{"_id":"@antoniogiordano/hacli","_rev":"4-2fd8b6454e1804813db412cffa9f8bda","name":"@antoniogiordano/hacli","dist-tags":{"latest":"1.0.2"},"versions":{"0.0.0":{"name":"@antoniogiordano/hacli","version":"0.0.0","description":"ACL support for hapijs apps based on roles and permissions hierarchy","main":"index.js","scripts":{"test":"mocha test","coverage":"istanbul cover _mocha test; cat ./coverage/lcov.info | coveralls"},"repository":{"type":"git","url":"git+ssh://git@github.com/antoniogiordano/hapi-authorization.git"},"keywords":["hapi","auth","authorization","acl"],"contributors":[{"name":"Antonio Giordano","email":"antonio.giordano@getapper.com","url":"http://www.getapper.com"}],"license":"ISC","bugs":{"url":"https://github.com/antoniogiordano/hapi-authorization/issues"},"homepage":"https://github.com/antoniogiordano/hapi-authorization","engines":{"node":">=8.9.0"},"dependencies":{"boom":"^7.2.0","hoek":"^5.0.3","joi":"^13.4.0","underscore":"^1.9.1","underscore.get":"^0.2.9"},"devDependencies":{"chai":"^3.4.1","coveralls":"^2.11.6","hapi":"^17.4.0","istanbul":"^0.4.1","jscoverage":"^0.6.0","mocha":"^2.3.4"},"peerDependencies":{"hapi":">= 17"},"gitHead":"b9660122e5bc349243129a8fd9e33746b9d9ac31","_id":"@antoniogiordano/hacli@0.0.0","_nodeVersion":"12.2.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-QS8QkKlIYDn88Pksl/UgEyF+Rg+2deNY93ZbmfPkYhwNIyiEAxeDmY3NeFP5ZBn6YzxWMRbIsNJI6I+oLzEFsA==","shasum":"c51e1d6e79da794c5f3cc36d382710293febeed2","tarball":"https://registry.npmjs.org/@antoniogiordano/hacli/-/hacli-0.0.0.tgz","fileCount":13,"unpackedSize":146561,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdYr4KCRA9TVsSAnZWagAAgSIP/1zz/mZU8eFt+gl0uchW\nwoZIl1/qoCD/FqgZXPxaUqcw4naZH9Brd18/ePWluB9y4qk2DClxGSxLKUTQ\nsmffiSUscSHY7CZmMhIjFmxSj4BnET93CjOP3XDGhxVaexZXhjRjSr2TsPlU\n/FHva2TGN5AMeoWiErp1AHN1v8ZyIKkjxTOPMNo7DPSbUTCxJKe+3APvJBp/\nu6UtfA4+tp0IPTrtFO024aBFMVtlO5Sc7Z/6lEMiOAon8walX3eI1lrbsdXS\ndCZz415wyke1p29ucriVSzK6w1RI+bxLjWTlzaqwk4hfNjdSUjv4C50DDsTC\nvp1QQ/uMWN2+bXT3U5k0M7sbmW4JeNNRuD3HG6KeBMXV+sPCTzXRlq4cJvDI\nukSRlXBjf7P077nbvIUB8f8Jmrq45YOyeoueF8ieHNFbyY69I9s0Dp1jGQBf\nlbwPnrBfg7RYh8OHLDrrT/t3AL29X9slhwyPcLFsoa0t10FhEoc64Qt4eBtq\ny//Gl3/ZAOIa2qMDlgQy7PL745AebGIK6TK4n6VY5+k27CrLiE8hlscvtDcA\nrjgecbCZu9+9C4aP5cbjXWfck9jrYQyOv16jenY3o/Wj6oURsT4lDqUTOqIz\nTY3nNRgUs2+NqIEsiN1QoAKvqkRnyZfitZZliLZtebvkS3RB7zmK/hSy18f1\nG9kW\r\n=a1Kr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIQCld115hNPAYdivUz0ndo+KTOYOrxqMqioA8cOaTNO1nAIfdPpZwZ682q8kSJ0YIVar+gUsiwp1CWVcFeZ3y6EeHQ=="}]},"maintainers":[{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"}],"_npmUser":{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/hacli_0.0.0_1566752266358_0.9077624342861872"},"_hasShrinkwrap":false},"1.0.0":{"name":"@antoniogiordano/hacli","version":"1.0.0","description":"ACL support for hapijs apps based on roles and permissions hierarchy","main":"index.js","scripts":{"test":"mocha test","coverage":"istanbul cover _mocha test; cat ./coverage/lcov.info | coveralls"},"repository":{"type":"git","url":"git+ssh://git@github.com/antoniogiordano/hapi-authorization.git"},"keywords":["hapi","auth","authorization","acl"],"contributors":[{"name":"Antonio