{"_id":"@dudousxd/nestjs-authz-telescope","_rev":"2-8af2c17e0246bd18339c24ca3e14e9d0","name":"@dudousxd/nestjs-authz-telescope","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@dudousxd/nestjs-authz-telescope","version":"0.1.0","keywords":["nestjs","authorization","authz","telescope","observability","watcher","extension"],"author":{"name":"Davi Carvalho","email":"davi@goflip.ai"},"license":"MIT","_id":"@dudousxd/nestjs-authz-telescope@0.1.0","maintainers":[{"name":"dudousxd","email":"davi_carvalho96@hotmail.com"}],"homepage":"https://github.com/DavideCarvalho/nestjs-authz#readme","bugs":{"url":"https://github.com/DavideCarvalho/nestjs-authz/issues"},"dist":{"shasum":"07c63da7249b45bc620c494acd2b032249fd1e9e","tarball":"https://registry.npmjs.org/@dudousxd/nestjs-authz-telescope/-/nestjs-authz-telescope-0.1.0.tgz","fileCount":16,"integrity":"sha512-Bn517QIna7nem63HqZKPYmyLNJcyfusUHBhryQ6L8SQSvyUrv70eB9UdCQjMEkwMcKiQZHKEhwi6otpq/dFfgw==","signatures":[{"sig":"MEQCIEmiQ3wNYJ6vL/RJMC5b3i0BKT8Gn9TQ9NzSQ0udfpznAiBO3njavE02HfAdavmcct6TGfp7dv2Ej5qzZqfqVCK9Vw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dudousxd%2fnestjs-authz-telescope@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":30310},"main":"./dist/index.js","type":"module","_from":"file:dudousxd-nestjs-authz-telescope-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"dudousxd","email":"davi_carvalho96@hotmail.com"},"_resolved":"/tmp/5c491527b89e10011fb05955bd404cd6/dudousxd-nestjs-authz-telescope-0.1.0.tgz","_integrity":"sha512-Bn517QIna7nem63HqZKPYmyLNJcyfusUHBhryQ6L8SQSvyUrv70eB9UdCQjMEkwMcKiQZHKEhwi6otpq/dFfgw==","repository":{"url":"git+https://github.com/DavideCarvalho/nestjs-authz.git","type":"git","directory":"packages/telescope"},"_npmVersion":"10.8.2","description":"nestjs-telescope extension for @dudousxd/nestjs-authz — records every authorization decision (ability, allow/deny, reason) in the Telescope dashboard so 403s are debuggable.","directories":{},"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.4.0","@types/node":"^20.0.0","@dudousxd/nestjs-authz":"^0.3.0","@dudousxd/nestjs-telescope":"1.8.0","@dudousxd/nestjs-telescope-testing":"1.8.0"},"peerDependencies":{"@dudousxd/nestjs-authz":">=0.2.0","@dudousxd/nestjs-telescope":"^1.8.0"},"_npmOperationalInternal":{"tmp":"tmp/nestjs-authz-telescope_0.1.0_1781704713277_0.33366711345848654","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Retired: use @dudousxd/nestjs-diagnostics-telescope"}},"time":{"created":"2026-06-17T13:58:33.084Z","modified":"2026-06-17T18:37:42.978Z","0.1.0":"2026-06-17T13:58:33.406Z"},"bugs":{"url":"https://github.com/DavideCarvalho/nestjs-authz/issues"},"author":{"name":"Davi Carvalho","email":"davi@goflip.ai"},"license":"MIT","homepage":"https://github.com/DavideCarvalho/nestjs-authz#readme","keywords":["nestjs","authorization","authz","telescope","observability","watcher","extension"],"repository":{"url":"git+https://github.com/DavideCarvalho/nestjs-authz.git","type":"git","directory":"packages/telescope"},"description":"nestjs-telescope extension for @dudousxd/nestjs-authz — records every authorization decision (ability, allow/deny, reason) in the Telescope dashboard so 403s are debuggable.","maintainers":[{"name":"dudousxd","email":"davi_carvalho96@hotmail.com"}],"readme":"# @dudousxd/nestjs-authz-telescope\n\nA [`@dudousxd/nestjs-telescope`](https://www.npmjs.com/package/@dudousxd/nestjs-telescope) **extension**\nthat records every authorization decision the\n[`@dudousxd/nestjs-authz`](https://github.com/DavideCarvalho/nestjs-authz) `Gate` reaches — the\nability, allow/deny, the reason it was decided, the user and the resource — as a Telescope entry and\na dashboard panel. So when a request 403s, you can see exactly **which** ability was denied and\n**why**.\n\n```bash\npnpm add -D @dudousxd/nestjs-authz-telescope\n```\n\n```ts title=\"app.module.ts\"\nimport { TelescopeModule } from '@dudousxd/nestjs-telescope';\nimport { nestjsAuthzTelescope } from '@dudousxd/nestjs-authz-telescope';\n\n@Module({\n  imports: [\n    AuthzModule.forRoot({ policies: [PostPolicy] }),\n    TelescopeModule.forRoot({\n      extensions: [nestjsAuthzTelescope()],\n    }),\n  ],\n})\nexport class AppModule {}\n```\n\nThat's it — no decorators, no monkey-patching. The Gate publishes each decision on a\n`node:diagnostics_channel` (`nestjs-authz:decision`); the extension's watcher subscribes and records.\nWhen nothing subscribes, the Gate emits nothing — zero overhead.\n\n## What it records\n\nEvery `gate.allows(...)` / `gate.authorize(...)` / `gate.denies(...)` produces one `authorization`\nentry:\n\n```jsonc\n{\n  \"type\": \"authorization\",\n  \"familyHash\": \"update:deny\",\n  \"tags\": [\"ability:update\", \"decision:deny\", \"reason:policy\", \"resource:Post\", \"denied\"],\n  \"content\": {\n    \"ability\": \"update\",\n    \"allowed\": false,\n    \"reason\": \"policy\",      // super-admin | permission-provider | policy-before | policy | gate | anonymous\n    \"user\": \"User#42\",\n    \"resource\": \"Post#7\"\n  }\n}\n```\n\nThe `reason` names the resolution path that produced the verdict, so a deny is never a mystery.\n\n## Dashboard\n\nThe extension contributes an **Authorization** page (under a \"Security\" nav group) with:\n\n- a **top-N of the most denied abilities**, and\n- a **table of the most recent decisions** (ability, decision, reason, user, resource).\n\nIt also registers `authorization` as a navigable entry type so the decisions are filterable in the\nmain Telescope feed.\n\n## Options\n\n| Option | Default | Description |\n| --- | --- | --- |\n| `topDeniedLimit` | `10` | How many denied abilities to surface in the top-N panel. |\n| `recentLimit` | `50` | How many recent decisions to list in the table panel. |\n\n## How it works\n\n`@dudousxd/nestjs-authz`'s `Gate` publishes each decision on the `nestjs-authz:decision`\ndiagnostics channel — a dependency-free, loosely-coupled seam. This package's `AuthorizationWatcher`\nsubscribes on module init; because publishing is synchronous inside the check, recorded entries land\nin the active request/job batch. Malformed or wrong-version payloads are dropped, and recording is\nfully guarded so a Telescope error can never break an authorization check.\n","readmeFilename":"README.md"}