Member Junction
    Preparing search index...

    Class PermissionProviderBaseAbstract

    Abstract base class that every concrete permission provider extends. Serves as both the TypeScript type and the runtime ClassFactory key, mirroring the pattern used by BaseFormComponent / BaseResourceComponent.

    Register concrete providers with: @RegisterClass(PermissionProviderBase, 'MyProviderName') where 'MyProviderName' matches the ProviderClassName column in the PermissionDomain catalog.

    @RegisterClass(PermissionProviderBase, 'MJEntityPermissionProvider')
    export class EntityPermissionProvider extends PermissionProviderBase {
    readonly DomainName = 'Entity Permissions';
    // ... implement abstract methods
    }

    Hierarchy (View Summary)

    Implements

    Index

    Constructors

    Properties

    Description: string

    Human-readable description of what this provider covers.

    DomainName: string

    Opt-in marker read by ClassFactory (see ClassResolutionResult): this class CANNOT function standalone — every member below is abstract, so a base instance is a method-less stub. TypeScript's abstract is erased at runtime, so the factory cannot detect that on its own; without this marker an unresolvable ProviderClassName would silently be handed back as a live "provider" and blow up later at the first method call.

    With the marker set, CreateInstance throws and TryCreateInstance returns {Resolved: false, Instance: null} — both of which PermissionEngine handles by skipping the domain.

    SupportedActions: PermissionAction[]

    What actions this provider can evaluate.

    SupportedGranteeTypes: GranteeType[]

    What grantee types this provider supports.

    SupportsDeny: boolean

    Whether this provider supports explicit Deny records.

    Methods

    • Map a { Read?: boolean, Update?: boolean, … } descriptor to a canonical PermissionAction[]. Replaces the 9 hand-rolled copies that each walked their row's CRUD-ish booleans and pushed action names.

      Output order matches the canonical order declared in PermissionAction. Entries that are null/undefined/false are skipped.

      Parameters

      Returns PermissionAction[]

      const actions = this.boolsToActions({
      Read: row.CanRead,
      Update: row.CanEdit, // domain-specific flag name
      Delete: row.CanDelete,
      Share: row.CanShare,
      });
      // → ['Read', 'Update', 'Delete', 'Share'] // in this order, where truthy
    • Build a NormalizedPermission with DomainName and Effect pre-filled from the provider. Centralizes the ~10-field literal that used to be constructed in every GetUserResources / GetEffectivePermissions / GetResourcePermissions implementation.

      Effect defaults to 'Allow' since the vast majority of providers don't support Deny. Providers that emit Deny records (EntityPermissionProvider) pass { effect: 'Deny' } explicitly.

      Parameters

      • args: {
            actions: PermissionAction[];
            effect?: "Allow" | "Deny";
            expiresAt?: Date;
            granteeId: string;
            granteeName?: string;
            granteeType: GranteeType;
            resourceId: string;
            resourceName?: string;
            resourceType: string;
            sourceRecordId?: string;
        }

      Returns NormalizedPermission

    • Given a list of IDs, fetch {ID, <nameField>} from entityName and return a Map<ID, name>. Used by providers whose domain views don't denormalize a resource name onto the permission row (AI Agents, Artifacts, Collections).

      Returns an empty Map when ids is empty or the RunView fails — callers should treat a missing key as "name unknown."

      Parameters

      • entityName: string
      • ids: string[]
      • nameField: string = 'Name'

      Returns Promise<Map<string, string>>

    • Standard RunView wrapper that logs failures with <ProviderClass>.<methodName>: prefix and returns the row list (or [] on failure). Replaces the boilerplate that each provider previously carried around its RunView calls.

      Type Parameters

      • T

      Parameters

      • entityName: string
      • extraFilter: string
      • fields: string[]
      • methodName: string

      Returns Promise<T[]>

      const rows = await this.fetchRows<MyRow>(
      'MJ: AI Agent Permissions',
      `AgentID='${agentId}'`,
      ['ID', 'AgentID', 'CanView', 'CanRun'],
      'fetchPermissionsForAgent'
      );