Skip to content

Add a coverage getter: how much of the policy a role reaches #141

Description

@onury

A consumer that wants to show how far a role reaches (its granted resource and action cells, own and inherited, over all of them) has to count cells itself from getGrants(). That count is only right while every grant is possession: 'any', attributes: ['*'], unconditional and effect: 'grant'. An own grant, an attribute filter, a condition or a deny each make it overstate.

Coverage belongs in the model, so a consumer reads it instead of re-deriving it.

Roughly: ac.coverage(role, { resources?, actions?, context? }) returning { total, full, partial, denied, ratio }, with a per-resource breakdown on request.

  • Actions are free strings, so the universe is not fixed. The caller passes it, or it defaults to the union of actions the grants name.
  • Inheritance resolves the way a check does: $extend and deny-overrides, not a walk over getGrants().
  • A narrowed grant (own, filtered attributes) counts as partial, reported apart. The consumer decides what it is worth.
  • A condition cannot be judged without a context, so a conditional grant is partial unless context is passed; then it counts as it evaluates.
  • Tests: an all-any role scores 1; an own, a filtered, a conditional and a denied cell each move it the right way; inheritance and deny-overrides hold.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions