{"_id":"@aiquants/authz-core","_rev":"12-3a9635913b9cc845d5aa1e51ca8f9ac8","name":"@aiquants/authz-core","dist-tags":{"latest":"0.6.1"},"versions":{"0.1.0":{"name":"@aiquants/authz-core","version":"0.1.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.1.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"22739874071189a4a7055d2c581c479cb01f2797","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.1.0.tgz","fileCount":17,"integrity":"sha512-LM+8pgdkW9tqERlK+8vC47DsFw8xA6u/02EPRm1E78sF6CxfRVLvGNJl9qiOTmdV4ELOqbyEbi2vLdLsM4XwvA==","signatures":[{"sig":"MEUCIBjWUmYuUwSDJM5aTBYzQ0CgUmzz20THpdRj5zKidIApAiEA4XEmEQs6pBQncOkoE5IklgBzTcsl3+cWKXlKGqDVfIQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":134394},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"npm version major && pnpm publish --no-git-checks","publish:minor":"npm version minor && pnpm publish --no-git-checks","publish:patch":"npm version patch && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.1.0_1782370718244_0.4166241780867721","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aiquants/authz-core","version":"0.2.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"35e5965c6d615ea3ddfc5207b6513705c3b9f2d8","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.0.tgz","fileCount":17,"integrity":"sha512-vIOr1ygW1XEQmGjImRV3/AItib/rHEqHB68kafOrv61+7//6kOyCw+QwFCG28j6gkwHOxWFVusC6A95GLByNYw==","signatures":[{"sig":"MEYCIQDv49jwuNEP9hw0IC0wLr9dvT/lqfm03GFRT8sccQFGKAIhALdPfer8Kby1rS9mrevDoe5IDP8curRsRlzHszjjQEIa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":140385},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"npm version major && pnpm publish --no-git-checks","publish:minor":"npm version minor && pnpm publish --no-git-checks","publish:patch":"npm version patch && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.0_1782876672776_0.6881886352511399","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@aiquants/authz-core","version":"0.2.1","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.1","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"8d74ce07c1de0f26cf71c5623d074678416a0b9a","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.1.tgz","fileCount":17,"integrity":"sha512-w7wSiRg5U2RJEMht8J/sX94PB/tvHJ6zHnlVdYFCrjPwO5XVlrUiKr1AqH+braS98DkIhSzfWK4J4nvc8o8Leg==","signatures":[{"sig":"MEUCIAIomK+wA86t2FrW8IzzjxBrQw/6gtLLpoKGfNcdMI4PAiEAoor6A5+lnr7u02Nm05TfCHY23NGDRQLJaNkUf7rXi/A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146580},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm version major --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm version minor --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm version patch --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.1_1784161542333_0.6946766399928295","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@aiquants/authz-core","version":"0.2.2","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.2","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"be3fb896591c1aa6b8869456d4f5f9872ae2ad12","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.2.tgz","fileCount":17,"integrity":"sha512-y0B/ZAlLM7pU4vCKCCsqnshXoA5t5b9i8SC4aZiBLjHOzmwIG75uUfNOzDuR5gOosRWtSJC+X5debMlXJto0yQ==","signatures":[{"sig":"MEUCIQDi+i37FpQXrdGAvPQ300eyQQ03nYT7cOVXM4c1VCPNgAIgFa3ulYcewvrPg5NGHKDAmS9DYuJwsnUByqy1zxLZ78k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147508},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm version major --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm version minor --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm version patch --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.2_1784166525024_0.09746145284450236","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@aiquants/authz-core","version":"0.2.3","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.3","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"63650510dfa3771fd5ff34e4432c879d28061495","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.3.tgz","fileCount":17,"integrity":"sha512-oof2O/6INbett9o6OcjyoPQQp5oXC5g54Mut3kaJbB85IproOK18w0cyH3TuZ/ncNBHYhzLzGZs3DBz/mUk5Ag==","signatures":[{"sig":"MEQCIGFnt/AR0gUGouxr3nN/dEfCvRDRkk7R6667wNY0fJQoAiA2R0jNkwiTBivAWrM2ywotXIe7xI6tK+Pyyr/6yscY7g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147483},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.3_1784769447636_0.06973702815467808","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@aiquants/authz-core","version":"0.2.4","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.4","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"cef2ecb601cd504072438a38096097fecf67cdd8","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.4.tgz","fileCount":17,"integrity":"sha512-s4tAUJBC+Gg4HjT7i1EAeANiWpgNVgslHdS05Npa40mWVRtjTSLW1r1Ps8S13ZlqChgBrh+I4bF9ukb4rAPD8g==","signatures":[{"sig":"MEQCIF/vXZ1+Lh8s8fULa4JBZ9Bhks1+aoQPM9/TghSXnPYEAiAo9L5eU2gBqI1EHJmmYywn1Xh2XU28qD/cRvf5ixTVDA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147639},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.4_1784772268904_0.7157317596782999","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@aiquants/authz-core","version":"0.2.5","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.2.5","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"9e5b7962a2189123fe571293d1c6cc6469858f5d","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.2.5.tgz","fileCount":17,"integrity":"sha512-IhOVCH7BnKZ6j35rW9I9lMbDpeLpGxH8L5vnoQagpBfwfYiI7gNyMocxMKeNxMhu3Q52RGuNLmv9O7bDP4R4Ug==","signatures":[{"sig":"MEQCIFrEOLF3iEUwDWkfvubj1Vm/LNH6hsQkbup5Xkf7uVeVAiAxsnz221CBmOs8Wy4ppgJcRzPLrAZG/17fSnSq2nCRow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147639},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.2.5_1784772516400_0.7512964929166632","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aiquants/authz-core","version":"0.3.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.3.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"431f8e2ee44c0caaee7178f1235787d34a3ad9e7","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.3.0.tgz","fileCount":17,"integrity":"sha512-exDqVoXmQoHwjTsrOTbhUTXLUm75eej4YEmGLBbQR5uJsUCMO6R/CqkHSLkDQqwVxhON4UVOFUohMKIyzxcTtg==","signatures":[{"sig":"MEUCIGZwb5cYvXjrgKekElgFcUVKMlCCJqKO1U6eTB8FQ+MWAiEAxSZr0HdpAMx5LpBvDdH3g3LHQy8gfpxu0gpRZY0gt6c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":159205},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.3.0_1785927781945_0.9760437142830876","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@aiquants/authz-core","version":"0.4.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.4.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"072f44ac0a719eb5adbc629051d879c509e186cb","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.4.0.tgz","fileCount":17,"integrity":"sha512-GQ7KZ+geGdJ7yKO07maK0/n1rJ45G3os0GJNw4YuQnUJyZ7N051OxTep89HCAAsa/FiSYvK4lyLFuZFprqIeVA==","signatures":[{"sig":"MEYCIQDLvgrgnTU2UMIOLqTBE8sLS6kNvKLiTQ8CHrfQJ9wjPAIhALhnxD2//1tblY8e9Im9ZWxu70H3+QI71iBh8Oj0CyOM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165044},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.4.0_1786372556881_0.7127930417641368","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aiquants/authz-core","version":"0.5.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.5.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"fd90e664f2d2ab0e7d245039f5ed04ce4e24cb5a","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.5.0.tgz","fileCount":17,"integrity":"sha512-IK+HEtwFUD+6twueTNuexD0WZPVwr5x35T5q/1x/JbEvytE/9ROVopqQnxU1UBMeu2NkdI6fiqmu9VbLs5Zemg==","signatures":[{"sig":"MEUCIGC45ic6oUwIlIAN3zKmi30UwHlc2YvnCL7Gqc+AFhIaAiEA7UY8IDu+lqi9pTlorhpKnyO8agEyQwKk3KgSOp3GwhE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":397544},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.5.0_1788170273299_0.23993766250501425","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@aiquants/authz-core","version":"0.6.0","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