{"_id":"@alfiz-auth/core","_rev":"9-aea9e35ad1ff1c5e84dafd1e1ca2820e","name":"@alfiz-auth/core","dist-tags":{"latest":"0.5.1"},"versions":{"0.1.0":{"name":"@alfiz-auth/core","version":"0.1.0","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.1.0","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"f17a53dc9ee5899819b155a071bf04a06f396f09","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.1.0.tgz","fileCount":2,"integrity":"sha512-K65EA2kAwSfoP+GHqQIOjZ30SP7D6dx1Xy+rCsP+AfryjxI95koKM1JORnvW0Y6z11loXgOoyr7NmaOJEcWjKQ==","signatures":[{"sig":"MEUCIQC602MBo8iulMfGTqzyc1GlSwQXkIhEOssQjk/8FM7p3AIgFJ1CT6irjoONu2IuDW8WP0T5d2u1NBdvdpSgwUZqKVA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2817},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"5020a367209d4e0a13d315f1587ec1b8d700d30e","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.1.0_1785033120224_0.014718661979597591","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.1.1":{"name":"@alfiz-auth/core","version":"0.1.1","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.1.1","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"8c40a7bac07fe82f0d4e5478b505d84c9d85fa5f","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.1.1.tgz","fileCount":54,"integrity":"sha512-h2MqFM9gOGYs3J+1sT0/zwubG8DCVRq98IESBlTTzJcDVazItHzbGwzMAVQGMvc/BKvpTkhd/NHapL+aEcJ4bA==","signatures":[{"sig":"MEUCIQC8S0tojiySc2okWDCGQwoav2yEpTHPT4R3pNgN6HqmQwIgTZS8Ck75Mjm8xyGektNu1Z1uvPgye7hUWOgbfdzfV1Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257096},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"5020a367209d4e0a13d315f1587ec1b8d700d30e","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.1.1_1785039529575_0.5935634775271736","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.1.2":{"name":"@alfiz-auth/core","version":"0.1.2","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.1.2","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"5cec3fbf1726df45b39994eafa42d41a2d9a3030","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.1.2.tgz","fileCount":54,"integrity":"sha512-kgbjM5DRLFivxup8WumPaR8swvgjpgsgzbMwg7O/2uIGvQojEiKan567jfFHwonYZ6IlYpKteGzHAzUtWeGEKw==","signatures":[{"sig":"MEUCIQDZew5XyOBnNmzL0T99ilC6F7aFa/wAjwL81ZByuVKpXwIgQF+fclRdiMSz4l3ZDPxRFH5Gbh/4upULIgyXtH2FJVE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257126},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"5f97f0320caeceb705842d72ac46f7556d39cfbe","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.1.2_1785040038018_0.9456247125138715","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.0":{"name":"@alfiz-auth/core","version":"0.2.0","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.2.0","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"33ac2c3995a492d6361ee2f761d1824629a9e21f","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.2.0.tgz","fileCount":58,"integrity":"sha512-2hoU4Pz7c6Y4vUMfDQea/bgtW8+MCJ6PuUkPjLO9whG6S1YqFsCBKP405zoJflpij14M1phmtVPn4mwzmOvf0Q==","signatures":[{"sig":"MEUCIQCYPK+t2p/94Vq1vzCJTKq0LBkb4BMHVoDA71nyC0fc/QIgQzijzVOQdRLyIXchm7e3KyV6qOJx7crooZybmVJ3Iy0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":298638},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"6437d4ecb86a21b56c2cd8e5301438fadc3b9a3a","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.2.0_1785046183148_0.8329844141240734","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.1":{"name":"@alfiz-auth/core","version":"0.2.1","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.2.1","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"3ea221f447a8807d2bd74259cbff2b23f1fef49b","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.2.1.tgz","fileCount":58,"integrity":"sha512-84ptFln6joW4ISo8img2IYxudXodWR0zCs+z+KkprzjpWySpK34DbPhsb6Ont+7KVwA0gRJpytOqX/IwyOsmqQ==","signatures":[{"sig":"MEYCIQC3vFwG0mx/NuBNWa7mJY6f7qeVaKrMOiQnwSpGRpxKKgIhAKDTrdUFFvaK9RUeiWtbu+HD1+EZNUiUv6dMwVKeKg3i","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":325145},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"85b7974de29ef201e91a072955e048f79f927a50","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.2.1_1785080707177_0.1858455579303353","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.2":{"name":"@alfiz-auth/core","version":"0.2.2","