roles.ts

Role configuration fields and template defaults.

config/roles.ts exports a Record<string, { name: LocalizedText; description: LocalizedText; capabilities: StaticCapabilityKey[] }> object with one role per key. You can define your own role keys. guest, register, premium, and admin are template examples, not fixed fields. You can add, remove, or change keys, or export an empty object if there are no roles.

The Role union type exported at the end of the file is generated from the configuration object's keys. After changing role keys, also update references in product configuration, account data, and access control code.

Role keys

Role keys are nonempty strings. They should be short, stable English identifiers such as member, operator, or admin. Put the user-facing name in name.

Role records

Each role key maps to a role record with the following format:

Prop

Type

capabilities accepts full capability keys such as user.view and group paths such as user. A group path grants the role all role-granted capabilities under that group.

Template defaults

Role keyname.valuedescription.valuecapabilities
guestGuestGuest user[]
registerRegisteredRegistered useruser, ticket
premiumPaid MemberMember with an active paid product grantuser, ticket
adminAdminAdmin useradmin, user, ticket

These records only demonstrate the role configuration format. When deleting or replacing example roles, also update products.ts and role data already stored in the database.