usePermissions
Role-based access control with actions, subjects, and context-aware conditions.
Installation
Install the Permissions plugin in your app’s entry point:
import { createApp } from 'vue'
import { createPermissionsPlugin } from '@vuetify/v0'
import App from './App.vue'
const app = createApp(App)
app.use(
createPermissionsPlugin({
permissions: {
admin: [
[['read', 'write'], 'user', true],
[['read', 'write'], 'post', true],
['delete', ['user', 'post'], true],
],
editor: [
[['read', 'write'], 'post', true],
['read', 'user', true],
['delete', 'post', (context) => context.isOwner],
],
viewer: [
['read', ['user', 'post'], true],
],
},
})
)
app.mount('#app')Usage
Once the plugin is installed, check permissions for specific roles in any component:
<script setup lang="ts">
import { usePermissions } from '@vuetify/v0'
const permissions = usePermissions()
const currentUser = { role: 'editor', id: 'user123' }
</script>
<template>
<div>
<button v-if="permissions.can('admin', 'delete', 'user')">
Delete User (Admin Only)
</button>
<button v-if="permissions.can('editor', 'write', 'post')">
Edit Post
</button>
<button
v-if="permissions.can('editor', 'delete', 'post', { isOwner: true })"
>
Delete Own Post
</button>
</div>
</template>Optionally register permissions at runtime:
<script setup lang="ts">
import { usePermissions } from '@vuetify/v0'
const permissions = usePermissions()
// Register permission at runtime
permissions.register({
id: 'moderator.ban.user',
value: (context) => context.userLevel < 3
})
// Check the permission
const canBan = permissions.can('moderator', 'ban', 'user', { userLevel: 2 })
</script>Adapters
Adapters let you swap the underlying permission resolution strategy without changing your application code.
| Adapter | Import | Description |
|---|---|---|
V0PermissionsAdapter | @vuetify/v0/permissions/adapters/v0 | Token-based permission lookup (default) |
Custom Adapters
Extend the PermissionsAdapter abstract class to integrate any backend authorization system:
import { PermissionsAdapter } from '@vuetify/v0/permissions/adapters'
import type { PermissionContext, PermissionTicket } from '@vuetify/v0'
import type { ID } from '@vuetify/v0'
class MyPermissionsAdapter extends PermissionsAdapter {
can<Z extends PermissionTicket>(
role: ID,
action: string,
subject: string,
context: Record<string, any>,
permissions: PermissionContext<Z>,
): boolean {
// Delegate to your auth system
return myAuthClient.check(String(role), `${action}:${subject}`, context)
}
}
// Use with plugin
app.use(
createPermissionsPlugin({
adapter: new MyPermissionsAdapter(),
})
)Architecture
usePermissions uses createTokens for permission flattening and lookup:
Reactivity
Permissions are stored in a token registry. There are no reactive properties — all interactions are through lookup methods (can(), get(), has()).
Using with reactive state Wrap can() in a computed to react to permission changes:
const canEdit = computed(() => permissions.can(user.role, 'edit', 'post'))Examples
Quarterly report
Draft document actions
Publish is gated by ownership for editors. Toggle the owner switch to watch the context-aware condition re-evaluate without changing the role definition.
FAQ
usePermissions answers “can this role perform this action on this subject?” — role-based, with optional context conditions. useFeatures toggles capabilities on or off regardless of role. Use permissions for access control, flags for rollout and experiments.
Make the condition a function instead of true: ['delete', 'post', context => context.isOwner]. Supply the context as the fourth argument to can() — can('editor', 'delete', 'post', { isOwner: true }) — and it re-evaluates on each check.
can() is a plain lookup, not a reactive property. Wrap it in a computed — computed(() => permissions.can(user.role, 'edit', 'post')) — so it re-evaluates when its reactive dependencies change.
Pass arrays inside the permission tuple — [['read', 'write'], 'post', true] grants both actions, and ['delete', ['user', 'post'], true] covers both subjects. The third element is the grant: true, or a context function for ABAC.
Yes. Extend PermissionsAdapter and implement can() to delegate to your auth system, then pass it as the adapter option to createPermissionsPlugin. The default V0PermissionsAdapter does token-based lookup against the static rule map.