Skip to content

Commit 48d3d2b

Browse files
committed
docs(skills): gate the usePermissions example on can(), a boolean, and mark its fence
The `usePermissions` hook example in `skills/objectui/guides/auth-permissions.md` gated two buttons on `check('contacts', 'update', contact)`. `check` answers a `PermissionCheckResult` object, an object is truthy, and so both buttons rendered for every user, denied ones included. The fence was unmarked, so `check-skill-examples` never compiled it. The example now gates on `can('contacts', 'update')` / `can('contacts', 'delete')` — the one boolean spelling the guide's neighbouring paragraph already publishes — annotated `: boolean` so a `check(...)` put back in that position fails to compile. The record argument is dropped: measured against the built `@object-ui/permissions` dist with a throwing Proxy as the record, `evaluatePermission` performs zero property reads on it, and `can()` agrees with `check(..., record).allowed` on every (role, action) of the guide's own config. The fence carries the `os:check` marker and is tagged `tsx`, imports `Button` from `@object-ui/components`, and types `contact` inline, so the gate compiles it against the built dist from now on (Semantic phase: 16 of 16 ts fences). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W5y9kRg1YtYaMQYExVLRc2
1 parent edbcf1e commit 48d3d2b

1 file changed

Lines changed: 11 additions & 5 deletions

File tree

‎skills/objectui/guides/auth-permissions.md‎

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -221,14 +221,20 @@ guide does not govern it; the two look alike and are unrelated.
221221

222222
### usePermissions hook
223223

224-
```typescript
224+
<!-- os:check -->
225+
```tsx
225226
import { usePermissions } from '@object-ui/permissions';
227+
import { Button } from '@object-ui/components';
226228
227-
function ContactActions({ contact }) {
228-
const { check, checkField, getFieldPermissions, getRowFilter } = usePermissions();
229+
function ContactActions({ contact }: { contact: { salary?: number } }) {
230+
const { can, checkField, getFieldPermissions, getRowFilter } = usePermissions();
229231
230-
const canEdit = check('contacts', 'update', contact);
231-
const canDelete = check('contacts', 'delete', contact);
232+
// Gate on `can`, which answers a boolean. `check` answers `{ allowed, … }`, and
233+
// an object is truthy, so gated on it both buttons render for a denied user
234+
// too; its `record` argument reads no field of the record, so none is passed.
235+
// `: boolean` is what makes a `check(...)` here fail to compile.
236+
const canEdit: boolean = can('contacts', 'update');
237+
const canDelete: boolean = can('contacts', 'delete');
232238
const canSeeSalary = checkField('contacts', 'salary', 'read');
233239
234240
return (

0 commit comments

Comments
 (0)