{"id":"authz.roles.turbineh","compat":{"runtime":"node@>=20","framework":"next@^16.0.0"},"schema":"turbineh.component/v0.1","source":{"purl":"pkg:generic/turbineh/authz.roles.turbineh@0.1.0","repo":"https://github.com/alejandroruiz3c/code-api-turbineh"},"status":"approved","effects":{"db":false,"fs":false,"network":false,"external_services":[]},"license":{"declared":"Apache-2.0","detected":"Apache-2.0","obligations":["preserve-notice"]},"quality":{"tests":{"date":"2026-10-10","passed":true,"command":"recipe saas-crud: typecheck, lint, unit, build, e2e (sandbox, no network)"}},"version":"0.1.0","category":"authz","contract":{"errors":["see source"],"inputs":["see source"],"limits":["see source"],"outputs":["see source"]},"evidence":[{"ref":"bench/results/2026-10-10-d1-recipe-saas-crud.json","claim":"Unit tests on the role matrix; protected route redirects anonymous users (E2E)","origin":"tested"}],"security":{"scope":"First-party source reviewed; no third-party dependencies of its own.","tools":["gitleaks","review"],"findings":[],"scanned_at":"2026-10-10"},"relations":{"provides":["authz.roles"],"requires":[],"conflicts":[],"tested_with":["recipe.saas-crud"]},"capability":{"cons":["Single-instance assumptions documented in code"],"does":"Role policy (owner/admin/member) and requireMember guard used by every page and server action","pros":["Maintained by TurbineH","No third-party runtime dependency beyond the stack"],"does_not":"Does not implement fine-grained per-record permissions","use_cases":["saas-crud","landing-waitlist","internal-tool","bookings","client-portal"],"alternatives":[]},"integration":{"config":[],"install":"Included in recipe templates at src/server/authz.ts","strategy":"vendored-with-provenance","migrations":false}}