tekir
All Packages
Securityv0.1.4

@tekir/authorize

Policy-based authorization with abilities and policies.

Installation

$bun add @tekir/authorize

Features

  • Named abilities (gates) with define()
  • BasePolicy class for resource-level authorization
  • before() hooks to short-circuit checks
  • can() middleware for route-level authorization
  • AuthorizationResponse with allow/deny and messages

Quick Example

TypeScript
import { Authorize, BasePolicy, can } from '@tekir/authorize'

const auth = new Authorize()
auth.define('edit-post', (user, post) => post.userId === user.id)

app.router.put('/posts/:id', [can('edit-post')], handler)

Changelog

v0.1.4LatestSeptember 16, 2026
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.2June 13, 2026
  • before-hook semantics are now fail-safe and per-ability. A hook only decides the ability it returns a strict true/false or AuthorizationResponse for; an accidental truthy non-boolean is no longer coerced into a global deny, so a hook can no longer lock down the whole system by mistake.
  • can(ability, resolver) now accepts a lazy (ctx) => unknown[] resolver, so the resource can be loaded from the request and ownership/IDOR checks can run in the middleware. The static-args form stays backward compatible.
  • can() now denies when auth.isAuthenticated === false even if a user object is present, falling back to user presence only for older adapters that never set the flag.
  • Found and fixed with Fable.
v0.1.0April 1, 2026
  • Initial release

Other Security packages