For example: when I query a list of Contacts, I wo...
# prisma-whats-new
a
For example: when I query a list of Contacts, I would like to include in my query result if the current user has permission to create, so I know if the 'add' button in my frontend should be enabled/disabled
n
@agartha that's only possible if that information is also stored in your data. How is your permission setup in that regard, who can create contacts in general?
a
So there's no way to retrieve 'effective permissions' for a User on a Type based on the permission queries you have set up for that Type. The logic can be quite complex, and I don't feel like recreating that logic on the client.
n
other than executing the respective operation, there's not a direct way for that, no
That's a great idea though, could you please create a new feature request? https://github.com/graphcool/feature-requests
a
I will. A simple example: I have a permission query setup that does not allow editing a Post if it has Comments. The permission query is easy enough, but enabling/disabling the edit button for a Post based on these rules would require duplicating that logic on the client. The server should be 'in charge' of business logic, so that would mean setting up a webtask for it. Being able to get the result of the permission query { permissions: { update: false } } in the initial query would be great.
I'll think about how to capture this in a feature request...
n
@agartha thinking more about this, the permission system is extremely flexible, so you can't just ask if a user is able to update a node; you would need to ask if a user is able to execute a very specific mutation, right? because with the permission query system, you can allow/disallow a mutation based on the value of a certain field, or exclude/include fields for that permission
a
I think this needs more thought, I can imagine, for forms editing purposes, that it should be nice to do a tryCreate or tryUpdate, that actually goes through the permission queries, without persisting. This could be triggered in the onEdit event of a form field for example, and act almost like a validation system (actually, tryCreate/Update could call both permission queries and transform_argument event handlers). For checking if you are allowed to create a new item, without actually creating the item, you are right that you can't run any permission queries that depend on the field values of the instance you're trying to create. Maybe you can make a distinction between instance-dependant permission queries (result depends on field values of the instance itself) and non-instance-specific permission queries. The latter can be run before you know the actual instance. This is something that needs some careful thought. I'll try to come up with a viable solution in my feature request, but there's a good chance I'll leave some open ends for you guys to figure out 🙂
I tried my best: https://github.com/graphcool/feature-requests/issues/231. Good luck 🙂