feat(authz): reach the merged catalog from boot via a process-wide singleton
Fix round 1 for Task 14 — closes the gap flagged in the last report:
loadAppAuthzCatalog existed but nothing called it.
- packages/authz/src/client.ts (new): setAuthzCatalog/getAuthzCatalog/
hasAuthzCatalog, mirroring @wrnexus/db's client.ts. App middleware runs
at module-eval time and needs the catalog then, so ctx cannot carry it;
getAuthzCatalog() throws a setup error naming the fix, like getDb() does.
Exported from packages/authz/src/index.ts.
- packages/dev-server/src/index.ts: startServer calls loadAppAuthzCatalog +
setAuthzCatalog before middleware is resolved (schemasJs precedent),
and populates the new RuntimeDeps.authz field.
- packages/dev-server/src/runtime.ts: RuntimeDeps gains authz?: AuthzCatalog.
- packages/cli/src/build.ts: emits static imports of each app/authz/*.ts
file into the generated entry (components/layouts precedent) and passes
{ source, module } pairs through ProdOptions.authz — the catalog holds
policy functions, so it cannot be JSON-baked like schemasJs.
- packages/dev-server/src/prod.ts: createProductionHandlers merges those
declarations and calls setAuthzCatalog before the server accepts
traffic, so a conflict fails the boot instead of surfacing on the first
request. Runs for every deployment adapter, not only Bun.serve.
The framework never installs authzMiddleware itself; the app still
registers it with its own store.
Verified end-to-end: added a temporary app/authz declaration to
examples/basic-app, ran `bun run build`, inspected the generated entry's
static import + authz array, and booted dist/server.js to confirm the
merge/setAuthzCatalog call succeeds against real bundled code (reverted
before commit).
This commit is contained in:
@@ -506,7 +506,9 @@
|
||||
"filterAuthorized",
|
||||
"filterCan",
|
||||
"generatePermissionTypes",
|
||||
"getAuthzCatalog",
|
||||
"guardPermission",
|
||||
"hasAuthzCatalog",
|
||||
"hasRole",
|
||||
"memoryAuditSink",
|
||||
"memoryPermissionStore",
|
||||
@@ -516,7 +518,8 @@
|
||||
"requirePermission",
|
||||
"requireRole",
|
||||
"safeRecord",
|
||||
"scopeKey"
|
||||
"scopeKey",
|
||||
"setAuthzCatalog"
|
||||
],
|
||||
"./db": [
|
||||
"authzMigrationSql",
|
||||
|
||||
Reference in New Issue
Block a user