
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
permission-core
Advanced tools
Fine-grained RBAC and resource permission core for Node.js, with route permissions, data scopes, role inheritance, and wildcard matching.
Documentation | Quick Start | Examples | Changelog
permission-core is a tenant-aware authorization core for Node.js. It persists RBAC state through the host's MonSQLize 3.1 instance and uses one action + resource model for routes, menus, backend APIs, database rows, and fields.
npm install permission-core monsqlize@3.1.0
The root and permission-core/match entries support Node.js >=18.0.0. The optional permission-core/plugins/vext entry inherits Vext 0.3.26's stricter Node.js >=20.19.0 requirement.
import MonSQLize from 'monsqlize';
import { PermissionCore } from 'permission-core';
const msq = new MonSQLize({
type: 'mongodb',
databaseName: 'app',
config: { uri: 'mongodb://127.0.0.1:27017' },
});
await msq.connect();
const pc = new PermissionCore({ monsqlize: msq });
await pc.init();
const scope = { tenantId: 'acme' };
const scoped = pc.scope(scope, {
actorId: 'quick-start',
requestId: 'req-quick-start',
});
await scoped.roles.create({ id: 'order-reader', label: 'Order reader' });
await scoped.roles.allow('order-reader', {
action: 'invoke',
resource: 'api:GET:/api/orders',
});
await scoped.userRoles.assign('u-1', 'order-reader');
const subject = pc.forSubject({ userId: 'u-1', scope });
console.log(await subject.can('invoke', 'api:GET:/api/orders')); // true
console.log(await subject.cannot('invoke', 'api:DELETE:/api/orders')); // true
await pc.close();
await msq.close();
cannot(...) is the logical negation of can(...); the DELETE result is true because no allow rule exists, not because a blocked permission was assigned.
pc.scope(scope, defaults) binds trusted management context once. With actorId/requestId defaults present, ordinary writes reuse the same audit context and derive their own idempotency keys; hand-written idempotencyKey values are only for advanced gateway or queue integrations.
permission-core/plugins/vext for hosts on Node.js >=20.19.0The application owns authentication, trusted subject construction, the MonSQLize connection, business data, HTTP serialization, and operational policy. permission-core owns authorization state and decisions. It does not implement login, expose a generic database adapter layer, or close the host database connection.
npm run example:basic
npm run example:multi-tenant
npm run example:data-guard
npm run example:menu-admin
npm run example:vext
Run all five with npm run example:all. Each emits stable JSON and uses an in-memory Mongo replica set only as a repository fixture; production applications pass their existing connected MonSQLize 3.1 instance.
Repository validation and release commands are documented separately in CONTRIBUTING.md. Security reports follow SECURITY.md.
FAQs
Fine-grained RBAC and resource permission core for Node.js, with route permissions, data scopes, role inheritance, and wildcard matching.
We found that permission-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.