Kaizen
Browse modulesAccessaccess/serverClasses

Class: GrantRepository

Defined in: server/access/grant-repository.ts:44

CRUD over RbacGrants. Grants are allow-only in v1; binds to role identity (not a frozen version). The (scopeKey, subjectType, subjectId, roleId, grantFingerprint) unique constraint blocks exact duplicates while allowing the same role with different selectors.

Extends

  • CrudRepository<PrismaClient, RbacGrants, CreateInput, Partial<{ conditionLogic: Prisma.InputJsonValue; selector: Prisma.InputJsonValue; }>, string, Tx<PrismaClient>>

Constructors

Constructor

new GrantRepository(prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>, options?: RepositoryOptions): GrantRepository;

Defined in: server/persistence/base-repository.ts:68

Parameters

ParameterType
prismaClientPrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>
optionsRepositoryOptions

Returns

GrantRepository

Inherited from

CrudRepository.constructor

Properties

ENTITY_TYPE?

protected readonly optional ENTITY_TYPE?: string;

Defined in: server/persistence/base-repository.ts:61

Set ENTITY_TYPE in child repositories to enable automatic activity logging. When set, create/update/delete operations auto-log unless silenced with .silent. Requires an activity model on the consumer's Prisma schema.

Inherited from

CrudRepository.ENTITY_TYPE


logger?

protected readonly optional logger?: Logger;

Defined in: server/persistence/base-repository.ts:64

Inherited from

CrudRepository.logger


prismaClient

protected prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>;

Defined in: server/persistence/base-repository.ts:69

Inherited from

CrudRepository.prismaClient

Accessors

actorId

Get Signature

get protected actorId(): string | null | undefined;

Defined in: server/persistence/base-repository.ts:76

Returns

string | null | undefined

Inherited from

CrudRepository.actorId


auditCreate

Get Signature

get protected auditCreate(): {
  createdBy: string | null | undefined;
  updatedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:90

Returns
{
  createdBy: string | null | undefined;
  updatedBy: string | null | undefined;
}
createdBy
createdBy: string | null | undefined = actorId;
updatedBy
updatedBy: string | null | undefined = actorId;

Inherited from

CrudRepository.auditCreate


auditDelete

Get Signature

get protected auditDelete(): {
  deletedAt: Date;
  deletedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:99

Returns
{
  deletedAt: Date;
  deletedBy: string | null | undefined;
}
deletedAt
deletedAt: Date;
deletedBy
deletedBy: string | null | undefined;

Inherited from

CrudRepository.auditDelete


auditUpdate

Get Signature

get protected auditUpdate(): {
  updatedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:95

Returns
{
  updatedBy: string | null | undefined;
}
updatedBy
updatedBy: string | null | undefined;

Inherited from

CrudRepository.auditUpdate


silent

Get Signature

get silent(): this;

Defined in: server/persistence/base-repository.ts:115

Suppress activity logging for the next mutation call. One-shot: the flag is consumed by the next create/update/delete.

Example
await repo.silent.update(id, data);   // no activity logged
await repo.update(id, data);          // activity logged normally
Returns

this

Inherited from

CrudRepository.silent


tx

Get Signature

get protected tx(): TTx;

Defined in: server/persistence/base-repository.ts:86

The current Prisma handle: the active transaction if one is running on this async context, otherwise the raw client.

Returns

TTx

Inherited from

CrudRepository.tx

Methods

_count()

protected _count(): Promise<number>;

Defined in: server/access/grant-repository.ts:70

Returns

Promise<number>

Overrides

CrudRepository._count


_create()

protected _create(input: CreateInput): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/access/grant-repository.ts:91

Parameters

ParameterType
inputCreateInput

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Overrides

CrudRepository._create


_exists()

protected _exists(id: string): Promise<boolean>;

Defined in: server/access/grant-repository.ts:63

Parameters

ParameterType
idstring

Returns

Promise<boolean>

Overrides

CrudRepository._exists


_findById()

protected _findById(id: string): Promise<
  | {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}
| null>;

Defined in: server/access/grant-repository.ts:59

Parameters

ParameterType
idstring

Returns

Promise< | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } | null>

Overrides

CrudRepository._findById


_findMany()

protected _findMany(pagination: {
  page: number;
  pageSize: number;
}): Promise<{
  items: {
     conditionLogic: JsonValue;
     createdAt: Date;
     createdBy: string | null;
     deletedAt: Date | null;
     deletedBy: string | null;
     effectiveEnd: Date | null;
     effectiveStart: Date | null;
     grantFingerprint: string;
     id: string;
     organizationId: string | null;
     roleId: string;
     scopeKey: string;
     scopeType: RbacScopeType;
     selector: JsonValue;
     subjectId: string;
     subjectType: RbacSubjectType;
     updatedAt: Date;
     updatedBy: string | null;
  }[];
  total: number;
}>;

Defined in: server/access/grant-repository.ts:74

Parameters

ParameterType
pagination{ page: number; pageSize: number; }
pagination.pagenumber
pagination.pageSizenumber

Returns

Promise<{ items: { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }[]; total: number; }>

Overrides

CrudRepository._findMany


_hardDelete()

protected _hardDelete(id: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/access/grant-repository.ts:132

Parameters

ParameterType
idstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Overrides

CrudRepository._hardDelete


_softDelete()

protected _softDelete(id: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/access/grant-repository.ts:128

Parameters

ParameterType
idstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Overrides

CrudRepository._softDelete


_update()

protected _update(id: string, patch: Partial<{
  conditionLogic: Prisma.InputJsonValue;
  selector: Prisma.InputJsonValue;
}>): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/access/grant-repository.ts:118

Parameters

ParameterType
idstring
patchPartial<{ conditionLogic: Prisma.InputJsonValue; selector: Prisma.InputJsonValue; }>

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Overrides

CrudRepository._update


afterCreate()

protected afterCreate(entity: {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}, _input: CreateInput): Promise<void>;

Defined in: server/persistence/base-repository.ts:316

Parameters

ParameterType
entity{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }
entity.conditionLogicJsonValue
entity.createdAtDate
entity.createdBystring | null
entity.deletedAtDate | null
entity.deletedBystring | null
entity.effectiveEndDate | null
entity.effectiveStartDate | null
entity.grantFingerprintstring
entity.idstring
entity.organizationIdstring | null
entity.roleIdstring
entity.scopeKeystring
entity.scopeTypeRbacScopeType
entity.selectorJsonValue
entity.subjectIdstring
entity.subjectTypeRbacSubjectType
entity.updatedAtDate
entity.updatedBystring | null
_inputCreateInput

Returns

Promise<void>

Inherited from

CrudRepository.afterCreate


afterDelete()

protected afterDelete(_entity: {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}, id: string): Promise<void>;

Defined in: server/persistence/base-repository.ts:390

Parameters

ParameterType
_entity{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }
_entity.conditionLogicJsonValue
_entity.createdAtDate
_entity.createdBystring | null
_entity.deletedAtDate | null
_entity.deletedBystring | null
_entity.effectiveEndDate | null
_entity.effectiveStartDate | null
_entity.grantFingerprintstring
_entity.idstring
_entity.organizationIdstring | null
_entity.roleIdstring
_entity.scopeKeystring
_entity.scopeTypeRbacScopeType
_entity.selectorJsonValue
_entity.subjectIdstring
_entity.subjectTypeRbacSubjectType
_entity.updatedAtDate
_entity.updatedBystring | null
idstring

Returns

Promise<void>

Inherited from

CrudRepository.afterDelete


afterUpdate()

protected afterUpdate(
   _entity: {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}, 
   id: string, 
   input: Partial<{
  conditionLogic: InputJsonValue;
  selector: InputJsonValue;
}>
): Promise<void>;

