effectiveRoles: (
claims: any,
carried: string[],
tokenRealm: string,
) => { roles: string[]; subject: Subject; why: string; withdrawn: string[] } = ...
Type Declaration
-
- (
claims: any,
carried: string[],
tokenRealm: string,
): { roles: string[]; subject: Subject; why: string; withdrawn: string[] }
-
Parameters
- claims: any
- carried: string[]
- tokenRealm: string
Returns { roles: string[]; subject: Subject; why: string; withdrawn: string[] }
{ roles, withdrawn, why, subject }: withdrawn is every gated
permission carried that no held role authorizes any longer
Returns the roles a policy should decide on for a verified access token: the roles its subject holds now in the issuing realm, less any role whose permissions the token does not carry (held ∩ carried).
A role revoked after the token was minted stops working at once.