","_id":"@aiquants/authz-core@0.6.0","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"dist":{"shasum":"73cdc24d30b83707ef217a5b622303328dee1f85","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.6.0.tgz","fileCount":17,"integrity":"sha512-uhWuo4+wZJeKOOhoyjlReknPnFKfEt/VsliekzTzaTMRZP1z9nttGwOsrU4YBHsGxXG9AVKYEeGgILYIgwTxpw==","signatures":[{"sig":"MEYCIQC06BKFMTrgFML48K5VyO9EEQBAWJsrMESQwLPeeVmLYAIhAOrHTtYLgA0h79qEgbu4/x2jgR3ze7YsVIuwDSkwtCpJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":402012},"main":"dist/index.js","types":"dist/index.d.ts","module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"tmp":"tmp/authz-core_0.6.0_1788967884952_0.6500855473822991","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"_id":"@aiquants/authz-core@0.6.1","dist":{"shasum":"0d4d29d4dc15d478a04f56d5ce73bca8a0b1a086","tarball":"https://registry.npmjs.org/@aiquants/authz-core/-/authz-core-0.6.1.tgz","fileCount":13,"integrity":"sha512-6PtNWZdMyCDskzFJmrCvoQaai0mEqmPn0J6r+JqDZHec1loSOyWluuuObJCyP0hhE8ax0nh0ULZGraOd/pLZdA==","signatures":[{"sig":"MEUCIG9BI9Arm8Dtu6uIVTHNB7k5ObUxTWZZtv5FFtPQjHH/AiEAq9Dz2LkNVGWqqVpNe+wsi/RpbHbQt2DoOsHD//7BYSM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCQN/YMtGE88B9IR5Q3wbp6vFWFEnnje+jb2Ue0ZqouRgIgDte2TwWwMMBdQyowl+Kw3d4ttcCsvqUjxH2Iz/TZd2Y="}],"unpackedSize":66382},"main":"dist/index.js","name":"@aiquants/authz-core","types":"dist/index.d.ts","author":{"url":"https://x.com/fehdek","name":"fehde-k"},"module":"dist/index.mjs","engines":{"node":">=18.0.0","pnpm":">=8.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.mjs","require":"./dist/testing.js"}},"license":"MIT","scripts":{"dev":"tsup --watch","lint":"biome lint src/","test":"vitest run","build":"tsup && node ../../.config/scripts/strip-dts-comments.mjs dist","check":"biome check src/","clean":"rimraf dist","check:fix":"biome check --write src/","typecheck":"tsc --noEmit","build:watch":"tsup --watch","license-check":"pnpm dlx license-checker --production --onlyAllow \"MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;Unlicense\"","publish:major":"pnpm run typecheck && pnpm run --if-present test && pnpm version major --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:minor":"pnpm run typecheck && pnpm run --if-present test && pnpm version minor --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","publish:patch":"pnpm run typecheck && pnpm run --if-present test && pnpm version patch --no-git-tag-version --no-git-checks && pnpm publish --no-git-checks","test:coverage":"vitest run --coverage"},"version":"0.6.1","_npmUser":{"name":"fehde","email":"genbu0498@gmail.com"},"keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","directories":{},"maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"sideEffects":false,"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.76","tsup":"^8.5.1","rimraf":"^6.1.2","vitest":"^4.1.8","typescript":"^5.9.3","@vitest/coverage-v8":"^4.1.8"},"peerDependencies":{"zod":"^3.25.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/authz-core_0.6.1_1789684177683_0.3451533246235796"}}},"time":{"created":"2026-06-25T06:58:38.074Z","modified":"2026-09-17T22:29:38.011Z","0.1.0":"2026-06-25T06:58:38.401Z","0.2.0":"2026-07-01T03:31:12.927Z","0.2.1":"2026-07-16T00:25:42.529Z","0.2.2":"2026-07-16T01:48:45.157Z","0.2.3":"2026-07-23T01:17:27.777Z","0.2.4":"2026-07-23T02:04:29.070Z","0.2.5":"2026-07-23T02:08:36.557Z","0.3.0":"2026-08-05T11:03:02.112Z","0.4.0":"2026-08-10T14:35:57.020Z","0.5.0":"2026-08-31T09:57:53.444Z","0.6.0":"2026-09-09T15:31:25.113Z","0.6.1":"2026-09-17T22:29:37.765Z"},"author":{"url":"https://x.com/fehdek","name":"fehde-k"},"license":"MIT","keywords":["rbac","authorization","authz","access-control","row-level-security","column-level-security","zod","typescript"],"description":"Transport- and DB-agnostic RBAC authorization core: action/scope types (zod), scope merge/eval, and a DI guard factory.","maintainers":[{"name":"fehde-k","email":"owner@aiquants.co.jp"},{"name":"fehde","email":"genbu0498@gmail.com"}],"readme":"# @aiquants/authz-core\n\nTransport- and DB-agnostic **RBAC** authorization core: action/scope types (zod), scope **merge/eval**, and a DI **guard factory**. No DB or framework dependency — pair it with a DB adapter and a framework adapter.