Giordano","email":"antonio.giordano@getapper.com","url":"http://www.getapper.com"}],"license":"ISC","bugs":{"url":"https://github.com/antoniogiordano/hapi-authorization/issues"},"homepage":"https://github.com/antoniogiordano/hapi-authorization","engines":{"node":">=8.9.0"},"dependencies":{"boom":"^7.2.0","hoek":"^5.0.3","joi":"^13.4.0","underscore":"^1.9.1","underscore.get":"^0.2.9"},"devDependencies":{"chai":"^3.4.1","coveralls":"^2.11.6","hapi":"^17.4.0","istanbul":"^0.4.1","jscoverage":"^0.6.0","mocha":"^2.3.4"},"peerDependencies":{"hapi":">= 17"},"gitHead":"c236e6f36a6e9e3cf50581ee24bab58e038e3ecd","_id":"@antoniogiordano/hacli@1.0.0","_nodeVersion":"12.2.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-VTIzpxmflfoxIe3diRKuK94u0Yu6pmPb8KPtUmJqiH2D8ivkjaRctrlolbr3d9jNSKRacEXv7D/PXZ7Zdot2IA==","shasum":"838fa90ea76e2940f37e17b7f5eac10864f3e58c","tarball":"https://registry.npmjs.org/@antoniogiordano/hacli/-/hacli-1.0.0.tgz","fileCount":13,"unpackedSize":151012,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdYvCkCRA9TVsSAnZWagAALSwP/3qBGbVdD15klLmAi+3B\nZJefWw72sFqd8JpdB3ILgxiB/+/Lf4sScmyMAnRgBvpmpOtQAaNVD8CMtewZ\nailF77JsiecP2Hjz+gLQT+8oQ/Pvl+1wQo/DFOe85R9n75K83Bcu5LuJfDNG\nQXVrvDC05w/g0XQnGtdDjoN1zjs7BPhDXcyBFF4Ld5uKNCgmRv5muCZd1wdx\npqqnAB+Qc4e8lZb49Oqpd3yR/ShfS7T5/GTGujxdFsoDUrGUUqzuPa/D+wME\nV2r6LRU8cIUfEz5X5B9nARRTm4S1oPaC+yY5MQKXhAciMyY5yoUJQUJwCOZW\nkQ8r0ne2C846/AlC3JjQhYVrqPPJxsBNdzLRsSq9CLU/xWRBMebbqxP/eQUO\nmj1E7Ji4UCdZW2XrvCrZkKt0JIPTESjJzb/nfw3U71pN4eoSqmPVsPr57HwZ\njwqDXdfyIZ1598Oj8Zg9nIh6mgJ8dc0a1Qj+tj7djgxEUENK+STDTzJJ00eq\nGTkOEgLIkmEp+OUumExB3vzwe4MQzxfuDjuo2yIkdw61e9exv1G47V233XX3\n13ZivJCVn9fFELHlfnX2/83UKJXXon0P8fbWiqQLC0WfqkhM3mTyW22EBPhX\noWjv7XDE943tzljHOapPN/fyf5f/MrAkT36mA4ejXRVPqOm7DzjiDwXWk8h8\nhhr/\r\n=Npij\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEQTa9XM01I4WlVOiH128Vftgwg+xhoWLngediaBOkSvAiEAhLWP013aDfGxNDtcOQzaF/lMCD47/v9i4LLsMlfRTWg="}]},"maintainers":[{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"}],"_npmUser":{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/hacli_1.0.0_1566765219777_0.2895325908779447"},"_hasShrinkwrap":false},"1.0.1":{"name":"@antoniogiordano/hacli","version":"1.0.1","description":"ACL support for hapijs apps based on roles and permissions hierarchy","main":"index.js","scripts":{"test":"mocha test","coverage":"istanbul cover _mocha test; cat ./coverage/lcov.info | coveralls"},"repository":{"type":"git","url":"git+ssh://git@github.com/antoniogiordano/hapi-authorization.git"},"keywords":["hapi","auth","authorization","acl"],"contributors":[{"name":"Antonio Giordano","email":"antonio.giordano@getapper.com","url":"http://www.getapper.com"}],"license":"ISC","bugs":{"url":"https://github.com/antoniogiordano/hapi-authorization/issues"},"homepage":"https://github.com/antoniogiordano/hapi-authorization","engines":{"node":">=8.9.0"},"dependencies":{"boom":"^7.2.0","hoek":"^5.0.3","joi":"^13.4.0","underscore":"^1.9.1","underscore.get":"^0.2.9"},"devDependencies":{"chai":"^3.4.1","coveralls":"^2.11.6","hapi":"^17.4.0","istanbul":"^0.4.1","jscoverage":"^0.6.0","mocha":"^2.3.4"},"peerDependencies":{"hapi":">= 17"},"gitHead":"05d08730cdbddd2c6ccf7b885340a1f178c48ab3","_id":"@antoniogiordano/hacli@1.0.1","_nodeVersion":"12.2.