{"_id":"@aiquants/auth-directory-drizzle","_rev":"12-c41ffae7ce94127be693c880bd07b183","name":"@aiquants/auth-directory-drizzle","dist-tags":{"latest":"0.8.1"},"versions":{"0.2.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.2.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.2.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"331d85b9c8aa93c2bc158a0b5c70c7dd034c1702","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.2.0.tgz","fileCount":9,"integrity":"sha512-4/+N9FBan4wZ0m0WSKIKiKw0khNvWthDI6hwjyZtJCUD9CZw5/zcucWNtX7w2sWOCwxo9jcDeu68YSQKJDg1CQ==","signatures":[{"sig":"MEUCIF46ZZtnbqVHwXG3eEKI6/1ZNezCkZclzIjnlVMTBIAmAiEA1Y7cBdf2Eh8qzJ7gEvLaJcRXTJGPX/yKYBDevGovB9E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":607555},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.5.0","@aiquants/authz-drizzle":"1.1.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.5.0","@aiquants/authz-drizzle":"^1.1.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.2.0_1788961225877_0.798689839297178","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@aiquants/auth-directory-drizzle","version":"0.2.1","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.2.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"ae29239cf687d8700a2ff2bed8707e1b9ee2b598","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.2.1.tgz","fileCount":9,"integrity":"sha512-CTwFLNydA5UBcSQOKilKgdtHuIcjQdwhSWQ0If3HfwXa4yeHnjj8u8QgmXlD71hNtoLfP0lrI2YxkDZKulS7TA==","signatures":[{"sig":"MEUCIQDlfFk4mJLZTGp0A3xFfgWX9Dz26GkHTZDUJEyu7hSILgIgZqJjrftlC3tD0MgwpMHXOr5pupMQMH34RWh4NzZ5NRk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":610433},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.5.0","@aiquants/authz-drizzle":"1.1.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.5.0","@aiquants/authz-drizzle":"^1.1.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.2.1_1788965545882_0.20931142133252467","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.3.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.3.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"6f553a2580e7b61b25e3662e03a5f0f88b7752bb","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.3.0.tgz","fileCount":9,"integrity":"sha512-EgQDaz27KD8Aay++1hmxFvyQSPRp2oR8EQJmiFFqRJtpva7b/FFQoMhATZ2rEuLVmufaAU+V7GRpbqYZtIetLw==","signatures":[{"sig":"MEUCIQDpQaTdWJ00nmP7ezDvRmIXofHF2GTL/n+Hcg1aMP5XFgIgU8DHnhlk870+UV+Kihn8O7d/WKMRLcDRIhRUhdtRdec=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":620095},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.5.0","@aiquants/authz-drizzle":"1.1.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.5.0","@aiquants/authz-drizzle":"^1.1.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.3.0_1788966397898_0.22584035351958187","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.4.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.4.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"643ee274f37873d6b0f0acc8d94f5dd5c5282a73","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.4.0.tgz","fileCount":9,"integrity":"sha512-OrZHTQbROMnV3YUXMZdRsHSylxUOhSkhz+v7Qlodf37D13gn9LrpWHDGPTXGaLmcN7+2aEaJu8LqdY8V7zwEJg==","signatures":[{"sig":"MEUCIACHTB9YNr/EhZg+U8+eRNc8FU5Sr6bA8i8IX9IivLoYAiEA6+NygKczaNR9z85Eis/6gLkG0BJBO5UtgXa0xyNnL+Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":625325},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.4.0_1788968731647_0.33668172650805395","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@aiquants/auth-directory-drizzle","version":"0.4.1","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.4.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"cce806fd04429e7614908890d7e40dea1c61171b","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.4.1.tgz","fileCount":9,"integrity":"sha512-2Brhnx5ygAEM+0RJweiYTfLTJWWDEbKQugsIW43n7FIVjmor3ZjH3soxZovgV/u2ADlcQEBv213cIXuasT/MAg==","signatures":[{"sig":"MEQCIAmasNK+q9itbhqD/9lnVM7uam7bXDjiX9pGZ5nqqZh1AiAFG44HnRC7vlzEokv8OkGvZ55zQYQojKuXehyhpADUBA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":628707},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.4.1_1788969049241_0.005788774542252684","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.5.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.5.