\n\n`(user → role) × (resource × action) × (row / column scope)` — answer \"can this user do this action on this resource, and over which rows/columns?\". This package owns the **rules** (the §-contract below); adapters translate the result into SQL and HTTP.\n\n## Ecosystem\n\nThis is the contract layer. To build a working authorization setup you also need a **DB adapter** (resolves a user's grants from your database and applies scope to queries) and a **framework adapter** (guards your endpoints).\n\n| Layer | TypeScript | Python | Go |\n| :--- | :--- | :--- | :--- |\n| Contract (this) | `@aiquants/authz-core` | `aiquants-authz-core` | `github.com/aiquants/authz` |\n| DB adapter (mssql) | `@aiquants/authz-drizzle` | `aiquants-authz-sqlalchemy` | `…/authz/authzsql` |\n| Framework adapter | `@aiquants/authz-react-router` | `aiquants-authz-fastapi` | `…/authz/authzhttp` |\n\nAll three languages implement the **identical row / column scope contract** (same boundary tests). The required **database schema (DDL)** and a copy-paste **bootstrap (seed)** ship in the DB-adapter README (`@aiquants/authz-drizzle`). A full **zero → guarded endpoint** walkthrough ships in the framework-adapter README (`@aiquants/authz-react-router`).\n\nFor details on system-reserved roles (`@authenticated` and `@anonymous`), validation constraints, and database seeding, refer to the [Reserved Roles User Guide](docs/reserved-roles-user-guide.md).\n\n## Install\n\nInside this monorepo it is already wired as a pnpm workspace package — depend on it with the `workspace:*` protocol:\n\n```jsonc\n// consumer package.json\n\"dependencies\": { \"@aiquants/authz-core\": \"workspace:*\" }\n```\n\nExternal projects:\n\n```bash\npnpm add @aiquants/authz-core zod   # peer: zod ^3.25\n```\n\n`zod` is a **peer dependency** (provide it in the host app). Build / test from the package dir:\n\n```bash\npnpm run build   # tsup → dist (ESM + CJS + d.ts)\npnpm run test    # vitest\n```\n\nPublishing is gated by `prepublishOnly` (clean → typecheck → test → build); cut a release with `pnpm run publish:patch|minor|major` (npm, `--access public`).\n\n## Quick start (just the core)\n\nThe core has no DB — you supply four functions: how to resolve the tenant and the user id from your request context, how to prove the caller may act **as** that tenant, and how to load that user's grants. The DB adapter normally provides the last one; here it is inlined to show the shape.\n\n```ts\nimport { buildEffectivePermission, createRequirePermission } from \"@aiquants/authz-core\"\n\ntype Ctx = { tenantId: string; userId: number | null }\n\nconst requirePermission = createRequirePermission<Ctx, number>({\n  resolveTenantId: async (ctx) => ctx.tenantId,              // blank → AuthzTenantError (never \"all tenants\")\n  resolveUserId: async (ctx) => ctx.userId ?? null,          // null → anonymous, then denied (unresolved-user)\n  // may this caller act AS that tenant? REQUIRED, and never `() => true`: resolving a tenant only\n  // says WHICH tenant was named, and that name comes from a channel the client can influence.\n  assertTenantMembership: async ({ userId, tenantId }) => isMemberOf(userId, tenantId),\n  getEffectivePermissions: async ({ userId, tenantId }) =>\n    // normally: getEffectivePermissions(db, tables, {...})  (DB adapter)\n    buildEffectivePermission(userId, [\n      // tenantId is the grant row's OWN tenant, projected from the DB — not an echo of the argument\n      { tenantId, action: \"read\", rowScope: '{\"filters\":[{\"field\":\"dept\",\"op\":\"in\",\"values\":[\"A\"]}]}', columnScope: null },\n    ], tenantId),\n})\n\n// in a handler (ctx is your transport context — here `{ tenantId, userId }`):\nconst { userId, tenantId, scope, effectivePermission } = await requirePermission(ctx, { appKey: \"myapp\", resourceKey: \"report\", action: \"read\" })\n// allowed → apply scope.rowScope as a WHERE and scope.columnScope as a column mask (DB adapter),\n//           always together with the tenant predicate for the same tenantId.