Defined in: server/persistence/base-repository.ts:328

Parameters

ParameterType
_entity{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }
_entity.conditionLogicJsonValue
_entity.createdAtDate
_entity.createdBystring | null
_entity.deletedAtDate | null
_entity.deletedBystring | null
_entity.effectiveEndDate | null
_entity.effectiveStartDate | null
_entity.grantFingerprintstring
_entity.idstring
_entity.organizationIdstring | null
_entity.roleIdstring
_entity.scopeKeystring
_entity.scopeTypeRbacScopeType
_entity.selectorJsonValue
_entity.subjectIdstring
_entity.subjectTypeRbacSubjectType
_entity.updatedAtDate
_entity.updatedBystring | null
idstring
inputPartial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }>

Returns

Promise<void>

Inherited from

CrudRepository.afterUpdate


beforeCreate()

protected beforeCreate(_input: CreateInput): Promise<void>;

Defined in: server/persistence/base-repository.ts:315

Parameters

ParameterType
_inputCreateInput

Returns

Promise<void>

Inherited from

CrudRepository.beforeCreate


beforeDelete()

protected beforeDelete(_id: string, _existing: {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}): Promise<void>;

Defined in: server/persistence/base-repository.ts:388

Parameters

ParameterType
_idstring
_existing{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }
_existing.conditionLogicJsonValue
_existing.createdAtDate
_existing.createdBystring | null
_existing.deletedAtDate | null
_existing.deletedBystring | null
_existing.effectiveEndDate | null
_existing.effectiveStartDate | null
_existing.grantFingerprintstring
_existing.idstring
_existing.organizationIdstring | null
_existing.roleIdstring
_existing.scopeKeystring
_existing.scopeTypeRbacScopeType
_existing.selectorJsonValue
_existing.subjectIdstring
_existing.subjectTypeRbacSubjectType
_existing.updatedAtDate
_existing.updatedBystring | null

Returns

Promise<void>

Inherited from

CrudRepository.beforeDelete


beforeUpdate()

protected beforeUpdate(
   _id: string, 
   _input: Partial<{
  conditionLogic: InputJsonValue;
  selector: InputJsonValue;
}>, 
   _existing: {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}
): Promise<void>;

Defined in: server/persistence/base-repository.ts:323

Parameters

ParameterType
_idstring
_inputPartial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }>
_existing{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }
_existing.conditionLogicJsonValue
_existing.createdAtDate
_existing.createdBystring | null
_existing.deletedAtDate | null
_existing.deletedBystring | null
_existing.effectiveEndDate | null
_existing.effectiveStartDate | null
_existing.grantFingerprintstring
_existing.idstring
_existing.organizationIdstring | null
_existing.roleIdstring
_existing.scopeKeystring
_existing.scopeTypeRbacScopeType
_existing.selectorJsonValue
_existing.subjectIdstring
_existing.subjectTypeRbacSubjectType
_existing.updatedAtDate
_existing.updatedBystring | null

Returns

Promise<void>

Inherited from

CrudRepository.beforeUpdate


consumeSilent()

protected consumeSilent(): boolean;

Defined in: server/persistence/base-repository.ts:128

Consume and reset the silent flag. Called by template methods.

Returns

boolean

Inherited from

CrudRepository.consumeSilent


count()

count(): Promise<number>;

Defined in: server/persistence/base-repository.ts:191

Returns

Promise<number>

Inherited from

CrudRepository.count


create()

create(input: CreateInput): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/persistence/base-repository.ts:292

Parameters

ParameterType
inputCreateInput

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Inherited from

CrudRepository.create


exists()

exists(id: string): Promise<boolean>;

Defined in: server/persistence/base-repository.ts:187

Parameters

ParameterType
idstring

Returns

Promise<boolean>

Inherited from

CrudRepository.exists


findActiveByRoleId()

findActiveByRoleId(roleId: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}[]>;

Defined in: server/access/grant-repository.ts:181

Every active grant referencing a role — used to bump affected subjects on role edits.

