Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature Request] .check method for v3

Open
#2,339 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
15/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
typescript
Domain
authorization

Research direction

Start from the v2 check-permission guide (zenstack.dev/docs/2.x/guides/check-permission) to see how the removed .check API worked, then compare with the current v3 enhanced-client entry points and the policy-writing docs at zenstack.dev/docs/orm/access-control/write-policies. The proposal is an isAllowedTo('create' | 'update', ...) style call on the auth-scoped client, covering both model-level and row-level checks. Note v3 permission handling changed, so an equivalent design (or a decision to keep it removed) needs maintainer input before any test surface is chosen; none is defined here yet.

Written by the indexing model from the issue text.

Description

Turns out it was implemented in v2 the .check method

https://zenstack.dev/docs/2.x/guides/check-permission

Is your feature request related to a problem? Please describe.
Yes my schema defines permissions per row, some rows are editable, deleteable etc by a certain user, only my frontend is not aware of this. Currenly im mimicking my policies in some sort of permission layer to figure out if i need to show or hide a edit button in my admin area.

Describe the solution you'd like
I would like to have a similar solution as in Ruby's best authorisation plugin CanCanCan as explained here: https://github.com/CanCanCommunity/cancancan/blob/develop/docs/define_check_abilities.md

# check if a user is allowed to create a model (name is Article)
can? :create, Article, user: user

# or update a specific articel instance
@article = Article.find(params[:id])

can? :update, @article, user: user

Lets switch back to zensteack, i would like something like this, lets take the user policy

taken from https://zenstack.dev/docs/orm/access-control/write-policies
model User {
    id    Int    @id @default(autoincrement())
    email String @unique
    posts Post[]

    // open to signup, profiles are public
    @@allow('create,read', true)

    // the user himself has full access
    @@allow('all', auth().id == id)
}
This could be a solution?
const userDb = authDb.$setAuth(user);

// something like this? to see if a policiy is applicable, so that i could show a [create] button or whatever
userDb.user.isAllowedTo('create')

// than for a row based
userDb.user.findUnique({where: {id: auth().id}}).isAllowedTo('update')

Im searching for this isAllowedTo or in CanCanCan the can? method.

Describe alternatives you've considered
No ive got my Ai going over all my policies and it writes a permission.ts and this a horrible developmentflow.

Dominant language
TypeScript
Stars
2.9k
Forks
157
Avg merge
11h 42m
Merged PRs (30d)
20

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from zenstackhq/zenstack

All issues in zenstackhq/zenstack

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.