\n//           `effectivePermission` is the permission the decision was made from — describe it to a UI\n//           instead of loading it again, so the guard and what you show can never disagree.\n// denied  → AuthzDeniedError (map to HTTP 403).\n//           reason: \"unresolved-user\" | \"no-permission\" | \"tenant-mismatch\" | \"not-a-tenant-member\".\n```\n\n## Tenant contract\n\n`tenantId` is a **required, non-empty string** on every tenant-scoped surface — parameters, DTOs and\n`EffectivePermission` alike. There is no optional marker and no default:\n\n- A missing / blank tenant is an error (`AuthzTenantError`, `kind: \"invalid-tenant\"`), **never** \"no filter\"\n  or \"every tenant\". That inversion is what turns a scoping bug into a cross-tenant leak.\n- Comparison is exact — no trimming, no case folding. `Tenant-A` and `tenant-a` are different tenants.\n- `buildEffectivePermission` proves every grant row belongs to the requested tenant and throws\n  `AuthzTenantError` (`kind: \"tenant-mismatch\"`) otherwise, so a foreign row can never widen a result.\n- The guard verifies the permission it received was issued for the requested tenant and **denies**\n  (`reason: \"tenant-mismatch\"`) when it was not; it never stamps the requested tenant onto a foreign permission.\n- Helpers: `isTenantId`, `assertTenantId`, `isSameTenant`, `assertTenantMatch`, `AuthzTenantError`.\n\n## Model\n\n`(user → role) × (resource × action) × (row / column scope)`\n\n- **action** ∈ `read | create | update | delete` (`write` = create ∪ update, derived, never stored).\n- **row_scope** / **column_scope**: `NULL` = all rows / all columns; non-NULL = partial.\n- **fail-close**: unparseable / unresolved / unknown ⇒ deny (least privilege).\n\n## Scope contract (canonical)\n\n```jsonc\n// row_scope (NULL = all rows). filters are AND'd within one role.\n{ \"filters\": [ { \"field\": \"dept\", \"op\": \"in\", \"values\": [\"A\",\"B\"] } ] }\n// column_scope (NULL = all columns)\n{ \"mode\": \"allow\", \"columns\": [\"amount\",\"unit_price\"] }\n```\n\n`op` ∈ `in | notIn | eq | ne`. A `null` in `values` maps to `IS NULL` / `IS NOT NULL` on the SQL side.\n\n### Merge (multiple roles = UNION = wider)\n\n- **row** → disjunction (DNF) `{ anyOf: RowScope[] }`. Three canonical values (⚠️ fail-close):\n  - `null` = all rows · `{anyOf:[...]}` = OR of groups · **`{anyOf:[]}` = NO rows** (SQL `WHERE 1=0`).\n  - `null` and `{anyOf:[]}` are **opposites** — never conflate them.\n  - ⚠️ **Prohibition of Nullish Coalescing (`??`) fallbacks**: Never use `scope?.rowScope ?? { anyOf: [] }` or similar coalescing. Because `null` (all rows) is a valid truthy value representing unrestricted access, `??` will incorrectly override it to `{ anyOf: [] }` (deny all), turning full access into zero access. Instead, check the existence of the `scope` object itself using ternary or explicit checks: `scope ? scope.rowScope : { anyOf: [] }`.\n- **column** → normalized to **deny form** (no column universe needed):\n  - `allow A ∪ allow B = allow(A∪B)` · `NULL ∪ x = NULL` · `deny D1 ∪ deny D2 = deny(D1∩D2)` · `allow A ∪ deny D = deny(D∖A)`.\n\n## API\n\n- `parseRowScope`, `parseColumnScope`, `parseActionScope`\n- `mergeRowScopes`, `mergeColumnScopes`, `mergeScopes`, `buildEffectivePermission(userId, grants, tenantId)`\n- `isColumnAllowed`, `can`, `canWrite`\n- `isTenantId`, `assertTenantId`, `isSameTenant`, `assertTenantMatch`, `AuthzTenantError` — the tenant contract.\n- `createRequirePermission({ resolveTenantId, resolveUserId, assertTenantMembership, getEffectivePermissions, onDeny })` → `requirePermission(ctx, { appKey, resourceKey, action })` returns `{ userId, tenantId, scope, effectivePermission }` on allow (so callers can apply row WHERE / column mask **and** render the same decision without a second lookup); default `onDeny` throws `AuthzDeniedError` (403). `assertTenantMembership` is **required** (a missing port throws `TypeError` at factory time) and runs **before** the permission is loaded — `false` denies with `not-a-tenant-member`.