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-bnpma2Fw+DlZ5z+R314v04IdeaFmId5ulJD4QDpkhIjBHreCTOAcEm+ghU+BHtWnowajY7RTjmUroiaCB6mM4A==","shasum":"d11c2366417a4b4bc0e1d073be174c6143f9d8e1","tarball":"https://registry.npmjs.org/@antoniogiordano/hacli/-/hacli-1.0.1.tgz","fileCount":13,"unpackedSize":150882,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdY5T2CRA9TVsSAnZWagAAoQcP/2kNFeNhuUsRECRBIMCH\n+RV8f96KT3wqeINN5SKnsaglSyn2eLTtQfYyrM1DqNWHs7ukewAhpuc+80FL\nB9l0/TYPW16R3Kd6QQo6I6Pebg/fFskl3tog80/VWbjD12Uedb6IQLun5GVH\nIrLF3gSY95shDvraWZt2P/p4QiUwaQpOiOhPG8d1L9Enpj6wruc+VVYTjQJV\nmUw3rl2kByzVEcnlg8g5rdQ+Jy+4MPLE8iPrTiIu6whNLyTQDi1P2crVALH2\nt7UWt3+viyjKFIJG3TeefjogwhjhEZYN/ZFFL+NqhvmOdH0j+wISKabW96Rx\nCB6KyIgveG+NSakKCX729NEYIWGAioBupwD15VbyCkJ3mkNeQzE7lMWeB6V1\nMrOGTIWA1vyDXPvmztJWjikn9AWR35v6R0m0TAHxt1hU2zAlPEXEk/TMSE/T\nTBK0MDwrQW4Avt6mj47awLt6DuB12w1jmTYV9S9NyCiN1CdP/vvkhhdOlN/b\nz8e1tnt6nrwxM33yLY3BsXQ7g3SDX9B6IfhrBL+qHjzSbuiy4swzo22jRgnw\nieqNUutSfu5o2KYYdw7XoHwKCNxKahjZrT1mpictRkKuHJjnW4DIIiqvyEoE\nz1/UIofUVSH0We1rfSsDbc5edmMG9BAIDnJfGKooXlJc2mi0S6WXJkbSmA/C\nq2Lz\r\n=hydY\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDazhxnUd6x2WHoZi1aYAdmuv8VYmANuAY8ZvALtgpWfgIhAL99Iyj4SpGiCSWH6643cDDjvfTn66oSoruh/Vf+hM2B"}]},"maintainers":[{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"}],"_npmUser":{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/hacli_1.0.1_1566807285806_0.6263583684879386"},"_hasShrinkwrap":false},"1.0.2":{"name":"@antoniogiordano/hacli","version":"1.0.2","description":"ACL support for hapijs apps based on roles and permissions hierarchy","main":"index.js","scripts":{"test":"mocha test","coverage":"istanbul cover _mocha test; cat ./coverage/lcov.info | coveralls"},"repository":{"type":"git","url":"git+ssh://git@github.com/antoniogiordano/hapi-authorization.git"},"keywords":["hapi","auth","authorization","acl"],"contributors":[{"name":"Antonio Giordano","email":"antonio.giordano@getapper.com","url":"http://www.getapper.com"}],"license":"ISC","bugs":{"url":"https://github.com/antoniogiordano/hapi-authorization/issues"},"homepage":"https://github.com/antoniogiordano/hapi-authorization","engines":{"node":">=8.9.0"},"dependencies":{"@hapi/joi":"15.1.1","boom":"^7.2.0","hoek":"^5.0.3","underscore":"^1.9.1","underscore.get":"^0.2.9"},"devDependencies":{"chai":"^3.4.1","coveralls":"^2.11.6","hapi":"^17.4.0","istanbul":"^0.4.1","jscoverage":"^0.6.0","mocha":"^2.3.4"},"peerDependencies":{"hapi":">= 17"},"gitHead":"946e959ebc3f02e01e6168924e4932db0a41bb9a","_id":"@antoniogiordano/hacli@1.0.2","_nodeVersion":"12.2.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-xmU/1NFXHzzqalg5ltK5WtLfrtKe5XjokkhgxwzUUHez+gljMVkcu8RcC1il01vvLHHNbo7SA/AvBG6ReSfMGQ==","shasum":"23ecf7ce204f1d4261596b86b06ed79fb342c7f2","tarball":"https://registry.npmjs.org/@antoniogiordano/hacli/-/hacli-1.0.2.tgz","fileCount":13,"unpackedSize":134796,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdY93LCRA9TVsSAnZWagAA3WEQAJ0fFdDJop6JHG15ktJ1\nNF1Ws8JhwmQ1sHqCdwB0LAQvYdh6JBvFn0v7CMTP/olw32Trwat6cwvEKS/T\n8tJRPvSpTzTJ6Bk0tn+2vs010+1zU4hKRI31o7qXlzDv3HTZw1cD9jw4BG6+\n3NW1eU7NRJ0rEV9TDM5M2dlSWlz2ouqri1K7UIYBR/alAEFrPsGQNNvGRtJJ\nI6PDm6UwF2Gjf/faI3f+QYsxIayfDmS5T/Rpy3BkkTd+PGp3HrXcqg7/eYda\nDUd5TSlRPF1aIxe02m2a8PIqMW55b+ah6CdE2gDz6v0qnzm2xeb3r9ZSj4eS\nLHbcTqYjPU+wWfasPumu4QS7AVSHVdFwrGn3eqG/oSYPgVRYh6gFtmX/ASBu\nGmdUC4Qc3uCofbpcgTJ8BEL23anaX7h08ZmRjdj9vu15d7vUKE5i8dtQKQ3B\nNYNUDW0oRbYS2O8r7lLrpkr2vxI0MCwGb7kwPPQz2UEw7Rg+4BizMPM4uH8p\nxJkeL7PXLl+F+tMdATNHnXW+IDSlJGK8YT4phW4TtpYHSP6AxPgkgj+vVYt/\nAPYxCuNX6738xS0MGcxO