yetki 0.2.0
yetki: ^0.2.0 copied to clipboard
Role-based access control (RBAC) for Dart: role inheritance, wildcard permissions, pluggable persistence and change notifications.
0.2.0 #
A redesign that fixes correctness and security problems in 0.1.x. This release has breaking changes; see the migration guide.
Fixed #
- Loading the cache no longer races with changes made right after construction. Previously this could wipe the cached policy or the new changes.
- Changes made to a
RoleorYetkiUserafter registering them are no longer lost. Models are now immutable, and every change goes throughYetki. - A revoked role no longer comes back after a restart. The current user is no longer persisted.
removeRoleandremovePermissionnow also clean up the current user and role inheritance, so re-adding an id no longer restores access silently.hasRoleis nowfalsefor roles that are not registered.importFromJsonis now atomic and reports errors by throwing.- Singleton instances no longer silently ignore constructor arguments.
- The library no longer calls
print.
Added #
- Role inheritance (
Role.inherits) with cycle detection. - Wildcard grants:
posts.*and*. - Validation of ids and references, with a sealed
YetkiExceptionhierarchy. Yetki.changesstream anddispose().Yetki.create(storage:, onError:)and theYetkiStorageinterface, withInMemoryYetkiStorage. Writes are serialized and coalesced;flush()andreset()were added.addPermissions,addRoles,updatePermission,grantPermissionToRole,revokePermissionFromRole, and current-user helpersassignRole,revokeRole,grantDirectPermissionandrevokeDirectPermission.requirePermission,grantedPermissions, and an optionaluser:argument on every check.copyWithandwith…/without…helpers, and value equality on all models.- Versioned export format. The 0.1.x format can still be imported.
Changed #
- The package is now pure Dart. Flutter integration and shared_preferences
storage moved to the new
yetki_flutterpackage. - The minimum Dart SDK is now 3.8.
getCurrentUser,getAllRolesandgetAllPermissionsare deprecated in favor of thecurrentUser,rolesandpermissionsgetters.
Removed #
useSingleton,useCache,clearInstance()andclearCache().- The mutating methods on
RoleandYetkiUser.
0.1.0 #
- Initial public release: permissions, roles, users, singleton support and shared_preferences caching.
0.0.2 #
- Updated pubspec.yaml.