\n- `wouldRemoveLastAdmin(rows, removal, tenantId)` / `tenantsLosingLastAdmin(rows, removal)` / `applyRemoval` / `fullAdmins` — the lockout guard's pure logic (see below).\n- `@aiquants/authz-core/testing`: `makeEffectivePermission`, `makeMergedScope` fixtures.\n\n## Lockout guard (last administrator)\n\nAn administrator is a user holding **all four** actions on the admin resource. `wouldRemoveLastAdmin(rows, removal, tenantId)` decides whether a destructive change would leave that **tenant** with zero administrators (it returns `false` when the tenant already has none, so recovery is never blocked).\n\n`tenantsLosingLastAdmin(rows, removal)` answers the same question for **every** tenant present in `rows` and returns the offending ids. Use it for a removal that is not tenant-scoped by construction — above all `deactivateUserId`, since the host's user table carries no tenant and deactivating a user removes that user's admin paths in every tenant at once. Asking only about the acting tenant passes while another tenant is silently left with none. A tenant-scoped removal is unaffected: role / grant / group ids are globally unique, so its rows can only match inside their own tenant.\n\nThe evaluation is always tenant-scoped: the third argument is required, and every `AdminGrantRow` must carry its own real `tenantId` — a tenant-less row raises instead of quietly dropping out of the scoped set (which used to read as \"no administrators here\" and let the last one be deleted).\n\nPermissions can be held through two paths, and `AdminGrantRow.groupId` records which: `null` = granted directly to the user, a number = granted via that group. The same (user, role) reached through both paths is passed as **two rows** — collapsing them would make one-sided removals undecidable.\n\n`AdminRemoval` describes exactly one destructive change, and each variant strips only its own path:\n\n| Variant | Removes |\n| --- | --- |\n| `removeRoleId` | every row for that role (either path) |\n| `removeAssignment: {userId, roleId}` | the **direct** rows only |\n| `removeGroupAssignment: {groupId, roleId}` | that group's rows, for all its members |\n| `removeGroupMembership: {groupId, userId}` | that user's rows from that group |\n| `removeGroupId` | every row from that group |\n| `deactivateUserId` | every row for that user (both paths) |\n\n`removeAssignment` deliberately spares group-derived rows: revoking a direct grant from someone who also holds the role through a group is safe, and treating it as unsafe would block a legitimate change.\n\n## Group support in the admin store port\n\n`AuthzAdminStore` adds `listGroups` / `listGroupRoles` / `assignGroupRole` / `removeGroupRole`. The port knows only a `groupId` plus display-only `groupKey` / `groupName` / `tenantId` — group **membership** is an identity concern and lives outside this package.\n\nEvery port method — reads, writes and the destructive `guardedWrite(tenantId, removal, op, write)` — takes `tenantId` as its **first argument**. Payloads that carry a tenant-unique key or a cross-row reference (`RoleInput`, `RoleUpdate`, `ResourceInput`, `GrantInput`) also name the tenant they target; an implementation must verify that claim against the operation's `tenantId` with `assertTenantMatch` and reject a mismatch instead of preferring either side.\n\n## Next steps\n\n1. Create the database tables — see **DDL** in `@aiquants/authz-drizzle` (or `aiquants-authz-sqlalchemy`).\n2. Wire `getEffectivePermissions` + scope application — see the DB adapter README.\n3. Guard your endpoints + bootstrap an initial admin — see the **full walkthrough** in `@aiquants/authz-react-router` (TS) / `aiquants-authz-fastapi` (Python) / `…/authz/authzhttp` (Go).\n\nMIT\n","readmeFilename":""}