4RX88TVYEwh5t7VmQMXaur4LJb3vB+HFdxnphBac\nCHY2ccatB3AFUt2CoDThoUjiha2OXPIsSnx2y5CkjvTYVtFzO4jnidc6/P7t\nnPNf\r\n=gGJ+\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDdcpzFMKGdwkxrF30KIDwFKAhe4/YSEZuxkrabPg9xpgIhAPXIldmZnhAMYZ55QI98HuSKwVYRC/1ixAPGLadABGvQ"}]},"maintainers":[{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"}],"_npmUser":{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/hacli_1.0.2_1566825930576_0.7544069294910611"},"_hasShrinkwrap":false}},"time":{"created":"2019-08-25T16:57:46.145Z","0.0.0":"2019-08-25T16:57:46.487Z","modified":"2022-04-04T14:23:18.193Z","1.0.0":"2019-08-25T20:33:39.941Z","1.0.1":"2019-08-26T08:14:45.951Z","1.0.2":"2019-08-26T13:25:30.722Z"},"maintainers":[{"name":"antoniogiordano","email":"antonio.giordano@getapper.com"}],"description":"ACL support for hapijs apps based on roles and permissions hierarchy","homepage":"https://github.com/antoniogiordano/hapi-authorization","keywords":["hapi","auth","authorization","acl"],"repository":{"type":"git","url":"git+ssh://git@github.com/antoniogiordano/hapi-authorization.git"},"contributors":[{"name":"Antonio Giordano","email":"antonio.giordano@getapper.com","url":"http://www.getapper.com"}],"bugs":{"url":"https://github.com/antoniogiordano/hapi-authorization/issues"},"license":"ISC","readme":"# hacli\r\n\r\n*hacli only supports hapi 17+*\r\n\r\n> ACL support for hapijs apps based on permissions hierarchy\r\n\r\n[![npm version][npm-badge]][npm-url]\r\n[![Build Status][travis-badge]][travis-url]\r\n[![Coverage Status][coveralls-badge]][coveralls-url]\r\n\r\nYou can use this plugin to add ACL and protect your routes. You can configure required permissions and allow access to certain endpoints only to specific users or to users having that specific permission.\r\n\r\n# Installation\r\n\r\n```npm i @antoniogiordano/hacli -S```\r\n\r\n# Usage\r\n\r\n**Note**: To use hacli you must have an authentication strategy defined.\r\n\r\nThere are 2 ways to use hacli:\r\n\r\n1. With the default permissions which are: \"SUPER_ADMIN\", \"ADMIN\", \"USER\", \"GUEST\"\r\n2. By defining your own permissions\r\n\r\n## Using hacli with default permissions\r\n1. Include the plugin in your hapijs app.\r\nExample:\r\n```js\r\nlet plugins = [\r\n\t{\r\n\t\tplugin: require('hapi-auth-basic')\r\n\t},\r\n\t{\r\n\t\tplugin: require('@antoniogiordano/hacli'),\r\n\t\toptions: {}\r\n\t}\r\n];\r\n\r\nawait server.register(plugins);\r\n```\r\n\r\n## Using hacli with a list of permissions\r\n1. Include the plugin in your hapijs app.\r\nExample:\r\n```js\r\nlet plugins = [\r\n\t{\r\n\t\tplugin: require('hapi-auth-basic')\r\n\t},\r\n\t{\r\n\t\tplugin: require('@antoniogiordano/hacli'),\r\n\t\toptions: {\r\n\t\t\tpermissions: ['CAN_CREATE_RESOURCE', 'CAN_EDIT_RESOURCE', 'CAN_DELETE_RESOURCE']\r\n\t\t}\r\n\t}\r\n];\r\n\r\nawait server.register(plugins);\r\n```\r\n\r\n## Using hacli with an hierarchy of permissions\r\n1. Include the plugin in your hapijs app.\r\nExample:\r\n```js\r\nlet plugins = [\r\n\t{\r\n\t\tplugin: require('hapi-auth-basic')\r\n\t},\r\n\t{\r\n\t\tplugin: require('@antoniogiordano/hacli'),\r\n\t\toptions: {\r\n\t\t\tpermissions: {\r\n\t\t\t  SUPERADMIN: {\r\n\t\t\t    ADMIN: {\r\n                  CAN_EDIT_RESOURCE: {},\r\n                  CAN_DELETE_RESOURCE: {},\r\n                  USER: {\r\n\t\t\t        CAN_CREATE_RESOURCE: {},\r\n                  }               \r\n                }               \r\n              }                   \r\n            }\r\n\t\t}\r\n\t}\r\n];\r\n\r\nawait server.register(plugins);\r\n```\r\n\r\n## permissions option\r\nhacli behaviour is based on the ``permissions`` option type passed during plugin configuration, that can be an array or an object.