generated from CodrJS/ts-npm-template
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
implement new policy, rule, authorization, and organization models
- Loading branch information
DylanBulmer
committed
Apr 7, 2024
1 parent
8109cc6
commit e1b9491
Showing
23 changed files
with
276 additions
and
162 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,10 +1,10 @@ | ||
import type { Types } from "mongoose"; | ||
import type { IBase } from "./Base"; | ||
import type { ActionType, EntityType } from "../types"; | ||
import type { ActionEnum, ResourceEnum } from "../types"; | ||
|
||
export interface IAudit extends Omit<IBase<"Audit">, "createdBy"> { | ||
entityType: EntityType; // (where) what entity got modified | ||
action: ActionType; // action taken | ||
entityType: ResourceEnum; // (where) what entity got modified | ||
action: ActionEnum; // action taken | ||
userId: Types.ObjectId; // who | ||
payload: object; // what data got modified | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
import type { Types } from "mongoose"; | ||
import { Base, IBase } from "./Base"; | ||
import type { ActionType, AtLeast, ResourceType } from "@/types"; | ||
|
||
export interface IAuthorization extends IBase<"Authorization"> { | ||
userId: Types.ObjectId; | ||
roleId: Types.ObjectId[]; | ||
} | ||
|
||
export interface IAuthorizationResponse { | ||
userId: Types.ObjectId; | ||
roleCodes: string[]; | ||
grants: Partial<Record<ResourceType, Partial<Record<ActionType, boolean>>>>; | ||
} | ||
|
||
export class Authorization extends Base { | ||
userId: Types.ObjectId; | ||
roleId: Types.ObjectId[]; | ||
|
||
constructor({ | ||
userId, | ||
roleId = [], | ||
_id, | ||
__v, | ||
createdAt, | ||
updatedAt, | ||
createdBy, | ||
updatedBy, | ||
}: AtLeast<IAuthorization, "createdBy" | "userId">) { | ||
super({ _id, __v, createdAt, updatedAt, createdBy, updatedBy }); | ||
this.userId = userId; | ||
this.roleId = roleId; | ||
} | ||
|
||
toJSON() { | ||
const json = super.toJSON(); | ||
return { | ||
userId: this.userId, | ||
roles: this.roleId, | ||
...json, | ||
}; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,54 @@ | ||
import { Group, IGroup } from "./Group"; | ||
|
||
interface Flags { | ||
isActive: boolean; | ||
isDeleted: boolean; | ||
} | ||
export interface IOrganization extends IGroup<"Organization", Flags> { | ||
slug: string; | ||
domain: string; // to restrict signin to a specified domain | ||
} | ||
|
||
export class Organization extends Group { | ||
readonly slug: string; | ||
readonly domain: string; | ||
|
||
constructor({ | ||
flags = { | ||
isActive: true, | ||
isDeleted: false, | ||
}, | ||
_id, | ||
__v, | ||
createdAt, | ||
updatedAt, | ||
createdBy, | ||
updatedBy, | ||
name, | ||
members, | ||
slug, | ||
domain, | ||
}: IOrganization) { | ||
super({ | ||
_id, | ||
__v, | ||
createdAt, | ||
updatedAt, | ||
createdBy, | ||
updatedBy, | ||
name, | ||
members, | ||
flags, | ||
}); | ||
this.slug = slug; | ||
this.domain = domain; | ||
} | ||
|
||
toJSON() { | ||
const json = super.toJSON(); | ||
return { | ||
...json, | ||
slug: this.slug, | ||
}; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,62 @@ | ||
import { Base, IBase } from "./Base"; | ||
import { User } from "./User"; | ||
import { AtLeast, JwtPayload } from "@/types"; | ||
import { ActionEnum, ResourceEnum } from "@/types/Permissions"; | ||
|
||
export interface IGrant<R = object> { | ||
resource: ResourceEnum; | ||
actions: ActionEnum[]; | ||
conditions: { | ||
operator: "eq" | "within"; | ||
subjectField: keyof JwtPayload; | ||
resourceField: keyof R; | ||
actions?: ActionEnum[]; | ||
}[]; | ||
} | ||
|
||
export interface IRole extends IBase<"Role"> { | ||
name: string; | ||
code: string; | ||
description: string; | ||
grants: IGrant[]; | ||
} | ||
|
||
export class Role extends Base { | ||
name: string; | ||
code: string; | ||
description?: string; | ||
grants: IGrant[]; | ||
|
||
constructor({ | ||
name, | ||
code, | ||
description, | ||
grants, | ||
_id, | ||
__v, | ||
createdAt, | ||
updatedAt, | ||
createdBy, | ||
updatedBy, | ||
}: AtLeast< | ||
IRole & { user: User }, | ||
"createdBy" | "name" | "code" | "description" | "grants" | ||
>) { | ||
super({ _id, __v, createdAt, updatedAt, createdBy, updatedBy }); | ||
this.name = name; | ||
this.code = code; | ||
this.description = description; | ||
this.grants = grants; | ||
} | ||
|
||
toJSON() { | ||
const json = super.toJSON(); | ||
return { | ||
name: this.name, | ||
code: this.code, | ||
description: this.description, | ||
grants: this.grants, | ||
...json, | ||
}; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.