Parameters

ParameterType
roleIdstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }[]>


findActiveByTuple()

findActiveByTuple(input: {
  grantFingerprint: string;
  roleId: string;
  scopeKey: string;
  subjectId: string;
  subjectType: SubjectType;
}): Promise<
  | {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}
| null>;

Defined in: server/access/grant-repository.ts:168

The single ACTIVE grant matching the partial unique index's tuple (scope_key, subject_type, subject_id, role_id, grant_fingerprint WHERE deleted_at IS NULL), or null. Used by GrantService.ensure to resolve the row a P2002 collided with — Prisma cannot upsert against a partial index, because a partial index is not expressible in the schema.

Parameters

ParameterType
input{ grantFingerprint: string; roleId: string; scopeKey: string; subjectId: string; subjectType: SubjectType; }
input.grantFingerprintstring
input.roleIdstring
input.scopeKeystring
input.subjectIdstring
input.subjectTypeSubjectType

Returns

Promise< | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } | null>


findActiveForSubject()

findActiveForSubject(
   scopeKey: string, 
   subjectType: SubjectType, 
   subjectId: string, 
   groupIds?: string[]
): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}[]>;

Defined in: server/access/grant-repository.ts:141

Active grants for a subject within a scope, plus active grants to any group the subject belongs to. groupIds is resolved by the caller from RbacGroupMemberships. Used to compile the PermissionSnapshot.

Parameters

ParameterTypeDefault value
scopeKeystringundefined
subjectTypeSubjectTypeundefined
subjectIdstringundefined
groupIdsstring[][]

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }[]>


findById()

findById(id: string): Promise<
  | {
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}
| null>;

Defined in: server/persistence/base-repository.ts:177

Parameters

ParameterType
idstring

Returns

Promise< | { conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; } | null>

Inherited from

CrudRepository.findById


findByIdOrThrow()

findByIdOrThrow(id: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/persistence/base-repository.ts:181

Parameters

ParameterType
idstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Inherited from

CrudRepository.findByIdOrThrow


findMany()

findMany(pagination: {
  page: number;
  pageSize: number;
}): Promise<OffsetPaginatedResult<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>>;

Defined in: server/persistence/base-repository.ts:195

Parameters

ParameterType
pagination{ page: number; pageSize: number; }
pagination.pagenumber
pagination.pageSizenumber

Returns

Promise<OffsetPaginatedResult<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>>

Inherited from

CrudRepository.findMany


findSubjectsForRole()

findSubjectsForRole(roleId: string): Promise<{
  scopeKey: string;
  subjectId: string;
  subjectType: SubjectType;
}[]>;

Defined in: server/access/grant-repository.ts:251

Introspection: which subjects hold a given role?

Parameters

ParameterType
roleIdstring

Returns

Promise<{ scopeKey: string; subjectId: string; subjectType: SubjectType; }[]>


hardDelete()

hardDelete(id: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/persistence/base-repository.ts:377

Parameters

ParameterType
idstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Inherited from

CrudRepository.hardDelete


loadConditionsTable()

loadConditionsTable(conditionIds: string[]): Promise<Record<string, {
  condition_type: string;
  config: AccessRecord;
  created_at: string;
  created_by: string;
  description: string | null;
  domain: string;
  id: string;
  module: string | null;
  name: string | null;
  organization_id: string;
}>>;

Defined in: server/access/grant-repository.ts:194

Load the engine-shape conditions table for the given condition ids, inlining config from each condition's current version. ABAC reuses the shared rules conditions / condition_versions tables, so this read lives here (where this.tx is already typed against the full client) rather than the AccessService reaching into a private handle.

Parameters

ParameterType
conditionIdsstring[]

Returns

Promise<Record<string, { condition_type: string; config: AccessRecord; created_at: string; created_by: string; description: string | null; domain: string; id: string; module: string | null; name: string | null; organization_id: string; }>>


logActivity()

protected logActivity(
   _entityId: string, 
   _action: string, 
   _metadata?: Record<string, unknown>
): Promise<void>;

Defined in: server/persistence/base-repository.ts:140

Log an activity entry.

