| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| AccessControl v3.1.1 source code.tar.gz | 2026-09-24 | 294.2 kB | |
| AccessControl v3.1.1 source code.zip | 2026-09-24 | 348.4 kB | |
| README.md | 2026-09-24 | 958 Bytes | |
| Totals: 3 Items | 643.6 kB | 1 | |
Fixed
grant()anddeny()given anIAccessInfoobject with an explicitattributes: []now keep it, as the chain (readAny('r', [])), the grants list and the grants object always did. The object form used to turn[]into['*'], soac.grant({ role, resource, action, attributes: [] })granted every attribute instead of none, and a deny of[]denied everything. Omitted attributes still default to['*']. This dates back to 2.0.0.- The attribute notes in the chain's TSDoc and on
IAccessInfo.attributessaid a deny defaults to an empty array; since 3.0 an omitted list defaults to['*']for a deny too. They now say so, and that an explicit[]is kept.
Security
- The fix above closes a privilege-escalation shape on the object form: an empty allow-list loaded from a data store could grant full access. If you relied on
attributes: []meaning every attribute on the object form, write['*']or leave the field out.