Interface: CreateGrantGuard
Defined in: server/access/grant-service.ts:32
Properties
actor
actor: {
id: string;
type: SubjectType;
};Defined in: server/access/grant-service.ts:51
Identifies the acting subject. Everything else about them is derived server-side and NOTHING is caller-asserted:
- their held permissions come from the shared H3
coarsePermissionsForActor, over the scope chain of the grant's own target scope (input.scope); the new grant's role must be a SUBSET of that derived set (and each permission delegable), enforcing "you can only grant what you hold"; - their FOOTING — which scopes actually back them — comes from the same
load, and is what the
self-orgcap reads.
There is deliberately no actorOrganizationId. It was the module's only
caller-asserted security input, was never verified against anything, and
no value made the cap it fed mean something: passing the target org (what
every caller did) made self-org a tautology, while passing a
platform-scoped actor's null made it always throw.
id
id: string;type
type: SubjectType;