import { InferredAttributes } from "../../../runtime/types.mjs"; import { UserBooleanArrayOperand, UserBooleanOperand, UserStringArrayOperand, UserStringOperand } from "../../types/permission-operand.types.mjs"; //#region src/configure/services/tailordb/permission.d.ts /** * Record-level permission configuration for a TailorDB table. * Defines create, read, update, and delete permissions. * * Prefer object format with explicit `conditions` and `permit` for readability. * Shorthand array format is supported for compatibility, but less readable. * * For update operations, use `newRecord`/`oldRecord` operands instead of `record`. * @example * const permission: TailorTypePermission = { * create: [{ conditions: [[{ user: "_loggedIn" }, "=", true]], permit: true }], * read: [{ conditions: [[{ record: "isPublic" }, "=", true]], permit: true }], * update: [{ conditions: [[{ newRecord: "ownerId" }, "=", { user: "id" }]], permit: true }], * delete: [{ conditions: [[{ record: "ownerId" }, "=", { user: "id" }]], permit: true }], * }; */ export type TailorTypePermission = { create: readonly ActionPermission<"record", User, Type, false>[]; read: readonly ActionPermission<"record", User, Type, false>[]; update: readonly ActionPermission<"record", User, Type, true>[]; delete: readonly ActionPermission<"record", User, Type, false>[]; }; type ActionPermission = { conditions: PermissionCondition | readonly PermissionCondition[]; description?: string | undefined; /** * Whether matching records are granted (`true`) or denied (`false`). * Omitting `permit` in this object form defaults to `deny` and emits a * warning; set it explicitly. (The array shorthand defaults to `allow`.) */ permit?: boolean; } | readonly [...PermissionCondition, ...([] | [boolean])] | readonly [...PermissionCondition[], ...([] | [boolean])]; export type TailorTypeGqlPermission = readonly GqlPermissionPolicy[]; type GqlPermissionPolicy = { conditions: readonly PermissionCondition<"gql", User, boolean, Type>[]; actions: "all" | readonly GqlPermissionAction[]; /** * Whether matching requests are granted (`true`) or denied (`false`). * Omitting `permit` defaults to `deny` and emits a warning; set it explicitly. */ permit?: boolean; description?: string; }; type GqlPermissionAction = "read" | "create" | "update" | "delete" | "aggregate" | "bulkUpsert"; type EqualityOperator = "=" | "!="; type ContainsOperator = "in" | "not in"; type HasAnyOperator = "hasAny" | "not hasAny"; type RecordOperand = Update extends true ? { oldRecord: (keyof Type & string) | "id"; } | { newRecord: (keyof Type & string) | "id"; } : { record: (keyof Type & string) | "id"; }; type StringEqualityCondition = (Level extends "gql" ? readonly [string, EqualityOperator, boolean] : never) | readonly [string, EqualityOperator, string] | readonly [UserStringOperand, EqualityOperator, string] | readonly [string, EqualityOperator, UserStringOperand] | (Level extends "record" ? readonly [RecordOperand, EqualityOperator, string | UserStringOperand] | readonly [string | UserStringOperand, EqualityOperator, RecordOperand] : never); type BooleanEqualityCondition = readonly [boolean, EqualityOperator, boolean] | readonly [UserBooleanOperand, EqualityOperator, boolean] | readonly [boolean, EqualityOperator, UserBooleanOperand] | (Level extends "record" ? readonly [RecordOperand, EqualityOperator, boolean | UserBooleanOperand] | readonly [boolean | UserBooleanOperand, EqualityOperator, RecordOperand] : never); type EqualityCondition = StringEqualityCondition | BooleanEqualityCondition; type StringContainsCondition = readonly [string, ContainsOperator, string[]] | readonly [UserStringOperand, ContainsOperator, string[]] | readonly [string, ContainsOperator, UserStringArrayOperand] | (Level extends "record" ? readonly [RecordOperand, ContainsOperator, string[] | UserStringArrayOperand] | readonly [string | UserStringOperand, ContainsOperator, RecordOperand] : never); type BooleanContainsCondition = (Level extends "gql" ? readonly [string, ContainsOperator, boolean[]] : never) | readonly [boolean, ContainsOperator, boolean[]] | readonly [UserBooleanOperand, ContainsOperator, boolean[]] | readonly [boolean, ContainsOperator, UserBooleanArrayOperand] | (Level extends "record" ? readonly [RecordOperand, ContainsOperator, boolean[] | UserBooleanArrayOperand] | readonly [boolean | UserBooleanOperand, ContainsOperator, RecordOperand] : never); type ContainsCondition = StringContainsCondition | BooleanContainsCondition; type HasAnyCondition = readonly [string[] | UserStringArrayOperand, HasAnyOperator, string[] | UserStringArrayOperand] | (Level extends "record" ? readonly [RecordOperand, HasAnyOperator, string[] | UserStringArrayOperand] | readonly [string[] | UserStringArrayOperand, HasAnyOperator, RecordOperand] : never); /** * Type representing a permission condition that combines user attributes, record fields, and literal values using comparison operators. * * The User type is extended by `tailor.d.ts`, which is automatically generated when running `tailor generate`. * Attributes enabled in the config file's `auth.userProfile.attributes` (or * `auth.machineUserAttributes` when userProfile is omitted) become available as types. * @example * ```ts * // tailor.config.ts * export const auth = defineAuth("my-auth", { * userProfile: { * type: user, * attributes: { * isAdmin: true, * roles: true, * } * } * }); * ``` */ export type PermissionCondition = EqualityCondition | ContainsCondition | HasAnyCondition; /** * Grants full record-level access without any conditions. * * Unsafe and intended only for local development, prototyping, or tests. * Do not use this in production environments, as it effectively disables * authorization checks. */ export declare const unsafeAllowAllTypePermission: TailorTypePermission; /** * Grants full GraphQL access (all actions) without any conditions. * * Unsafe and intended only for local development, prototyping, or tests. * Do not use this in production environments, as it effectively disables * authorization checks. */ export declare const unsafeAllowAllGqlPermission: TailorTypeGqlPermission; //#endregion