Beer Can Labs
Contracts / authorize
Contract

authorize

Whether a principal’s roles hold one named privilege on a resource. Every control-plane route calls it with exactly one privilege.

Signature

authorize({ principal, privilege, resource? })
  : AuthorizeResult

packages/bouncer/src/authorize.ts ↗

Rules

  • Roles map to privileges in one table inside the Bouncer.
  • agent-owner, agent-member and requester come from data, never from a credential.
  • A role check outside packages/bouncer and packages/auth fails conformance.
  • A route missing from the matrix test fails conformance.

Where it appears