# Entity Policy Coverage This document provides an overview of all domain entities in the application, their policy implementations, and authorization rules. ## Coverage Summary - **Total Entities**: 14 - **With Policies**: 14 (100%) - **Extending BaseEntity**: 14 (100%) All entities have: - ✅ Extend `BaseEntity` - ✅ Have corresponding policy classes - ✅ Policies registered in their modules ## Entity Policy Table | Entity | Extends BaseEntity? | Policy Class | Location | |--------|---------------------|--------------|----------| | Application | ✅ Yes | ✅ ApplicationPolicy | | | Company | ✅ Yes | ✅ CompanyPolicy | | | CV | ✅ Yes | ✅ CVPolicy | | | CVTemplate | ✅ Yes | ✅ CVTemplatePolicy | | | Education | ✅ Yes | ✅ EducationPolicy | | | Institution | ✅ Yes | ✅ InstitutionPolicy | | | Level | ✅ Yes | ✅ LevelPolicy | | | Organization | ✅ Yes | ✅ OrganizationPolicy | | | OrganizationRole | ✅ Yes | ✅ OrganizationRolePolicy | | | Role | ✅ Yes | ✅ RolePolicy | | | Skill | ✅ Yes | ✅ SkillPolicy | | | User | ✅ Yes | ✅ UserPolicy | | | UserJobExperience | ✅ Yes | ✅ UserJobExperiencePolicy | | | Vacancy | ✅ Yes | ✅ VacancyPolicy | | ## Authorization Rules ### User-Owned Resources These entities are owned by users and follow ownership-based authorization: - **Application**: Users can only view, create, update, and delete their own applications - **Education**: Users can only view, create, update, and delete their own education records - **UserJobExperience**: Users can only view, create, update, and delete their own job experience records - **CV**: Users can only view, create, update, and delete their own CVs - **Vacancy**: Users can view public vacancies or their own vacancies; can only create, update, and delete their own vacancies - **User**: Users can only view, update, and delete their own user account ### Reference Data These entities are shared reference data with restricted modification: - **Company**: All users can view and create; update and delete are restricted - **Level**: All users can view and create; update and delete are restricted - **Role**: All users can view and create; update and delete are restricted - **Skill**: All users can view and create; update and delete are restricted - **Institution**: All users can view and create; update and delete are restricted - **CVTemplate**: All users can view; create, update, and delete are restricted ### Organization Resources These entities have membership-based authorization (to be implemented): - **Organization**: All users can view and create; update and delete require organization membership verification (TODO) - **OrganizationRole**: All users can view; create, update, and delete require organization membership verification (TODO) ## Policy Implementation All policies implement the `Policy` interface with the following methods: - `view(user: User, resource: TResource): boolean | Promise` - `create(user: User, resource?: Partial): boolean | Promise` - `update(user: User, resource: TResource): boolean | Promise` - `delete(user: User, resource: TResource): boolean | Promise` - `can(action: string, user: User, resource: TResource | Partial | undefined): boolean | Promise` Policies are automatically discovered and registered by the `PolicyRegistry` service using NestJS's `DiscoveryService`. They must: 1. Be decorated with `@Policy(EntityClass)` 2. Implement the `Policy` interface 3. Be registered as providers in their respective modules ## Adding New Entities When adding a new entity: 1. **Extend BaseEntity**: Ensure the entity extends `BaseEntity` 2. **Create Policy Class**: Create a policy class in the same module as the entity 3. **Register Policy**: Add the policy to the module's providers array 4. **Implement Authorization Rules**: Implement the policy methods according to your authorization requirements Example: ```typescript import { Injectable } from "@nestjs/common"; import { Policy, type IPolicy } from "@cv/auth"; import type { User } from "@cv/auth"; import { YourEntity } from "./your-entity.entity"; @Injectable() @Policy(YourEntity) export class YourEntityPolicy implements IPolicy { view(user: User, resource: YourEntity): boolean | Promise { // Implementation } create(user: User, resource?: Partial): boolean | Promise { // Implementation } update(user: User, resource: YourEntity): boolean | Promise { // Implementation } delete(user: User, resource: YourEntity): boolean | Promise { // Implementation } can( action: string, user: User, resource: YourEntity | Partial | undefined, ): boolean | Promise { // Implementation } } ```