Utix implements a simple role-based access control system to protect privileged operations and administrative endpoints.
Default role for all users. Can access all public tools and features.
Permissions:
view:tools- Access utility toolsview:dashboard- View dashboard
Administrative role for project maintainers and operators.
Permissions:
- All viewer permissions
admin:health- Access operational health dashboardadmin:recovery- Run disaster recovery validationadmin:metrics- View system metrics
Limited administrative role for automated services and monitoring systems.
Permissions:
admin:health- Access operational health dashboardadmin:metrics- View system metrics
All permission checks are enforced server-side and cannot be bypassed through UI manipulation.
import { requirePermission, getAuthContext } from '@/core/auth/middleware';
export async function adminAction() {
const context = getAuthContext();
requirePermission(context, 'admin:health');
// Privileged operation here
}For server actions and API routes, use the withPermission wrapper:
import { withPermission } from '@/core/auth/middleware';
export const protectedAction = withPermission(
'admin:recovery',
async (param: string) => {
// This code only runs if permission is granted
return performRecoveryValidation(param);
}
);Set the user role via environment variable:
UTIX_USER_ROLE=maintainerIf not set, defaults to viewer.
While security is enforced server-side, the UI can hide or disable unauthorized actions for better UX:
import { hasPermission } from '@/core/auth/types';
const canAccessAdmin = hasPermission(userRole, 'admin:health');
{canAccessAdmin && <AdminDashboardLink />}Important: UI checks are hints only. Never rely on them for security.
All permission combinations are tested in core/auth/__tests__/permissions.test.ts. Every privileged action must have corresponding permission tests.
When adding new privileged operations:
- Define the permission in
core/auth/types.ts - Add it to the appropriate role in
ROLE_PERMISSIONS - Protect the handler with
requirePermissionorwithPermission - Add test coverage for the permission check
- Update this documentation