# Entity Policy Coverage
This document provides an overview of all domain entities in the application, their policy implementations, and authorization rules.
## Coverage Summary
- **Total Entities**: 14
- **With Policies**: 14 (100%)
- **Extending BaseEntity**: 14 (100%)
All entities have:
- ✅ Extend `BaseEntity`
- ✅ Have corresponding policy classes
- ✅ Policies registered in their modules
## Entity Policy Table
| Entity | Extends BaseEntity? | Policy Class | Location |
|--------|---------------------|--------------|----------|
| Application | ✅ Yes | ✅ ApplicationPolicy | |
| Company | ✅ Yes | ✅ CompanyPolicy | |
| CV | ✅ Yes | ✅ CVPolicy | |
| CVTemplate | ✅ Yes | ✅ CVTemplatePolicy | |
| Education | ✅ Yes | ✅ EducationPolicy | |
| Institution | ✅ Yes | ✅ InstitutionPolicy | |
| Level | ✅ Yes | ✅ LevelPolicy | |
| Organization | ✅ Yes | ✅ OrganizationPolicy | |
| OrganizationRole | ✅ Yes | ✅ OrganizationRolePolicy | |
| Role | ✅ Yes | ✅ RolePolicy | |
| Skill | ✅ Yes | ✅ SkillPolicy | |
| User | ✅ Yes | ✅ UserPolicy | |
| UserJobExperience | ✅ Yes | ✅ UserJobExperiencePolicy | |
| Vacancy | ✅ Yes | ✅ VacancyPolicy | |
## Authorization Rules
### User-Owned Resources
These entities are owned by users and follow ownership-based authorization:
- **Application**: Users can only view, create, update, and delete their own applications
- **Education**: Users can only view, create, update, and delete their own education records
- **UserJobExperience**: Users can only view, create, update, and delete their own job experience records
- **CV**: Users can only view, create, update, and delete their own CVs
- **Vacancy**: Users can view public vacancies or their own vacancies; can only create, update, and delete their own vacancies
- **User**: Users can only view, update, and delete their own user account
### Reference Data
These entities are shared reference data with restricted modification:
- **Company**: All users can view and create; update and delete are restricted
- **Level**: All users can view and create; update and delete are restricted
- **Role**: All users can view and create; update and delete are restricted
- **Skill**: All users can view and create; update and delete are restricted
- **Institution**: All users can view and create; update and delete are restricted
- **CVTemplate**: All users can view; create, update, and delete are restricted
### Organization Resources
These entities have membership-based authorization (to be implemented):
- **Organization**: All users can view and create; update and delete require organization membership verification (TODO)
- **OrganizationRole**: All users can view; create, update, and delete require organization membership verification (TODO)
## Policy Implementation
All policies implement the `Policy` interface with the following methods:
- `view(user: User, resource: TResource): boolean | Promise`
- `create(user: User, resource?: Partial): boolean | Promise`
- `update(user: User, resource: TResource): boolean | Promise`
- `delete(user: User, resource: TResource): boolean | Promise`
- `can(action: string, user: User, resource: TResource | Partial | undefined): boolean | Promise`
Policies are automatically discovered and registered by the `PolicyRegistry` service using NestJS's `DiscoveryService`. They must:
1. Be decorated with `@Policy(EntityClass)`
2. Implement the `Policy` interface
3. Be registered as providers in their respective modules
## Adding New Entities
When adding a new entity:
1. **Extend BaseEntity**: Ensure the entity extends `BaseEntity`
2. **Create Policy Class**: Create a policy class in the same module as the entity
3. **Register Policy**: Add the policy to the module's providers array
4. **Implement Authorization Rules**: Implement the policy methods according to your authorization requirements
Example:
```typescript
import { Injectable } from "@nestjs/common";
import { Policy, type IPolicy } from "@cv/auth";
import type { User } from "@cv/auth";
import { YourEntity } from "./your-entity.entity";
@Injectable()
@Policy(YourEntity)
export class YourEntityPolicy implements IPolicy {
view(user: User, resource: YourEntity): boolean | Promise {
// Implementation
}
create(user: User, resource?: Partial): boolean | Promise {
// Implementation
}
update(user: User, resource: YourEntity): boolean | Promise {
// Implementation
}
delete(user: User, resource: YourEntity): boolean | Promise {
// Implementation
}
can(
action: string,
user: User,
resource: YourEntity | Partial | undefined,
): boolean | Promise {
// Implementation
}
}
```