Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions doc/api/permissions.md
Original file line number Diff line number Diff line change
Expand Up @@ -160,8 +160,9 @@ Audit mode is useful for discovering what permissions your application
requires before deploying with [`--permission`][]. It can also be combined
with the [`--allow-fs-read`][], [`--allow-fs-write`][], [`--allow-net`][],
[`--allow-env`][], [`--allow-child-process`][], [`--allow-worker`][],
[`--allow-addons`][], [`--allow-wasi`][], and [`--allow-ffi`][] flags to audit
a subset of permissions while granting others.
[`--allow-addons`][], [`--allow-wasi`][], [`--allow-ffi`][],
[`--allow-inspector`][], and [`--allow-openssl-store`][] flags to audit a subset
of permissions while granting others.

When a permission check fails in audit mode, a message is published to the
diagnostics channel corresponding to the denied scope. The channel names are:
Expand All @@ -174,13 +175,16 @@ diagnostics channel corresponding to the denied scope. The channel names are:
* `node:permission-model:wasi` — WASI
* `node:permission-model:addon` — Native Addons
* `node:permission-model:ffi` — FFI
* `node:permission-model:openssl-store` — OpenSSL STORE loaders
* `node:permission-model:env` — Environment variables

Each message is an object with the following properties:

* `permission` {string} The name of the denied permission scope.
* `resource` {string} The resource that access was denied to (e.g. a file path
or host).
* `drop` {boolean|undefined} `true` when the message was published by
[`permission.drop()`][] rather than by a failed permission check.

```js
const diagnostics_channel = require('node:diagnostics_channel');
Expand Down Expand Up @@ -535,6 +539,7 @@ Developers relying on --permission to sandbox untrusted code should be aware tha
[`--allow-ffi`]: cli.md#--allow-ffi
[`--allow-fs-read`]: cli.md#--allow-fs-read
[`--allow-fs-write`]: cli.md#--allow-fs-write
[`--allow-inspector`]: cli.md#--allow-inspector
[`--allow-net`]: cli.md#--allow-net
[`--allow-openssl-store`]: cli.md#--allow-openssl-store
[`--allow-wasi`]: cli.md#--allow-wasi
Expand Down
Loading