ReadonlyDescriptionHuman-readable description of what this provider covers.
ReadonlyDomainOpt-in marker read by ClassFactory (see ClassResolutionResult): this class CANNOT
function standalone — every member below is abstract, so a base instance is a method-less
stub. TypeScript's abstract is erased at runtime, so the factory cannot detect that on its
own; without this marker an unresolvable ProviderClassName would silently be handed back
as a live "provider" and blow up later at the first method call.
With the marker set, CreateInstance throws and TryCreateInstance returns
{Resolved: false, Instance: null} — both of which PermissionEngine handles by skipping
the domain.
ReadonlySupportedWhat actions this provider can evaluate.
ReadonlySupportedWhat grantee types this provider supports.
ReadonlySupportsWhether this provider supports explicit Deny records.
ProtectedboolsMap a { Read?: boolean, Update?: boolean, … } descriptor to a canonical
PermissionAction[]. Replaces the 9 hand-rolled copies that each walked
their row's CRUD-ish booleans and pushed action names.
Output order matches the canonical order declared in PermissionAction.
Entries that are null/undefined/false are skipped.
ProtectedbuildBuild a NormalizedPermission with DomainName and Effect
pre-filled from the provider. Centralizes the ~10-field literal that
used to be constructed in every GetUserResources / GetEffectivePermissions /
GetResourcePermissions implementation.
Effect defaults to 'Allow' since the vast majority of providers don't
support Deny. Providers that emit Deny records (EntityPermissionProvider)
pass { effect: 'Deny' } explicitly.
ProtectedbulkGiven a list of IDs, fetch {ID, <nameField>} from entityName and return
a Map<ID, name>. Used by providers whose domain views don't denormalize
a resource name onto the permission row (AI Agents, Artifacts, Collections).
Returns an empty Map when ids is empty or the RunView fails — callers should
treat a missing key as "name unknown."
OptionalnameField: stringCheck if a user has a specific permission on a specific resource.
The user whose permissions are being checked (roles come from user.UserRoles).
The resource type within this domain (e.g., entity name, resource type name).
The specific resource ID; null for domain-wide checks.
The action being requested.
Optionalprovider: IMetadataProviderProtectedfetchStandard RunView wrapper that logs failures with <ProviderClass>.<methodName>:
prefix and returns the row list (or [] on failure). Replaces the boilerplate
that each provider previously carried around its RunView calls.
Get all effective permissions a user has on a specific resource. Returns an empty array when the user has no access.
Optionalprovider: IMetadataProviderDefault implementation returns [] — role-only providers don't support user-granted
sharing. User-granted-sharing providers (Dashboards, Artifacts, Collections, Resource
Permissions, Access Control Rules) should override this to query their source table.
Optional_provider: IMetadataProviderDefault implementation returns [] — role-only providers have no "shared with me"
concept. User-grantee providers should override this to return only permissions where
grantee is the direct grantee AND someone else is the grantor/owner.
Optional_provider: IMetadataProviderGet all permissions granted on a specific resource across every grantee. Powers the Sharing Center's "Resource Access Report" view.
Optionalprovider: IMetadataProviderDefault implementation returns [] — providers should override to advertise
their supported resource types (see IPermissionProvider.GetResourceTypes).
Optionalprovider: IMetadataProviderGet all resources within this domain that the user has access to. Powers the Sharing Center's "User Access Report" view.
OptionalresourceType: stringOptional filter to one resource type within the domain.
Optionalprovider: IMetadataProvider
Wraps the Metadata +
EntityInfo.GetUserPermisions()path behind the unified PermissionProviderBase contract. Entity permissions are role-only, additive (OR across roles), and cover the CRUD action set only.resourceTypeis the entity name (e.g.,"Users").resourceIdis unused — entity permissions are domain-wide per entity, not per-row. Row-level filters are a separate concern handled by the RLS system.