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"85653323b9a591de473d1802402e20bed3e1d3ea","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.5.0.tgz","fileCount":9,"integrity":"sha512-RHSFBTPZg4TH2OCQJqKNdk0dQZUKbMtd2CVCLMg+KwoquYu7nxumyvPyefXg/3V6gP2qq66cc8uiBdVLQ87PBg==","signatures":[{"sig":"MEQCIB/RE5ZIusnu1f0VndDvheaP1KXN00wZ912tDX9iNIngAiBrL4ebPzULG2o0OSbTyothMHZ9z+IaSXkYDIsumNfnTw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":634352},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.4.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.1","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.4.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.1","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.5.0_1788970411330_0.04445619201022066","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.6.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.6.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"6b0792cd69d40a1c539a4716bc38270d83fe506f","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.6.0.tgz","fileCount":9,"integrity":"sha512-FLLFmF7cc33Ryt3xdfuK/dhh27CkO5jN+vmcakuQFjtsSh2fcb39oWjlBqRqOSXnjeCWyfBACQarA4QatJawMQ==","signatures":[{"sig":"MEUCICte0kUJXvdc/wKVAhXRZdwkLpCthT/25nIro7LRCQCnAiEAoYpoPnl9+Z3Bj4OJygJESHENz0JcsnTHIsy0NoPIg2k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":636496},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.5.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.1","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.5.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.1","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.6.0_1788973203613_0.2539638459948055","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@aiquants/auth-directory-drizzle","version":"0.6.1","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.6.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"fb7b1f2485ddaf81d62542d07af1b9f69d8fa116","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.6.1.tgz","fileCount":9,"integrity":"sha512-LD6bt75DgU4mPc5NJSHhFK9qVNar2kO9nelCGPa/l7+4pWpWmWRsPk6h+SS+0HvI2Z0YW0XClZhENABmkXke5Q==","signatures":[{"sig":"MEQCICaEfTDMwYCEUAjiUXg8sVkBsphuXU/FZ7H/IHtOTzmhAiAZ9VxszlYb+f5EC9mpC4JH4TWpQ7+xjdt+NZnY3oB0YQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":644810},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.5.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.1","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.5.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.1","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.6.1_1789007013092_0.05080693882811427","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.7.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.7.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"3c38b28ebc8daea3fa450e695c6e31030ab6c513","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.7.0.tgz","fileCount":9,"integrity":"sha512-KJG3L/IJF5FJHc1ZYhDo+tm4wel0wIsOMTgw/lHJfcPBXslCjwPhNH7/UrOucri8c1s5FYx2iJbRdR42jJn95Q==","signatures":[{"sig":"MEUCIHUX5NfRNQ74w2XeHpgSdgcSzdYooKzyQsWj6moMq901AiEAyRkjgpWy52WemMM0Nq4vws2Bh8ADUQz4puh82qItcdA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":880379},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.6.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.1","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.6.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.1","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.7.0_1789030560698_0.4989798127407774","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@aiquants/auth-directory-drizzle","version":"0.7.1","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.7.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"5119857bba3f1c01b5cc3c315899e5cb35544808","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.7.1.tgz","fileCount":9,"integrity":"sha512-ClQXWsbTQPG03ovbTwXGIbRI/0RDdBY5k46V4EXHUO3fqOQR4a3Bu/nmGFv7mkVSk3fyJUuApHNjiyg77kXcew==","signatures":[{"sig":"MEUCIQCnqKRMxMhOH+dhlXwy/WPo14G2ejjKFuYIkF+LVaC7MAIgLQj/YCs2lW5kjgmqGfoIHiIkNFu0vWKwYV6CWYuxplk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDlJfy/DB4KuzVlaLfd3EJXLVUHFUds0tnmWtPZRgiZlAIhAIlI3GGoQc3uw8GWIV9anDPv6DJ56kSlnCDa+7CqfKGT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":883939},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.6.