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.2.2","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"c176f227341875c18a116bff88fd8212b5b3aebd","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.2.2.tgz","fileCount":62,"integrity":"sha512-cwWeNJZFxU6+Anl+gYp77KqHYD7WBEEC+6Cs70upcXQghcynlmMeRsM99cP8qBn8ZlT0WmSzBy5cGOUQSFep+A==","signatures":[{"sig":"MEUCIAOF8An1nYIwHEBuFy40MaCJxkGPwxyIRCqghzJFOkUiAiEAr0QLUlz06b6BLDZ6Coff340rpHMzm74/OG3JnJYJWH4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":399868},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"0de2743b5dc7d475ae59125a4bd5f31e6bf23dbb","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.2.2_1785137728576_0.10869907674782064","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.5.0":{"name":"@alfiz-auth/core","version":"0.5.0","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.5.0","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"8d9333db081c792f9367f14b47d266dd81560b31","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.5.0.tgz","fileCount":70,"integrity":"sha512-4p85HKJMIfWWmnnd6SKhWAhhmIhLzm00uLJDW8VzZqlQtHvGK9HCwLN4JUGu7/RfGAuJNkaT3LY3gx+Rsp7s1g==","signatures":[{"sig":"MEUCIQCM1+ikGLqiW7S2v82TxfoN/7PCzVJIJLYmPdZv6A9KOgIgexSVDF1PhZfJZHKBWRG0cYLR1Lz3RK71RNgC93OhMio=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":525234},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"f0f9e3bd99ab6e014867f6cf2dcb81de12fa4238","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.5.0_1785207105151_0.42386191199297274","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.5.1":{"name":"@alfiz-auth/core","version":"0.5.1","keywords":["authorization","permissions","rbac","access-control"],"license":"UNLICENSED","_id":"@alfiz-auth/core@0.5.1","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"dist":{"shasum":"9dee8c2a77d0e5fa60bbc822cc15e99c5a5b7f38","tarball":"https://registry.npmjs.org/@alfiz-auth/core/-/core-0.5.1.tgz","fileCount":70,"integrity":"sha512-gu3S4uT8nUnBD7U/VUCbgC2MNoy4mqHdY26YlbIqMNihLveMWYAqRlRgzXampLmp9qxGgc5XRIY4D+l2zy8cfw==","signatures":[{"sig":"MEUCIEZcC/ksom7cJEt59eqdaAuP5uqmoZi2f9/N4U5RgmReAiEAr1OOcJ96ySCYZisC+MTLVR3yK2sWJJyxw68w7DrOlOc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":526100},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"bf0422412d9bdeaa8754abd6425c00f0c140fa45","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"bytestorm","email":"kamil.m.arif@gmail.com"},"_npmVersion":"11.11.0","description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/core_0.5.1_1785211738524_0.9059964760512316","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2026-07-26T02:32:00.071Z","modified":"2026-07-28T05:54:22.239Z","0.1.0":"2026-07-26T02:32:00.374Z","0.1.1":"2026-07-26T04:18:49.723Z","0.1.2":"2026-07-26T04:27:18.155Z","0.2.0":"2026-07-26T06:09:43.304Z","0.2.1":"2026-07-26T15:45:07.329Z","0.2.2":"2026-07-27T07:35:28.739Z","0.5.0":"2026-07-28T02:51:45.310Z","0.5.1":"2026-07-28T04:08:58.664Z"},"license":"UNLICENSED","keywords":["authorization","permissions","rbac","access-control"],"description":"The Alfiz Client: permission grammar, catalog, closure evaluation, check shapes, caching, and the provider contract. Pure functions over provider-supplied data — no storage, no I/O.","maintainers":[{"name":"bytestorm","email":"kamil.m.arif@gmail.com"}],"readme":"# @alfiz-auth/core\r\n\r\nThe Alfiz **Client**: the evaluator. Everything here is a pure function over\r\ndata a provider supplies — no storage, no I/O.\r\n\r\n- **Grammar** (`grammar.ts`) — key/pattern validation, forward-inclusive\r\n  subtree wildcard matching, pattern intersection.\r\n- **Catalog** (`catalog.ts`) — `defineCatalog` (permissions declared by their\r\n  full dotted key; `group()` blocks to organize a large one), derived\r\n  template-literal key and pattern types (`KeyOf`, `PatternOf`, plus\r\n  `ClientOf` / `SnapshotOf` for context objects), scope types, navigation\r\n  wiring, requestability, `lintCatalog`, the reserved `alfiz_internal.*`\r\n  project, `toDocument()`/`catalogFromDocument()` (the publish wire shape).\r\n- **Subjects & scopes** (`subjects.ts`, `scopes.ts`) — subject ids and\r\n  closure computation (groups, ancestors, implicit `directs:`/`orgof:`\r\n  groups from reporting edges, orgs, `everyone`); scope ids, the\r\n  `resolveAncestors` seam, object closures.