NOTE: This is not implemented because there's no activity model implemented in taproot yet! https://linear.app/kaizenlabs/issue/ENG-7846/add-activity-log-tables

Parameters

ParameterType
_entityIdstring
_actionstring
_metadata?Record<string, unknown>

Returns

Promise<void>

Inherited from

CrudRepository.logActivity


notFoundError()

protected notFoundError(id: string): Error;

Defined in: server/access/grant-repository.ts:55

Create a not-found error. Override to provide custom error types.

Parameters

ParameterType
idstring

Returns

Error

Overrides

CrudRepository.notFoundError


softDelete()

softDelete(id: string): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/persistence/base-repository.ts:366

Parameters

ParameterType
idstring

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Inherited from

CrudRepository.softDelete


update()

update(id: string, input: Partial<{
  conditionLogic: InputJsonValue;
  selector: InputJsonValue;
}>): Promise<{
  conditionLogic: JsonValue;
  createdAt: Date;
  createdBy: string | null;
  deletedAt: Date | null;
  deletedBy: string | null;
  effectiveEnd: Date | null;
  effectiveStart: Date | null;
  grantFingerprint: string;
  id: string;
  organizationId: string | null;
  roleId: string;
  scopeKey: string;
  scopeType: RbacScopeType;
  selector: JsonValue;
  subjectId: string;
  subjectType: RbacSubjectType;
  updatedAt: Date;
  updatedBy: string | null;
}>;

Defined in: server/persistence/base-repository.ts:301

Parameters

ParameterType
idstring
inputPartial<{ conditionLogic: InputJsonValue; selector: InputJsonValue; }>

Returns

Promise<{ conditionLogic: JsonValue; createdAt: Date; createdBy: string | null; deletedAt: Date | null; deletedBy: string | null; effectiveEnd: Date | null; effectiveStart: Date | null; grantFingerprint: string; id: string; organizationId: string | null; roleId: string; scopeKey: string; scopeType: RbacScopeType; selector: JsonValue; subjectId: string; subjectType: RbacSubjectType; updatedAt: Date; updatedBy: string | null; }>

Inherited from

CrudRepository.update

On this page

ExtendsConstructorsConstructorParametersReturnsInherited fromPropertiesENTITY_TYPE?Inherited fromlogger?Inherited fromprismaClientInherited fromAccessorsactorIdGet SignatureReturnsInherited fromauditCreateGet SignatureReturnscreatedByupdatedByInherited fromauditDeleteGet SignatureReturnsdeletedAtdeletedByInherited fromauditUpdateGet SignatureReturnsupdatedByInherited fromsilentGet SignatureExampleReturnsInherited fromtxGet SignatureReturnsInherited fromMethods_count()ReturnsOverrides_create()ParametersReturnsOverrides_exists()ParametersReturnsOverrides_findById()ParametersReturnsOverrides_findMany()ParametersReturnsOverrides_hardDelete()ParametersReturnsOverrides_softDelete()ParametersReturnsOverrides_update()ParametersReturnsOverridesafterCreate()ParametersReturnsInherited fromafterDelete()ParametersReturnsInherited fromafterUpdate()ParametersReturnsInherited frombeforeCreate()ParametersReturnsInherited frombeforeDelete()ParametersReturnsInherited frombeforeUpdate()ParametersReturnsInherited fromconsumeSilent()ReturnsInherited fromcount()ReturnsInherited fromcreate()ParametersReturnsInherited fromexists()ParametersReturnsInherited fromfindActiveByRoleId()ParametersReturnsfindActiveByTuple()ParametersReturnsfindActiveForSubject()ParametersReturnsfindById()ParametersReturnsInherited fromfindByIdOrThrow()ParametersReturnsInherited fromfindMany()ParametersReturnsInherited fromfindSubjectsForRole()ParametersReturnshardDelete()ParametersReturnsInherited fromloadConditionsTable()ParametersReturnslogActivity()ParametersReturnsInherited fromnotFoundError()ParametersReturnsOverridessoftDelete()ParametersReturnsInherited fromupdate()ParametersReturnsInherited from