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.2.1","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.6.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.2.1","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.7.1_1789175173947_0.8301728233780081","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@aiquants/auth-directory-drizzle","version":"0.8.0","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/auth-directory-drizzle@0.8.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"26d758bff04d2a762cc6b43472d0cff110850755","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.8.0.tgz","fileCount":9,"integrity":"sha512-POLEuYJWt/sCyitGtc0J62K00O5+wsv+P87jS0IkhHSpbynoewGO0YJbOueZdZ2tLFeQi9XP8S8BbqCeXcnsnw==","signatures":[{"sig":"MEUCIEISQ/yR3VgeFEMd88B28D7l30MugpvmWwm9qKPqNt1HAiEA8XDP6CmaxIbzd4W6ZhiTblWJrn3JVYgqDQYz1Ve+F9U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIEe4xOTsKaglr+PUc7nLJOaraItI78aa0hnwHgXCWB0TAiEAv1zCldl7x2zeZs5cIfR+gFB5rSoWft4S99An/D/RxNo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":874606},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"sideEffects":false,"dependencies":{"@aiquants/mssql":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.6.0","@aiquants/authz-core":"0.6.0","@aiquants/authz-drizzle":"1.3.0","@aiquants/auth-directory-core":"0.2.0"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.6.0","@aiquants/authz-core":"^0.6.0","@aiquants/authz-drizzle":"^1.3.0","@aiquants/auth-directory-core":"^0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-directory-drizzle_0.8.0_1789649564289_0.5527622560492989","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"_id":"@aiquants/auth-directory-drizzle@0.8.1","dist":{"shasum":"7ab6f5f44cb0f2eb1c12864599a10f79fe5392b1","tarball":"https://registry.npmjs.org/@aiquants/auth-directory-drizzle/-/auth-directory-drizzle-0.8.1.tgz","fileCount":7,"integrity":"sha512-RjKMVWZglKj2Cyh7sL6oCFZmVpUt1NIUC91VBtXbqgY3nn3LPb2irnbGChnNeafTtKuzIJO/vterRiKraBdlsg==","signatures":[{"sig":"MEUCIGLg8+C4bfACWB21ztJllIkhbH51MVjh7BcqxQr1ZXV9AiEAjoTMCXv0VPBoLmFznmoHBRc0KJebxFUs1spH3fASIcs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDIJG++NfhAtjf6gRBv6HAtIqNuSt1vctfRjGYrflocKAIhAK6hymsT3JB6kjMdI6/37RAsb4lK5TuYVCyuh4gHbSwv"}],"unpackedSize":229237},"main":"dist/index.js","name":"@aiquants/auth-directory-drizzle","types":"dist/index.d.ts","author":{"url":"https://x.com/fehdek","name":"fehde-k"},"module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"license":"MIT","scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup && node ../../.config/scripts/strip-dts-comments.mjs dist","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"version":"0.8.1","_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","directories":{},"maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"sideEffects":false,"dependencies":{"@aiquants/mssql":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","drizzle-orm":"1.0.0-rc.4","@aiquants/auth-core":"0.6.1","@aiquants/authz-core":"0.6.1","@aiquants/authz-drizzle":"1.3.0","@aiquants/auth-directory-core":"0.2.1"},"peerDependencies":{"drizzle-orm":">=1.0.0-beta.4 <2.0.0","@aiquants/auth-core":"^0.6.1","@aiquants/authz-core":"^0.6.1","@aiquants/authz-drizzle":"^1.3.0","@aiquants/auth-directory-core":"^0.2.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-directory-drizzle_0.8.1_1789699411261_0.08000464894025194"}}},"time":{"created":"2026-09-09T13:40:25.705Z","modified":"2026-09-18T02:43:31.508Z","0.2.0":"2026-09-09T13:40:26.009Z","0.2.1":"2026-09-09T14:52:26.038Z","0.3.0":"2026-09-09T15:06:38.086Z","0.4.0":"2026-09-09T15:45:31.838Z","0.4.1":"2026-09-09T15:50:49.393Z","0.5.0":"2026-09-09T16:13:31.525Z","0.6.0":"2026-09-09T17:00:03.788Z","0.6.1":"2026-09-10T02:23:33.248Z","0.7.0":"2026-09-10T08:56:00.837Z","0.7.1":"2026-09-12T01:06:14.054Z","0.8.0":"2026-09-17T12:52:44.392Z","0.8.1":"2026-09-18T02:43:31.363Z"},"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","keywords":["auth","directory","drizzle","mssql","rbac","typescript"],"description":"Drizzle (mssql) adapter for @aiquants/auth-directory-core: the identity-side tables (external group links, upstream member ledger, tenant membership groups, login allowlist), the synchronization writer that runs inside the authz lockout guard, and an admi","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"readme":"# @aiquants/auth-directory-drizzle\n\nDrizzle (SQL Server) adapter for [`@aiquants/auth-directory-core`](../auth-directory-core). It owns\nthe **identity-side** tables and the four surfaces that operate on them.