CapabilityScope typedef

CapabilityScope = Object?

An explicit statement of the capabilities an entry holds. Exactly one of three shapes, discriminated by scope: ceiling (the role's full ceiling), none, or listed with a NON-EMPTY list of CapabilityGrant. The empty list is invalid, not a fourth shape.

Implementation

typedef CapabilityScope = Object?;