npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

userly-acl

v0.1.0

Published

Userly authorization snapshot and ACL evaluator helper for resource servers

Readme

userly-acl

userly-acl нь Userly resource server/backend дээр authorization snapshot ашиглан role, permission, policy check хийх helper package.

Энэ package OAuth/OIDC login SDK биш. Login redirect, Authorization Code + PKCE, refresh token rotation, browser session/cookie management хийхгүй.

Release 1 scope

  • Access token claim болон authorization snapshot consistency check.
  • hasRole() болон can() authorization evaluator.
  • System Role -> Permission direct check.
  • Tenant Top Role -> Child Role -> Permission -> Policy expansion.
  • Explicit system + resource болон tenant + tenant_id + resource scope consistency.
  • Built-in policy guard evaluator: time_window, ip_allowlist, ip_denylist, owner_only.
  • Snapshot fetch helper, Userly-ACL-Version header injection, ETag support.
  • authz.snapshot_changed, authz.subject_changed webhook payload parser.

Snapshot-г заавал network-оор fetch хийх албагүй. sysop-server, tenant-server зэрэг first-party server snapshot data-г өөрөө build/fill хийгээд evaluator-д өгч болно.

Install

npm install userly-acl

Snapshot fetch

fetchAuthorizationSnapshot() нь /authz/snapshot endpoint-оос snapshot авна. Client authentication буюу private_key_jwt assertion үүсгэхийг энэ package хийхгүй. Caller нь бэлэн Authorization header дамжуулна.

import { fetchAuthorizationSnapshot } from "userly-acl";

const result = await fetchAuthorizationSnapshot({
    baseUrl: "https://auth.example.mn",
    scope: "tenant",
    tenantId: "tenant-id",
    resource: "crm-api",
    etag: previousEtag,
    authorizationHeader: async () => `Bearer ${await createClientAssertion()}`
});

if (!result.notModified && result.snapshot) {
    cache.set("crm-api:tenant-id", {
        etag: result.etag,
        snapshot: result.snapshot
    });
}

ACL check

import { createAclEvaluator } from "userly-acl";

const acl = createAclEvaluator(snapshot);
const decision = acl.can({
    token: accessTokenClaims,
    permission: "customer.read",
    context: {
        ipAddress: requestIp
    }
});

if (!decision.allowed) {
    throw new Error(decision.code);
}

hasRole() нь access token дээрх role claim тухайн snapshot дээр байгаа эсэхийг шалгана. can() нь role expansion, permission, policy guard бүгдийг шалгана.

Webhook

Userly дээр ACL snapshot эсвэл subject state өөрчлөгдвөл resource server webhook авч cache refresh хийж болно.

import { parseAuthzWebhookEvent } from "userly-acl";

const event = parseAuthzWebhookEvent(requestBody);

if (event.event === "authz.snapshot_changed") {
    await refreshSnapshot(event.scope, event.resource, event.tenantId);
}

if (event.event === "authz.subject_changed") {
    await refreshSubjectState(event.userId, event.scope, event.tenantId);
}

Version compatibility

Package нь snapshot request бүр дээр Userly-ACL-Version header илгээнэ. Default утга нь package version-тэй ижил байна.

Release 1 publish эхлэх version: 0.1.0.

Publish checklist

npm run typecheck -w userly-acl
npm run test -w userly-acl
npm pack --dry-run -w userly-acl
npm publish -w userly-acl

npm pack --dry-run output дээр зөвхөн dist, README.md, package.json орсон байх ёстой.