\n\n## Why these tables are not in `@aiquants/authz-drizzle`\n\nNothing in the authorization query path reads them — only authentication and user administration do.\nBeyond the separation of concerns there is a practical reason: `@aiquants/authz-drizzle` is a shared,\npublished package, and adding a column or a table to it **forces a DDL migration on every deployment\nthat uses it**. Drizzle puts every declared column in its `INSERT` column list, so a column the\nphysical table does not have fails with `Invalid column name` (SQL Server 207) on the very next\nwrite. Deployments that never touch an external directory should not be dragged into that migration.\n\n## Tables\n\n| Table | `tenant_id` | Notes |\n| --- | --- | --- |\n| `TDGroupExternalLink` | yes (denormalized) | One link per group. The column duplicates `TMGroup.tenant_id` so `UNIQUE (tenant_id, provider, external_id)` is expressible, and is also used as a predicate; writes must prove it matches the parent, and reads re-verify it against the parent |\n| `TDGroupMemberEmail` | no — inherited | Every member observed upstream, **including people with no local user row**. `resolved_user_id` is nullable and carries no foreign key: rows that cannot be resolved are the reason this table exists |\n| `TDTenantMembershipGroup` | yes (it is the key) | Groups a tenant accepts as proof of membership. At least one row must be `is_break_glass` and locally managed |\n| `TDAllowlistGroup` | yes (**owner**, not a filter) | Groups whose members may sign in |\n| `TDDirectorySyncRequest` | yes | The \"sync now\" queue. `group_id` is `NULL` for a whole-tenant run |\n| `TMAllowlist` | yes (**owner**, not a filter) | Moved here from `@aiquants/authz-drizzle`, now tenant-scoped |\n\nNo table declares a drizzle `.default()` on `tenant_id`, and the new tables carry no physical\n`DEFAULT` either. A default makes `tenantId` optional in the insert type, so a write that forgot the\ntenant type-checks and lands in whichever tenant the DBA happened to name.\n\n### \"Owner\" is not a filter\n\n`TMAllowlist.tenant_id` and `TDAllowlistGroup.tenant_id` answer *who may edit this row*, not *who may\nsign in*. Authentication happens before a tenant is resolved, so the login decision is the union over\nevery tenant this deployment serves. `isEmailAllowedByGroup` deliberately emits **no tenant\npredicate** — a regression test asserts its absence, because adding one silently breaks every first\nsign-in.\n\n## Surfaces\n\n| Export | Role |\n| --- | --- |\n| `defineAuthDirectorySchema` | Table factory (schema name and referenced tables injected) |\n| `createDirectoryLinkStore` | Links, tenant membership proof, group allowlist, sync queue, health |\n| `createDirectorySyncRepository` | Storage operations for one sync run; **removals go through the authz lockout guard** |\n| `assertMembershipMode` | The single reader of `membership_mode` — no reader may default it |\n| `promoteLedgerForUser` | First-sign-in promotion of ledger rows to real memberships |\n| `withExternalGroupGuards` / `assertGroupMayBeLinked` | Keep administrative roles off externally-sourced groups, in both directions |\n\n### Removals go through the lockout guard, and one refusal does not stop the group\n\nGroup membership reaches roles through `TDGroupRole`, so one upstream departure can take a tenant's\nlast administrator with it. Every projection removal is written inside\n`createAdminLockoutGuard(...).guardedWrite(...)` — the same serializable transaction the\nauthorization admin UI uses. Removals are issued one at a time because `AdminRemoval` takes a single\ndescriptor; adding a batch form to the authorization core would breach the package boundary, and the\ncount is already bounded by the reconciler's circuit breaker.\n\n**Every transaction goes through one seam.