\r\nIf ``permissions`` is an array, then the order of the permissions string has NO hierarchy effect, and every permission will be treated separately.\r\nInstead, if you pass an object as a ``permissions`` option, that you can nest the permissions in an hierarchy form, where all the keys nested inside an other one, are included in that.\r\nIn the previous example, a user with a SUPERADMIN permission, can actually access ALL the other permissions, because they are all nested inside it. In the same way, a user with USER permission, can access all the routes with both USER and CAN_CREATE_RESOURCE permissions.\r\n\r\n## Full Examples using hapi-auth-basic and hacli\r\n\r\n### permissions array\r\n```js\r\nconst Hapi = require('hapi');\r\n\r\n// Instantiate the server\r\nlet server = new Hapi.Server();\r\n\r\n/**\r\n * The hapijs plugins that we want to use and their configs\r\n */\r\nlet plugins = [\r\n\t{\r\n\t\tregister: require('hapi-auth-basic')\r\n\t},\r\n\t{\r\n\t\tregister: require('@antoniogiordano/hacli'),\r\n\t\toptions: {\r\n\t\t\tpermissions: ['OWNER', 'MANAGER', 'EMPLOYEE']\r\n\t\t}\r\n\t}\r\n];\r\n\r\nlet validate = (username, password) => {\r\n\t// Perform authentication and respond with object that contains a permission or an array of permissions\r\n\treturn {username: username, permission: 'EMPLOYEE'};\r\n}\r\n\r\n/**\r\n * Setup the server with plugins\r\n */\r\nawait server.register(plugins);\r\nserver.start().then(() => {\r\n\r\n\tserver.auth.strategy('simple', 'basic', {validateFunc: validate});\r\n\tserver.auth.default('simple');\r\n  \r\n    server.route({\r\n     method: 'GET',\r\n     path: '/getEmployeesList',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'OWNER'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with EMPLOYEE permission can NOT access this!\r\n\r\n    server.route({\r\n     method: 'GET',\r\n     path: '/getReport',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'EMPLOYEE'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with EMPLOYEE permission can access this!\r\n\r\n\t/**\r\n\t * Starts the server\r\n\t */\r\n\tserver.start()\r\n        .then(() => {\r\n            console.log('Hapi server started @', server.info.uri);\r\n        })\r\n        .catch((err) => {\r\n            console.log(err);\r\n        });\r\n})\r\n.catch((err) => {\r\n  // If there is an error on server startup\r\n  throw err;\r\n});\r\n```\r\n\r\n### permissions hierarchy object\r\n```js\r\nconst Hapi = require('hapi');\r\n\r\n// Instantiate the server\r\nlet server = new Hapi.Server();\r\n\r\n/**\r\n * The hapijs plugins that we want to use and their configs\r\n */\r\nlet plugins = [\r\n\t{\r\n\t\tregister: require('hapi-auth-basic')\r\n\t},\r\n\t{\r\n\t\tregister: require('@antoniogiordano/hacli'),\r\n\t\toptions: {\r\n            permissions: {\r\n              SUPERADMIN: {\r\n                CAN_CREATE_ADMIN: {},\r\n                CAN_LIST_ADMINS: {},\r\n                