{"_id":"@andrew_l/lilu","_rev":"1-a5a575272a2f0531d5e5e966884b5459","name":"@andrew_l/lilu","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@andrew_l/lilu","version":"1.0.0","description":"Attribute-based access control with some sugar","main":"dist/lilu.cjs.js","module":"dist/lilu.esm.js","browser":"dist/lilu.umd.js","scripts":{"build":"rollup -c","lint":"eslint lib","test":"echo \"Error: no test specified\" && exit 1"},"keywords":["abac","access","control"],"engines":{"node":">=6.0.0"},"author":{"name":"Andrew L."},"license":"MIT","directories":{"src":"src","dist":"dist","examples":"examples"},"repository":{"type":"git","url":"git+https://github.com/men232/lilu-js.git"},"devDependencies":{"@babel/core":"^7.11.6","@babel/plugin-proposal-class-properties":"^7.10.4","@babel/plugin-transform-runtime":"^7.12.1","@babel/preset-env":"^7.11.5","@rollup/plugin-babel":"^5.2.1","@rollup/plugin-commonjs":"^15.1.0","@rollup/plugin-json":"^4.1.0","@rollup/plugin-node-resolve":"^9.0.0","babel-eslint":"^10.1.0","eslint":"^7.10.0","js-yaml":"^3.14.0","rollup":"^2.28.2","rollup-plugin-terser":"^7.0.2"},"dependencies":{"clone-deep":"^4.0.1","debug":"^4.2.0","esprima":"^4.0.1","glob-to-regexp":"^0.4.1","static-eval":"^2.1.0"},"gitHead":"232b644d938bc13e2824941a1017096af15ed7e0","bugs":{"url":"https://github.com/men232/lilu-js/issues"},"homepage":"https://github.com/men232/lilu-js#readme","_id":"@andrew_l/lilu@1.0.0","_nodeVersion":"12.16.2","_npmVersion":"6.14.4","dist":{"integrity":"sha512-aBnCcvmBvTyCOmZUNLez34SJfuu1rqG03U5TP7dG9UYM66ciroLvfR1KtBinqlE2swqEo9XCjjFOCjNEdkXghA==","shasum":"0957154a13a2ada9d9c0cad4a1fe34b529b366b0","tarball":"https://registry.npmjs.org/@andrew_l/lilu/-/lilu-1.0.0.tgz","fileCount":43,"unpackedSize":3679957,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfnApWCRA9TVsSAnZWagAAEAEP+QGTZXk5JjWiskvL1aGe\nhY8Jv4S4iy4Ei5/BastzMdj+5ZplqAlNm+EwuFc1/77EaNnwANGdR4d4JXG9\nsxJhc3X3ryeZGp69a93FNADRzOMXyfV7HY2i2ikpANNAA8PitsKIAPY7nQFw\nKZkf4O6bUcfyuaN3Mn+O6YBI0OT2Ap1LBwLG7C/wW17YE7cQjWBpZYJAB4l8\nw6/1yucNz6RypIg8Rzg7Uw7xSQ9m5Mny0BWMO2i6HzZyPMpjdCpSd3CH/pJr\noIvImNDEkv/3ZK2obQFDOlAZveqptZtdBZEqU0Fe/x65eIjIFF/pSH/ME3Jl\n8uljYi5NmR/vE3V8aasRXmcDnk8lQPmHZPPa3pz6XNrRJjuZTrLvY4CaC0A9\nHbzwHmD6pypDEXip0ocNw2+MQFyyrjwkuXY0o18bNpFWti4GUpYwlKUn223H\nPAFTBIfQOrlNHuVSTe65in0iBf2OzHX5Ez4u+AlBt17MS/PfQ2//SO8Z7cf7\nbcEwweITqaw1JJ+z2c7E9BF2FDhv3BGQ3GgJJ63hC5pMSGwuz1drNJdDyPhc\nRby4CuPt9kQcH8uC/lkUHOKJ1znjJTiEIGR/LDs0cFvx0e6gSRda8pArsHFS\n/ctmztCK4gbp9CzZdWLVAAWmgf5/p0ky9VbNcpkkm5syVZDMxi0/9jT2I9N8\nA6OH\r\n=KhjR\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDxvw/+XrBkwf5nv10DWKAXIz0Hi67P0o2zoH/viGLmaAIgH1ls84jTJ6hPHqCUMR7aXNMyuhcCy4Q48sgQkPE4pJ4="}]},"maintainers":[{"name":"andrew_l","email":"andrew.io.dev@gmail.com"}],"_npmUser":{"name":"andrew_l","email":"andrew.io.dev@gmail.com"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/lilu_1.0.0_1604061782013_0.45655284123458895"},"_hasShrinkwrap":false}},"time":{"created":"2020-10-30T12:43:01.945Z","1.0.0":"2020-10-30T12:43:02.235Z","modified":"2022-04-04T14:01:12.811Z"},"maintainers":[{"name":"andrew_l","email":"andrew.io.dev@gmail.com"}],"description":"Attribute-based access control with some sugar","homepage":"https://github.com/men232/lilu-js#readme","keywords":["abac","access","control"],"repository":{"type":"git","url":"git+https://github.com/men232/lilu-js.git"},"author":{"name":"Andrew L."},"bugs":{"url":"https://github.com/men232/lilu-js/issues"},"license":"MIT","readme":"![Image of Yaktocat](https://pbs.twimg.com/profile_images/901714986006970369/sQc7Guot_400x400.jpg)\n\n`npm i @andrew_l/lilu`\n\n# LiLu\nAttribute-based access control with some sugar.