** All nine of them are opened by `transactionRunner` in\n`db.ts`, which runs the work again when — and only when — the server rolled it back\n(see [`@aiquants/mssql`](../mssql/README.md) — **only the deadlock victim `1205` is run again**, and the closure is wrapped in `capture` so the ORM cannot destroy that evidence). Calling `db.transaction` directly\nat each site means touching nine places to change the policy, and one of them eventually gets left\nbehind without saying so. Configure with `transactionRetry` on any factory's options; the closure\nmust keep its side effects inside the database, because a retry runs it from the start.\n\n**A refusal does not abort the run.** Stopping at the first refused removal leaves the additions\ncommitted, the earlier removals committed and the ledger untouched — and every later run recomputes\nthe same plan and dies at the same index, so one legitimately-guarded row blocks the whole group's\nconvergence forever. Refusals are collected into `ApplyReport.refusals`, the remaining removals\nproceed, and the caller records that the group has not converged. The refused person keeps both\ntheir membership **and** their ledger row: revoking sign-in while leaving the role would produce a\nstate that makes sense from neither side.\n\nLedger deletions are chunked. SQL Server binds one parameter per value in an `IN` list against a\n2,100-parameter statement limit; a group large enough to exceed it would fail with error 8003 after\nthe memberships were already removed, and every subsequent run would fail identically — the state\ndoes not self-heal.\n\n### Deactivation is not a one-way door\n\nA group missing upstream is deactivated only after `vanishedThreshold` **consecutive** absences, so a\npropagation window or a scope change does not disable a live group. Deactivated groups keep being\npolled, and a successful read reactivates them; `setGroupActive` gives an operator the same exit.\n\nDeactivation revokes: `is_active` is part of the login gate and of the tenant-membership evidence, not\nonly of the sync query. The reverse — enforced for syncing, ignored for access — leaves a frozen\nledger granting sign-in to departed members while the only process that could clean it is switched\noff.\n\n### Promotion never reaches the directory\n\n`promoteLedgerForUser` matches an identity against the ledger and inserts the missing membership\nrows. That is entirely local work, so the web tier can grant group permissions during a first sign-in\n**without holding the directory credential** — which stays with the sync job alone. Do not import a\n`DirectoryProvider` here; the placement is the point.\n\n## Testing the shape of the SQL\n\nThis adapter accepts drizzle through structural types, so `tsc` checks neither the order of the\nbuilder calls nor the presence of a tenant predicate: putting `.innerJoin()` before `.from()`,\ndropping `.output()`, or forgetting `WHERE tenant_id = ?` all type-check. `link-store.spec.ts` and\n`sync-repository.spec.ts` therefore record the actual call sequence against a fake builder and walk\neach condition for the columns it references.\n\n`sync-repository.ts` is the only module that deletes rows, so it is tested directly rather than\nthrough the orchestration's fake repository — an orchestration test proves nothing about whether the\nreal writer goes through the lockout guard. Fifteen mutations are each caught by at least one test,\nincluding: replacing `guardedWrite` with a bare `db.delete`, excluding deactivated groups from the\nsync query, pinning `membership_mode` to a constant, removing the `IN`-list chunking, dropping a\ntenant predicate, skipping reactivation, omitting the audit actor, opening the third escalation\ndirection, ignoring `appKey` when deciding what is administrative, dropping `is_active` from the\nlogin gate, collapsing the identity precedence back to an `OR`, treating a removal-only run as\n\"unchanged\", and skipping the resolver completeness check.\n\n## Install\n\n```bash\npnpm add @aiquants/auth-directory-drizzle @aiquants/auth-directory-core @aiquants/auth-core @aiquants/authz-core @aiquants/authz-drizzle drizzle-orm zod\n```\n\nAll five `@aiquants/*` peers are **value** imports and every one is listed in this package's tsup\n`external`, so omitting any of them yields `ERR_MODULE_NOT_FOUND` at runtime rather than a type\nerror. `zod` is required transitively by `@aiquants/authz-core`.\n","readmeFilename":""}