{"_id":"@adobedjangir/aio-commerce-lib-ims-access","name":"@adobedjangir/aio-commerce-lib-ims-access","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@adobedjangir/aio-commerce-lib-ims-access","version":"1.0.0","description":"Email-based RBAC library for Adobe App Builder / Adobe Commerce apps. A function-based API for role resolution, access-record management, and fail-closed server-side role guards — usable in any project. Mirrors the shape of @adobe/aio-commerce-lib-config.","license":"Apache-2.0","author":{"name":"Adobe Inc."},"keywords":["adobe-io","aio","app-builder","commerce","adobe-commerce","rbac","access-control","ims","roles","authorization"],"type":"module","engines":{"node":">=18"},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.cts","bin":{"aio-commerce-lib-ims-access":"bin/cli.mjs"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./commands":{"import":{"types":"./dist/commands/index.d.ts","default":"./dist/commands/index.js"},"require":{"types":"./dist/commands/index.d.cts","default":"./dist/commands/index.cjs"}},"./package.json":"./package.json"},"sideEffects":false,"scripts":{"build":"tsdown","prepare":"npm run build","typecheck":"tsc --noEmit"},"dependencies":{"valibot":"^1.0.0"},"peerDependencies":{"@adobe/aio-lib-state":">=4"},"peerDependenciesMeta":{"@adobe/aio-lib-state":{"optional":true}},"devDependencies":{"@adobe/aio-lib-state":"^5.3.1","@types/node":"^20.0.0","tsdown":"^0.9.0","typescript":"^5.5.4"},"_id":"@adobedjangir/aio-commerce-lib-ims-access@1.0.0","_nodeVersion":"24.15.0","_npmVersion":"11.4.1","dist":{"integrity":"sha512-V72jO9bl8GB0Ydn6DOead5eo3Dou6cV5TQQpGYjpLkIX0rWTlqW4D+eSAYGpKdPcK1BubeaxvUwHHR0GDCAA2w==","shasum":"407de854362bfd594e636f2f7c2d85aaf6b3de6e","tarball":"https://registry.npmjs.org/@adobedjangir/aio-commerce-lib-ims-access/-/aio-commerce-lib-ims-access-1.0.0.tgz","fileCount":16,"unpackedSize":84357,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCs1Q7wxT6Q51cdNYATNVLrn1cQhxPqg0UBvtVYJW7ClwIgF7cWBHYwQF9IQs9bsvYS7KJBtaLJFiNFbl3e9VqabrI="}]},"_npmUser":{"name":"deepakjangid04","email":"djangir@adobe.com"},"directories":{},"maintainers":[{"name":"deepakjangid04","email":"djangir@adobe.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aio-commerce-lib-ims-access_1.0.0_1784655595149_0.8655538735859967"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-21T17:39:54.989Z","1.0.0":"2026-07-21T17:39:55.282Z","modified":"2026-07-21T17:39:55.564Z"},"maintainers":[{"name":"deepakjangid04","email":"djangir@adobe.com"}],"description":"Email-based RBAC library for Adobe App Builder / Adobe Commerce apps. A function-based API for role resolution, access-record management, and fail-closed server-side role guards — usable in any project. Mirrors the shape of @adobe/aio-commerce-lib-config.","keywords":["adobe-io","aio","app-builder","commerce","adobe-commerce","rbac","access-control","ims","roles","authorization"],"author":{"name":"Adobe Inc."},"license":"Apache-2.0","readme":"# `@adobedjangir/aio-commerce-lib-ims-access`\n\nEmail-based RBAC (role-based access control) library for Adobe App Builder / Adobe Commerce apps — usable in **any** project.\n\nThis library provides a small, function-based API for resolving a caller's identity from their IMS token, managing email→role assignments, and enforcing **fail-closed** server-side role guards inside your runtime actions. It has no UI and no host-app coupling: you own your actions and UI and call the library.\n\n## Features\n\n- **Identity resolution** — validate a forwarded IMS bearer token against IMS (not just trust a header) → email / profile, cached per warm container.\n- **Role model** — `admin` / `editor` / `viewer` by default, fully customizable and rank-ordered.\n- **Assignment management** — list / grant / revoke email→role assignments, persisted via `@adobe/aio-lib-state` (or your own adapter).\n- **Server-side guards** — `requireRole(params, minRole)` resolves the caller and enforces a minimum role, **failing closed** on any resolution error.\n- **Super-admins** — bootstrap emails that always hold the top role and can never be locked out via the store.\n- **Pluggable storage** — inject any `StorageAdapter`; the default uses `@adobe/aio-lib-state` (no DB provisioning).\n- Ships dual **CJS + ESM** with **TypeScript declarations**, tree-shakeable (`sideEffects: false`), plus a small CLI.\n\n## Installation\n\n```bash\nnpm install @adobedjangir/aio-commerce-lib-ims-access\n```\n\n`@adobe/aio-lib-state` is an optional peer — needed only for the default storage adapter (every App Builder project already has it via `@adobe/aio-sdk`). If you inject a custom `storage` adapter, you don't need it.\n\n## Quick start\n\n```typescript\nimport { initialize, requireRole, listAccess, setAccess } from '@adobedjangir/aio-commerce-lib-ims-access'\n\n// Once per action module load:\ninitialize({ superAdmins: process.env.SUPER_ADMIN_EMAILS })\n\n// Inside a write action — gate on 'admin' (throws AccessDeniedError otherwise):\nexport async function main (params) {\n  try {\n    const caller = await requireRole(params, 'admin')   // fail-closed\n    await setAccess('teammate@corp.com', 'editor')\n    return { statusCode: 200, body: { ok: true, caller: caller.email } }\n  } catch (e) {\n    if (e.statusCode === 403) return { statusCode: 403, body: { ok: false, error: e.message } }\n    throw e\n  }\n}\n```\n\nSee the [Usage Guide](./docs/usage.md) for the full API.\n\n## CLI\n\n```bash\nnpx aio-commerce-lib-ims-access roles          # print the role model\nnpx aio-commerce-lib-ims-access list           # list assignments (needs OW creds)\nnpx aio-commerce-lib-ims-access grant a@b.com editor\nnpx aio-commerce-lib-ims-access revoke a@b.com\n```\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md","_rev":"1-4ac2410f55db8c59619c98aacf5a4023"}