@accesscontroll/sdk
v0.0.5
Published
AccessControl PEP SDK — shared PDP URL + per-app applicationId
Readme
@accesscontrol/sdk
Node PEP: calls a shared PDP for decisions and the PAP API for user sync.
Decisions: App → POST /v1/decide → ALLOW / DENY
User sync: App → POST /api/sdk/users/register|remove → PAP PortalUsersUsage
import { create } from "@accesscontrol/sdk";
const ac = create({
pdpUrl: process.env.AC_PDP_URL || "http://127.0.0.1:8181",
papUrl: process.env.AC_PAP_URL || "http://127.0.0.1:8081",
applicationId: process.env.AC_APPLICATION_ID,
applicationSecret: process.env.AC_APPLICATION_SECRET,
});
// Authorization check (PDP) — pass role keys, not GUIDs
const { allowed } = await ac.check({
user: { roles: ["user"], attributes: { family: "relative" } },
resource: "shareddocs",
action: "getfiles",
});
// Resource-set conditions may need resource attributes
await ac.check({
user: { roles: ["user"], attributes: { family: "relative" } },
resource: { key: "internal_files", attributes: { tag: "internal" } },
action: "getfiles",
});
// UI permission map — role matrix, or matched user-set when attributes match
const { permissions } = await ac.getPermissions({
roles: ["user"],
attributes: { family: "relative" },
});
// Sync user on portal signup (PAP) — role key → group membership
await ac.registerUser({
name: "Jane Doe",
email: "[email protected]",
externalId: "portal-user-uuid",
role: "user",
attributeValues: { family: "relative" },
});
// Remove user on portal delete (PAP)
await ac.removeUser({ email: "[email protected]" });Environment
| Variable | Purpose |
|----------|---------|
| AC_PDP_URL | Decision service base URL |
| AC_PAP_URL | Policy admin API base URL |
| AC_APPLICATION_ID | Application UUID (from PAP URL) |
| AC_APPLICATION_SECRET | App secret from PAP credentials page |
Methods
| Method | Target | Description |
|--------|--------|-------------|
| check | PDP | Allow/deny decision |
| assert | PDP | Throws if denied |
| checkMany | PDP | Batch decisions |
| getPermissions | PDP | Grant map for UI |
| decide | PDP | Raw decide response |
| status | PDP | Bundle sync status |
| register | PDP | Register app for polling |
| resolveRolesByEmail | PAP | Look up group → role keys by email |
| registerUser | PAP | Create or update portal user (idempotent by email) |
| removeUser | PAP | Delete user by id, email, or externalId |
ABAC notes
- User sets and resource sets are dynamic (condition
whentrees). There is no “add user to set.” - Send
user.attributeson eachcheck/getPermissions. When attributes match a user-set, the PDP uses that set’s matrix only; otherwise the role matrix. - PAP Custom Attribute Values are for admin testing / optional sync — the PDP does not read them at decide time unless your app forwards them as
attributes.
registerUser
Creates a user in the RBAC system when a user is created in your portal. If the email already exists for the application, updates the record instead.
Pass role (PAP role key, e.g. "user"). PAP finds the group linked to that role and sets exclusive membership (one group per user). Do not pass group IDs from portal apps.
removeUser
Removes a user from the RBAC system when deleted in your portal. Provide one of: id, email, or externalId.
