@saysyes/engine
v0.1.1
Published
Authorization decisions in your process. No sidecar, no network hop.
Maintainers
Readme
@saysyes/engine
Authorization that runs inside your own process. Write who may do what in one small policy file; the engine compiles it to WebAssembly and answers every check in-process, in a few microseconds, with the rule that decided.
import { createAuthz } from '@saysyes/engine';
const authz = await createAuthz({ policy }); // once, at boot
authz.document.can(user, 'write', doc); // true or false
authz.document.explain(user, 'write', doc); // which rule decidedPass { apiKey } instead of policy to fetch the policy from a SaysYes
workspace at boot, and change rules from the dashboard without a deploy.
Works in Node, Deno, Bun, Workers and browsers. No build step, no sidecar. The engine is Apache 2.0. Documentation: https://saysyes.dev
Subject ids
A subject is whoever is asking: a person, a service, or an agent. Its id is your own internal id, prefixed by kind so the kinds never collide:
user_7f3a a person
svc_billing a service
agent_planner an agentPass that id as user.id to can(), and use the same id when granting a
role or adding a relationship. Never use an email address: it is personal
data, and the control plane refuses ids containing @. Names, emails and
attributes stay in your app and travel with the check, in-process.
Staying current
With an apiKey, the engine downloads the policy, the role grants and the
relationship edges once, then refreshes from the control plane's change
stream every 5 seconds (refreshMs; 0 turns the timer off). A role granted
or revoked in the dashboard decides in your process within that window.
A policy change takes a fresh snapshot. Call authz.refresh() to pull
changes now, and authz.close() when the service shuts down.
Roles and relations your app passes with a check are honoured alongside the ones held in the dashboard; either alone is a complete way to run.
