Function: assertPolicyAllows()
function assertPolicyAllows(
booking: ComposedBookingRow,
event: string,
input: {
actorId: string;
allowLateCancel?: boolean;
allowOutsideHours?: boolean;
allowOverbook?: boolean;
allowTransfer?: boolean;
expectedVersion?: number;
reason?: string;
},
deps: PolicyGuardDeps
): Promise<void>;Defined in: server/bookings/policy-guards.ts:170
Assert the policy layer allows event on booking, or throw
PolicyDeniedError. Runs inside the transition's transaction (the rules
repositories route through the ambient TransactionManager client, so
reads join it automatically).
Parameters
| Parameter | Type | Description |
|---|---|---|
booking | ComposedBookingRow | - |
event | string | - |
input | { actorId: string; allowLateCancel?: boolean; allowOutsideHours?: boolean; allowOverbook?: boolean; allowTransfer?: boolean; expectedVersion?: number; reason?: string; } | - |
input.actorId | string | - |
input.allowLateCancel? | boolean | Admin late-cancel override (spec §7): when true, cancel skips the rules-engine cancellation policy guard and records a cancelled_by_admin timeline event instead — the same bypass-and-record contract as allowOverbook (§6.6). The CONSUMER owns the permission decision; taproot only honors + records the flag. Ignored on every event other than cancel. |
input.allowOutsideHours? | boolean | Admin outside-hours override (spec §6.9): when true, claiming transitions skip the window-containment check and record an hours_overridden_by_admin timeline event instead — the same bypass-and-record contract as allowOverbook. The CONSUMER owns the permission decision. |
input.allowOverbook? | boolean | Admin overbook override (spec §6.6): when true, claiming transitions skip the capacity/overlap check and record an overbooked_by_admin timeline event instead. The CONSUMER owns the permission decision — taproot is auth-agnostic and only honors + records the flag. |
input.allowTransfer? | boolean | Admin transfer override (spec §7.1): when true, the transfer/reschedule family skips the rules-engine policy guard for the transfer event and records a transfer_overridden_by_admin timeline event instead — the same bypass-and-record contract as allowLateCancel/allowOverbook. The CONSUMER owns the permission decision; taproot only honors + records the flag. Ignored on every event other than transfer. |
input.expectedVersion? | number | - |
input.reason? | string | - |
deps | PolicyGuardDeps | - |
Returns
Promise<void>