistence/base-repository.ts:187
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<boolean>
Inherited from
findActiveByRoleId()
findActiveByRoleId(roleId: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>;Defined in: server/access/grant-repository.ts:181
Every active grant referencing a role — used to bump affected subjects on role edits.
Parameters
| Parameter | Type |
|---|---|
roleId | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>
findActiveByTuple()
findActiveByTuple(input: {
grantFingerprint: string;
roleId: string;
scopeKey: string;
subjectId: string;
subjectType: SubjectType;
}): Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>;Defined in: server/access/grant-repository.ts:168
The single ACTIVE grant matching the partial unique index's tuple
(scope_key, subject_type, subject_id, role_id, grant_fingerprint WHERE
deleted_at IS NULL), or null. Used by GrantService.ensure to resolve
the row a P2002 collided with — Prisma cannot upsert against a partial
index, because a partial index is not expressible in the schema.
Parameters
| Parameter | Type |
|---|---|
input | { grantFingerprint: string; roleId: string; scopeKey: string; subjectId: string; subjectType: SubjectType; } |
input.grantFingerprint | string |
input.roleId | string |
input.scopeKey | string |
input.subjectId | string |
input.subjectType | SubjectType |
Returns
Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>
findActiveForSubject()
findActiveForSubject(
scopeKey: string,
subjectType: SubjectType,
subjectId: string,
groupIds?: string[]
): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>;Defined in: server/access/grant-repository.ts:141
Active grants for a subject within a scope, plus active grants to any
group the subject belongs to. groupIds is resolved by the caller from
RbacGroupMemberships. Used to compile the PermissionSnapshot.
Parameters
| Parameter | Type | Default value |
|---|---|---|
scopeKey | string | undefined |
subjectType | SubjectType | undefined |
subjectId | string | undefined |
groupIds | string[] | [] |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}[]>
findById()
findById(id: string): Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>;Defined in: server/persistence/base-repository.ts:177
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<
| {
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}
| null>
Inherited from
findByIdOrThrow()
findByIdOrThrow(id: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/persistence/base-repository.ts:181
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Inherited from
CrudRepository.findByIdOrThrow
findMany()
findMany(pagination: {
page: number;
pageSize: number;
}): Promise<OffsetPaginatedResult<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>>;Defined in: server/persistence/base-repository.ts:195
Parameters
| Parameter | Type |
|---|---|
pagination | { page: number; pageSize: number; } |
pagination.page | number |
pagination.pageSize | number |
Returns
Promise<OffsetPaginatedResult<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>>
Inherited from
findSubjectsForRole()
findSubjectsForRole(roleId: string): Promise<{
scopeKey: string;
subjectId: string;
subjectType: SubjectType;
}[]>;Defined in: server/access/grant-repository.ts:251
Introspection: which subjects hold a given role?
Parameters
| Parameter | Type |
|---|---|
roleId | string |
Returns
Promise<{
scopeKey: string;
subjectId: string;
subjectType: SubjectType;
}[]>
hardDelete()
hardDelete(id: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/persistence/base-repository.ts:377
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Inherited from
loadConditionsTable()
loadConditionsTable(conditionIds: string[]): Promise<Record<string, {
condition_type: string;
config: AccessRecord;
created_at: string;
created_by: string;
description: string | null;
domain: string;
id: string;
module: string | null;
name: string | null;
organization_id: string;
}>>;Defined in: server/access/grant-repository.ts:194
Load the engine-shape conditions table for the given condition ids,
inlining config from each condition's current version. ABAC reuses the
shared rules conditions / condition_versions tables, so this read lives
here (where this.tx is already typed against the full client) rather than
the AccessService reaching into a private handle.
Parameters
| Parameter | Type |
|---|---|
conditionIds | string[] |
Returns
Promise<Record<string, {
condition_type: string;
config: AccessRecord;
created_at: string;
created_by: string;
description: string | null;
domain: string;
id: string;
module: string | null;
name: string | null;
organization_id: string;
}>>
logActivity()
protected logActivity(
_entityId: string,
_action: string,
_metadata?: Record<string, unknown>
): Promise<void>;Defined in: server/persistence/base-repository.ts:140
Log an activity entry.
NOTE: This is not implemented because there's no activity model implemented in taproot yet! https://linear.app/kaizenlabs/issue/ENG-7846/add-activity-log-tables
Parameters
| Parameter | Type |
|---|---|
_entityId | string |
_action | string |
_metadata? | Record<string, unknown> |
Returns
Promise<void>
Inherited from
notFoundError()
protected notFoundError(id: string): Error;Defined in: server/access/grant-repository.ts:55
Create a not-found error. Override to provide custom error types.
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Error
Overrides
softDelete()
softDelete(id: string): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/persistence/base-repository.ts:366
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>
Inherited from
update()
update(id: string, input: Partial<{
conditionLogic: InputJsonValue;
selector: InputJsonValue;
}>): Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>;Defined in: server/persistence/base-repository.ts:301
Parameters
| Parameter | Type |
|---|---|
id | string |
input | Partial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }> |
Returns
Promise<{
conditionLogic: JsonValue;
createdAt: Date;
createdBy: string | null;
deletedAt: Date | null;
deletedBy: string | null;
effectiveEnd: Date | null;
effectiveStart: Date | null;
grantFingerprint: string;
id: string;
organizationId: string | null;
roleId: string;
scopeKey: string;
scopeType: RbacScopeType;
selector: JsonValue;
subjectId: string;
subjectType: RbacSubjectType;
updatedAt: Date;
updatedBy: string | null;
}>