Priority and Overrides
Problem
Suspend a user without removing their broader staff role or rewriting every staff rule.
Solution
Add a more specific deny rule with a higher priority than the normal staff allow rule.
ts
import { createWard } from '@vielzeug/ward';
const ward = createWard([
{ role: 'staff', resource: 'posts', action: 'read', effect: 'allow', priority: 10 },
{ role: 'suspended', resource: 'posts', action: 'read', effect: 'deny', priority: 100 },
]);
ward.explain({ principal: { id: 'u1', roles: ['staff', 'suspended'] }, resource: 'posts', action: 'read' }).allowed; // false
ward.explain({ principal: { id: 'u2', roles: ['staff'] }, resource: 'posts', action: 'read' }).allowed; // truePitfalls
- Higher priority wins before effect; deny only breaks otherwise equal precedence.
- Keep priority values intentional and documented rather than relying on declaration order.