Interface: CreateVersionGuard
Defined in: server/access/role-service.ts:36
The role-edit guard: identifies the acting subject only. Their held
permissions are NEVER caller-supplied — createVersion derives them
server-side via the shared H3 coarsePermissionsForActor (the same
unconditionally-held-only derivation GrantService.create uses), over the
scope chain of the role's own organization. Accepting a caller-asserted
permission array here would let a selector/condition-narrowed permission be
copied into a role and become unconstrained for every holder of that role.
Properties
actor
actor: {
id: string;
type: SubjectType;
};Defined in: server/access/role-service.ts:37
id
id: string;type
type: SubjectType;