Entity
    Preparing search index...

    Class EntityPrivacyPolicy<TFields, TIDField, TViewerContext, TEntity, TSelectedFields>Abstract

    Privacy policy for an entity.

    A privacy policy declares lists of PrivacyPolicyRule for create, read, update, and delete actions for an entity and provides logic for authorizing an entity against rules.

    Evaluation of a list of rules is performed according the following example. This allows constructing of complex yet testable permissioning logic for an entity.

    foreach rule in rules:
    return authorized if rule allows
    return not authorized if rule denies
    continue to next rule if rule skips
    return not authorized if all rules skip

    Type Parameters

    Index
    createRules: readonly PrivacyPolicyRule<
        TFields,
        TIDField,
        TViewerContext,
        TEntity,
        TSelectedFields,
    >[] = []

    List of rules to evaluate for create authorization.

    deleteRules: readonly PrivacyPolicyRule<
        TFields,
        TIDField,
        TViewerContext,
        TEntity,
        TSelectedFields,
    >[] = []

    List of rules to evaluate for delete authorization.

    readRules: readonly PrivacyPolicyRule<
        TFields,
        TIDField,
        TViewerContext,
        TEntity,
        TSelectedFields,
    >[] = []

    List of rules to evaluate for read authorization.

    updateRules: readonly PrivacyPolicyRule<
        TFields,
        TIDField,
        TViewerContext,
        TEntity,
        TSelectedFields,
    >[] = []

    List of rules to evaluate for update authorization.

    • Produce an end-user-safe explanation for a denial of this policy. The result is attached to the thrown EntityNotAuthorizedError as userFacingReason.

      Parameters

      Returns EntityNotAuthorizedUserFacingReason | null

      The default returns null, meaning no user-facing explanation is available and callers should display a generic message. Override to map denials to messages appropriate for end users. When all rules skip, denialReason.skippedRules holds each skipped rule with the reason codes it contributed, so the policy can select a message for a specific reason, for example "You must be a member of this account to view this project." when a rule skipped with a NOT_ACCOUNT_MEMBER reason.

      The denied entity and the evaluation context are intentionally not passed to this method. The viewer is not authorized to see the entity, and the evaluation context may contain it (as the previous value or the cascading deletion cause), so neither may influence or appear in the user-facing message. Rules should instead communicate what is needed through reason codes.