\r\n- **Access algebra** (`access.ts`) — the grant tuple with provenance and\r\n  expiry, personal-only revokes, `checkKey`/`explainKey` (negative always\r\n  wins, scope-inclusive), `checkAny`, granted/revoked scope sets, virtual\r\n  parent dissolution planning.\r\n- **Graph integrity** (`graph.ts`) — cycle detection with named paths,\r\n  whole-graph validation, SCC auto-condensation for directory imports.\r\n- **Requests** (`requests.ts`) — the request object (a proposed grant\r\n  tuple), approval policies (auto predicates, named approvers, management\r\n  layers), pure stage evaluation.\r\n- **Client** (`client.ts`) — `createAlfizClient`: `can` / `canAny` /\r\n  `require*` / `can.fresh`, closure caches parameterized by provider\r\n  invalidation events, `explain`, `grantedScopes`, `holds` / `heldKeys`.\r\n  One name per question, on every surface — the client, the snapshot, and\r\n  the session spell each check shape identically.\r\n  Every check is verified against the catalog first —\r\n  an undeclared key or pattern raises `UnknownPermissionError` (a\r\n  programming error: map it to 500, never 403) instead of being evaluated,\r\n  which is what keeps a misspelled gate from passing for wildcard holders.\r\n  Both caches are LRU-bounded; `subject`/`role`/`scope` events bust in\r\n  O(affected entries) via secondary indexes, and in-flight fetches\r\n  coalesce and honor busts that land mid-flight.\r\n- **Cache tiers** (`cache.ts` + client options) — `revalidateAfterMs`\r\n  turns on epoch revalidation against a provider that persists its\r\n  invalidation events (`provider.epoch`): one constant-cost head read per\r\n  window validates both caches for every principal, renews TTLs while\r\n  writes are quiet, and replays only the missed events when they are not.\r\n  `cacheStore` plugs in a shared L2 (`CacheStore` — three string-valued\r\n  methods, zero dependencies) so cold processes find warm closures;\r\n  `respCacheStore(client)` adapts any RESP-family client (node-redis or\r\n  ioredis call shape — Redis, Valkey, KeyDB, Dragonfly, ElastiCache,\r\n  Upstash) structurally, no dependency added.\r\n- **Snapshot** (`snapshot.ts`) — `client.snapshot(principal)`: one provider\r\n  round-trip, then SYNCHRONOUS `can`/`canAny`/`require*`/`holds`/`heldKeys`\r\n  over one consistent instant — the pattern for server-rendered frameworks,\r\n  where render helpers cannot be async. Flat (`parent: null`) scope types\r\n  check synchronously with no pre-resolution; `resolve(scopes)` extends a\r\n  snapshot after a query without a second fetch (hierarchical list pages).\r\n- **Listing** (`listing.ts`) — `planListing` plus materialized-path and\r\n  closure-table query helpers.\r\n- **Headless tree** (`tree.ts`) — the wildcard-aware permission-tree\r\n  selection logic behind role editors and grant pickers.\r\n- **Metrics** (`metrics.ts`, `otel.ts`) — the optional `CheckObservation`\r\n  stream off every check path, with the shape, decision, permission, scope\r\n  type, principal, and the rows that decided it. Sync, guarded, and\r\n  fire-and-forget: an observer that throws or hangs loses counts, never a\r\n  decision. `sampleRate` is one random draw inside the call before anything\r\n  is built (gates and visibility traffic sampled separately, each\r\n  observation carrying the rate that kept it, so counts extrapolate);\r\n  `createMetricsAggregator` is a pure bounded windowed fold with a live\r\n  `snapshot()` — a complete direct-read API needing no external system;\r\n  `otelMetricsObserver` writes into an OpenTelemetry `Meter` (structurally\r\n  typed, so `@opentelemetry/api` is not a dependency);\r\n  `createProviderMetricsSink` batches to a provider that stores usage; and\r\n  `revocationSafeguard` turns stored usage into the \"what breaks if I revoke\r\n  this\" warning — keyed on `soleMatch`, the counterfactual, never on raw\r\n  participation, and never claiming an unused grant is safe to remove.\r\n- **Provider contract** (`provider.ts`) — the single interface every\r\n  provider implements; capability discovery for progressive disclosure.\r\n\r\nSee the repo root README and `docs/CONVENTIONS.md`.\r\n","readmeFilename":"README.md"}