diff --git a/doc/api/permissions.md b/doc/api/permissions.md index 27acf9d4c69..79cc2679fbf 100644 --- a/doc/api/permissions.md +++ b/doc/api/permissions.md @@ -160,8 +160,9 @@ Audit mode is useful for discovering what permissions your application requires before deploying with [`--permission`][]. It can also be combined with the [`--allow-fs-read`][], [`--allow-fs-write`][], [`--allow-net`][], [`--allow-env`][], [`--allow-child-process`][], [`--allow-worker`][], -[`--allow-addons`][], [`--allow-wasi`][], and [`--allow-ffi`][] flags to audit -a subset of permissions while granting others. +[`--allow-addons`][], [`--allow-wasi`][], [`--allow-ffi`][], +[`--allow-inspector`][], and [`--allow-openssl-store`][] flags to audit a subset +of permissions while granting others. When a permission check fails in audit mode, a message is published to the diagnostics channel corresponding to the denied scope. The channel names are: @@ -174,6 +175,7 @@ diagnostics channel corresponding to the denied scope. The channel names are: * `node:permission-model:wasi` — WASI * `node:permission-model:addon` — Native Addons * `node:permission-model:ffi` — FFI +* `node:permission-model:openssl-store` — OpenSSL STORE loaders * `node:permission-model:env` — Environment variables Each message is an object with the following properties: @@ -181,6 +183,8 @@ Each message is an object with the following properties: * `permission` {string} The name of the denied permission scope. * `resource` {string} The resource that access was denied to (e.g. a file path or host). +* `drop` {boolean|undefined} `true` when the message was published by + [`permission.drop()`][] rather than by a failed permission check. ```js const diagnostics_channel = require('node:diagnostics_channel'); @@ -535,6 +539,7 @@ Developers relying on --permission to sandbox untrusted code should be aware tha [`--allow-ffi`]: cli.md#--allow-ffi [`--allow-fs-read`]: cli.md#--allow-fs-read [`--allow-fs-write`]: cli.md#--allow-fs-write +[`--allow-inspector`]: cli.md#--allow-inspector [`--allow-net`]: cli.md#--allow-net [`--allow-openssl-store`]: cli.md#--allow-openssl-store [`--allow-wasi`]: cli.md#--allow-wasi