Interface: PermissionSnapshot
Defined in: shared/access/types.ts:162
The full server-only policy for a subject, compiled once per request. NEVER sent to the browser — it would leak role names, org structure, and policy logic. The client gets the minimized CapabilitySnapshot instead.
Properties
conditionsTable?
optional conditionsTable?: Record<string, Condition>;Defined in: shared/access/types.ts:182
Conditions table keyed by Conditions.id, inlined from the current
ConditionVersions. Threaded into the ABAC walker; built server-side
(requires Prisma row shapes), so it is optional on the shared type.
grants
grants: CompiledGrant[];Defined in: shared/access/types.ts:170
roleVersionIds
roleVersionIds: string[];Defined in: shared/access/types.ts:176
Role version ids that contributed to this snapshot. (v1 compiles fresh per request; a v2 cache would fold these into its key — see the deferred snapshot cache in docs/rbac/design.md.)
scopes
scopes: GrantScope[];Defined in: shared/access/types.ts:169
The scope chain this snapshot was compiled over, [0] being the target of
the check — see scopeChain. The kernel ORs across the resulting grants
and never reads scope itself.
subject
subject: Subject;Defined in: shared/access/types.ts:163