Skip to main content

checkModelPermission

@webda/core


Function: checkModelPermission()

checkModelPermission(object, context, action, model?): Promise<void>

Defined in: packages/core/src/models/permissions.ts:284

Enforce a model's permission for an action on an object: the single check used by every client path (REST, gRPC, MCP, GraphQL and any transport dispatching operations)

A caller who may not read the object (canAct(ctx, "get", object) refused) gets exactly the error of a missing object (NotFound("Object not found")), whatever the action, so a refusal never reveals that the key exists. A caller who may read the object but not perform the action gets a Forbidden. On "create" the object does not exist yet: a refusal is always a Forbidden.

The refusal reason returned by canAct is logged, never sent to the client.

Parameters​

object​

any

the model instance

context​

IOperationContext

the caller context

action​

string

the action name

model?​

any

the model class (defaults to the object's class)

Returns​

Promise<void>

Throws​

WebdaError.NotFound when the caller may not read the object

Throws​

WebdaError.Forbidden when the caller may read the object but not perform the action