fix(authz): reserve role inheritance namespace
Quality / quality (ubuntu-latest) (push) Failing after 21s
Quality / quality (windows-latest) (push) Canceled after 0s

This commit is contained in:
2026-08-23 19:35:03 +05:30
parent 4be4b2c346
commit 56cde5aaf8
4 changed files with 13 additions and 2 deletions
+1 -1
View File
@@ -257,7 +257,7 @@
},
"packages/authz": {
"name": "@wrnexus/authz",
"version": "0.8.14",
"version": "0.8.15",
"dependencies": {
"@wrnexus/core": "workspace:*",
"@wrnexus/db": "workspace:*",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@wrnexus/authz",
"version": "0.8.14",
"version": "0.8.15",
"private": true,
"type": "module",
"main": "src/index.ts",
+5
View File
@@ -16,6 +16,11 @@ export function defineAuthz<Subject = any, Resource = any>(
const bindings = module.bindings ?? {};
for (const id of Object.keys(permissions)) {
if (id.startsWith("role:")) {
throw new Error(
`WRN-AUTHZ-DECL: permission id '${id}' uses the reserved 'role:' prefix; role grants use 'role:<name>' for inheritance.`,
);
}
if (id.includes("*")) {
throw new Error(
`WRN-AUTHZ-DECL: permission id '${id}' must not contain a wildcard; wildcards belong in roles.`,
+6
View File
@@ -26,6 +26,12 @@ describe("defineAuthz", () => {
expect(() => defineAuthz({ permissions: { "post:*": {} } })).toThrow(/wildcard/i);
});
test("rejects permission ids that collide with role inheritance", () => {
expect(() => defineAuthz({ permissions: { "role:assign": {} } })).toThrow(
/reserved 'role:' prefix/i,
);
});
test("rejects a role granting an unknown-shaped entry", () => {
expect(() => defineAuthz({ roles: { editor: [""] } })).toThrow(/role 'editor'/i);
});