\n\n# Permissions example\n\n```yaml\npermissions:\n- title: Any User\n  actions: ['order.view', 'order.edit']\n  rules:\n  - title: 'Owned'\n    operation: AND\n    conditions:\n    - order.owner == user.id\n\n- title: Delete Order\n  actions: ['order.delete']\n  rules:\n  - title: 'Owned'\n    operation: AND\n    conditions:\n    - order.owner == user.id\n  - title: 'Recently Placed'\n    operation: AND\n    conditions:\n    - order.placedAt = {{ env.now - (1000 * 60 * 60 * 24 * 5) }}\n```\n\n# Usage\n```js\nimport { Lilu } from 'lilu';\n\nconst user = {\n  id: 1,\n  name: 'Andrew L.',\n  email: 'andrew.io.dev@gmail.com',\n  role: ['ROLE_USER']\n};\n\nconst order = {\n  title: 'Netflix Subscription',\n  owner: 1,\n  placedAt: new Date(),\n  items: [1, 2, 3, 4]\n};\n\nconst lilu = new Lilu({\n  strict: false,\n  permissions: [{\n    title: 'Review Order',\n    actions: ['order.view'],\n    rules: [{\n      title: 'Owned',\n      operation: 'AND',\n      conditions: [\n        'order.owner == user.id',\n      ]\n    }]\n  }]\n});\n\nlilu.granted('order.view', { user, order }, function(err, result) {\n  if (err) {\n    console.warn('Failed to process lilu access', err);\n    return;\n  }\n\n  if (result.passed) {\n    console.log('Yahu!!! I have access to review order.');\n  } else {\n    console.log('Oops!! I don\\'t have access to review order.');\n  }\n});\n\n```\n\nTo investigate more use cases, please check [examples folder](examples).\n\n## What is strict mode?\nIn this mode the module makes expression validation before granted function be called.\nAlso strict mode requires to pass all variables in context that used in rules conditions.\n\n## Condition operators\n|    | Description                                   |\n|----|-----------------------------------------------|\n| >  | Greater than                                  |\n| => | Greater  or equal to                          |\n| <  | Less than                                     |\n| <= | Less  or equal to                             |\n| == | Equal to                                      |\n| != | Not equal to                                  |\n| in | Value equals any value in the specified array |\n\n## Context variables\nEach time when you call granted function, you can pass the context of execution.\nFor example we need to make sure that user has admin role before delete the order.\n\n### 1 • Our case have next permission rules.\n\n```js\nconst permissions = {\n  strict: false,\n  permissions: [{\n    title: 'Remove Order',\n    actions: ['order.remove'],\n    rules: [{\n      title: 'Admin Access',\n      operation: 'AND',\n      conditions: [\n        'user.roles in \"ROLE_ADMIN\"',\n      ]\n    }]\n  }]\n}\n```\n\n### 2 • We have next context.\n\n```js\nconst context = {\n  user: {\n    name: 'Andrew',\n    roles: [\"ROLE_USER\"]\n  }\n};\n```\n\n### 3 • Now we can use context to check access.\n\n```js\nconst lilu = new Lilu({\n  strict: false,\n  permissions: permissions /* from step 1 */,\n});\n\nlilu.granted('order.remove', context /* from step 2 */, function(err, result) {\n  if (err) {\n    console.warn('Failed to process lilu access', err);\n    return;\n  }\n\n  if (result.passed) {\n    console.log('Yahu!!! I have access to delete order.');\n  } else {\n    console.log('Oops!! I don\\'t have access to delete order.');\n  }\n});\n```\n\n### Rules operation\nOur rules can be checked by follow operations:\n\n|     | Description                         |\n|-----|-------------------------------------|\n| AND | Each rule conditions must be true   |\n| OR  | Any of rule conditions must be true |\n\n## Rules conditions\nIt's pretty simple js-like expression parser inside, just to give you ability to use plain string.\n\n| Type           | Description                                                             | Example                                                   |\n|----------------|-------------------------------------------------------------------------|-----------------------------------------------------------|\n| Literal values | Support literal values like number and boolean.                         | `user.disabled == true`                                   |\n| String         | Should be in double quotes.                                             | `user.name == \"some text\"`                                |\n| Array          | Array expression should be in quotes. Also it support variables inside. | `user.roles in [\"ROLE_USER\", \"ROLE_MANAGER\"]`             |\n| Expression     | You also can use native javascript expression in two curly quotes.      | `user.createdAt > {{ Date.now() - 1000 * 60 * 60 * 24 }}` |\n","readmeFilename":"README.md"}