CAN_VIEW_FULL_REPORT: {},\r\n                ADMIN: {\r\n                  CAN_EDIT_RESOURCE: {},\r\n                  CAN_DELETE_RESOURCE: {},\r\n                  USER: {\r\n                    CAN_CREATE_RESOURCE: {},\r\n                  }               \r\n                }               \r\n              }                   \r\n            }\r\n\t\t}\r\n\t}\r\n];\r\n\r\nlet validate = (username, password) => {\r\n\t// Perform authentication and respond with object that contains a permission or an array of permissions\r\n\treturn {username: username, permissions: ['ADMIN', 'CAN_VIEW_FULL_REPORT']};\r\n}\r\n\r\n/**\r\n * Setup the server with plugins\r\n */\r\nawait server.register(plugins);\r\nserver.start().then(() => {\r\n\r\n\tserver.auth.strategy('simple', 'basic', {validateFunc: validate});\r\n\tserver.auth.default('simple');\r\n  \r\n    server.route({\r\n     method: 'GET',\r\n     path: '/listAdmins',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'CAN_LIST_ADMINS'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with ['ADMIN', 'CAN_VIEW_FULL_REPORT'] permissions can NOT access this!\r\n\r\n    server.route({\r\n     method: 'GET',\r\n     path: '/getAdminProfile',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'ADMIN'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with ['ADMIN', 'CAN_VIEW_FULL_REPORT'] permissions can access this!\r\n\r\n    server.route({\r\n     method: 'GET',\r\n     path: '/getAdminProfile',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'ADMIN'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with ['ADMIN', 'CAN_VIEW_FULL_REPORT'] permissions can access this!\r\n\r\n    server.route({\r\n     method: 'POST',\r\n     path: '/createResource',\r\n     config: {\r\n       handler: () => null, // some handler function\r\n       plugins: {\r\n         hacli: {\r\n           permissions: 'CAN_CREATE_RESOURCE'\r\n         }\r\n       }\r\n     }\r\n    })\r\n    // Our user with ['ADMIN', 'CAN_VIEW_FULL_REPORT'] permissions can access this!\r\n\r\n\t/**\r\n\t * Starts the server\r\n\t */\r\n\tserver.start()\r\n        .then(() => {\r\n            console.log('Hapi server started @', server.info.uri);\r\n        })\r\n        .catch((err) => {\r\n            console.log(err);\r\n        });\r\n})\r\n.catch((err) => {\r\n  // If there is an error on server startup\r\n  throw err;\r\n});\r\n```\r\n\r\n#### Whitelist Routes That Require Authorization\r\nIf you want no routes require authorization except for the ones you specify in the route config, add hacli instructions with the permission(s) that should have access to the route configuration.\r\n\r\nExample:\r\n\r\n**Authorize a single permission**\r\n```js\r\nserver.route({ method: 'GET', path: '/', options: {\r\n  plugins: {'hacli': {permission: 'ADMIN'}},\t// Only ADMIN permission\r\n  handler: (request, h) => { return \"Great!\"; }\r\n}});\r\n```\r\n\r\n**Authorize multiple permissions**\r\n```js\r\nserver.route({ method: 'GET', path: '/', options: {\r\n  plugins: {'hacli': {permissions: ['USER', 'ADMIN']}},\r\n  handler: (request, h) => { return \"Great!\"; }\r\n}});\r\n```\r\n\r\n#### Blacklist All Routes To Require Authorization\r\n\r\nIf you want all routes to require authorization except for the ones you specify that should not, add hacli instructions with the permission(s) that should have access to the server.connection options. Note that these can be overridden on each route individually as well.