Securityv0.1.4
@tekir/authorize
Policy-based authorization with abilities and policies.
Installation
$
bun add @tekir/authorizeFeatures
- Named abilities (gates) with define()
- BasePolicy class for resource-level authorization
- before() hooks to short-circuit checks
- can() middleware for route-level authorization
- AuthorizationResponse with allow/deny and messages
Quick Example
TypeScript
import { Authorize, BasePolicy, can } from '@tekir/authorize'
const auth = new Authorize()
auth.define('edit-post', (user, post) => post.userId === user.id)
app.router.put('/posts/:id', [can('edit-post')], handler)Changelog
v0.1.4LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.2June 13, 2026
- before-hook semantics are now fail-safe and per-ability. A hook only decides the ability it returns a strict
true/falseorAuthorizationResponsefor; an accidental truthy non-boolean is no longer coerced into a global deny, so a hook can no longer lock down the whole system by mistake. can(ability, resolver)now accepts a lazy(ctx) => unknown[]resolver, so the resource can be loaded from the request and ownership/IDOR checks can run in the middleware. The static-args form stays backward compatible.can()now denies whenauth.isAuthenticated === falseeven if a user object is present, falling back to user presence only for older adapters that never set the flag.- Found and fixed with Fable.
v0.1.0April 1, 2026
- Initial release