// the find
WebDevSimplified/permission-system
A companion repo to a WebDevSimplified YouTube video showing how to hand-roll role-based and attribute-based access control in TypeScript. It's two files, not a library — meant to be read and copied, not installed.
The ABAC implementation uses a genuinely nice pattern: permissions as functions that take (user, data) and return a boolean, composed via a typed rules object, so you get autocomplete on both resource and action. Zero dependencies, so there's nothing to audit or version-pin. Short enough to read end-to-end in five minutes, which is the point.
No tests, no npm package, no README explaining the tradeoffs between the RBAC and ABAC files — you have to already know what you're looking for. It's a teaching snippet, not something you can npm install and extend; anyone adopting the pattern has to hand-port it into their own codebase and add the missing pieces (role hierarchies, permission caching, DB-backed rules) themselves. Last pushed October 2024 and stayed at two files, so it's not a maintained project, just a frozen example.