\r\n\r\nExample:\r\n\r\n```js\r\nlet server = new Hapi.server({\r\n\troutes: {\r\n\t\tplugins: {\r\n\t\t\thacli: { permissions: ['ADMIN'] }\r\n\t\t}\r\n\t}\r\n});\r\n```\r\n\r\n**Override the authorization to require alternate permissions**\r\n```js\r\nserver.route({ method: 'GET', path: '/', options: {\r\n  plugins: {'hacli': {permission: 'USER'}},\t// Only USER permission\r\n  handler: (request, h) => { return \"Great!\" ;}\r\n}});\r\n```\r\n\r\n**Override the authorization to not require any authorization**\r\n```js\r\nserver.route({ method: 'GET', path: '/', options: {\r\n  plugins: {'hacli': false},\r\n  handler: (request, h) => { return \"Great!\"; }\r\n}});\r\n```\r\n\r\n**Note:** Every route that uses hacli must be protected by an authentication schema either via `auth.strategy.default('someAuthStrategy')` or by specifying the auth on the route itself.\r\n\r\n## Gotchas\r\n\r\n### Auth before routes\r\nYou must define your auth strategy before defining your routes, otherwise the route validation will fail.\r\n\r\n\r\n## Plugin Config\r\n\r\n* `permissions` \t\t\t\t- `Array|Object`: All the possible permissions. Defaults to permissions list [`SUPER_ADMIN`, `ADMIN`, `USER`, `GUEST`]. Can be an hierarchy object where every key is a permission, and can or not contain other permission keys. The \"leaves\" of the object (permission keys without sub-permissions) should any way be empty object.\r\n* `userPath` \t\t\t\t    - `String`: Where hacli should look for user object inside the request object. Defaults to \"auth.credentials\", that resolves to request.auth.credentials \r\n\r\n\r\n\r\n## Route config of supported parameters:\r\n* `permission` - `String`: enforces that only users that have this permission can access the route\r\n* `permissions` - `Array`: enforces that only users that have at least one of these permissions can access the route\r\n* `aclQuery` - `Function`: fetches an entity using the provided query, it allows the plugin to verify that the authenticated user has permissions to access this entity. the function signature should be `function(parameter, request)`.\r\n* `aclQueryParam` - `String`: The parameter key that will be used to fetch the entity. default: 'id'\r\n* `paramSource` - `String`: The source of the acl parameter, allowed values: payload, params, query.\r\n* `validateEntityAcl` - `Boolean`: Should the plugin validate if the user has access to the entity. if true, validateAclMethod is required.\r\n* `validateAclMethod` - `String`: A function name. the plugin will invoke this method on the provided entity and will use it to verify that the user has permissions to access this entity. function signature is `function(user, permission)`;\r\n\r\n\r\n[npm-badge]: https://badge.fury.io/js/%40antoniogiordano%2Fhacli.svg\r\n[npm-url]: https://www.npmjs.com/package/@antoniogiordano/hacli\r\n[travis-badge]: https://travis-ci.org/antoniogiordano/hacli.svg?branch=master\r\n[travis-url]: https://travis-ci.org/antoniogiordano/hacli\r\n[coveralls-badge]: https://coveralls.io/repos/antoniogiordano/hacli/badge.svg?branch=master&service=github\r\n[coveralls-url]:  https://coveralls.io/github/antoniogiordano/hacli?branch=master\r\n","readmeFilename":"README.md"}