Skip to main content
Nuxt Secure uses a profile-based RBAC model. Every user belongs to exactly one profile. Each profile holds a set of permissions, one row per application module. Each permission row defines five independent boolean action flags. This means access is controlled at two levels: which module and which action within that module.

The five permission actions

The PermisosAccion interface in useAuth.ts defines the five actions that can be granted or denied per module: All flags default to false in the database. A flag must be explicitly set to true for the action to be permitted.

Data model

The permisos_perfil table stores one row per profile-module combination:

Permission loading

After a successful login, cargarMisPermisos(idPerfil) fetches the current user’s permission set from the server:
app/composables/useAuth.ts
The API endpoint returns a Record<string, PermisosAccion> where each key is the module name in uppercase (e.g. "USUARIO", "PERMISOS-PERFIL"). This object is stored in useState('misPermisos') and is available reactively across the entire app. restaurarSesion() calls cargarMisPermisos again after a hard refresh if the in-memory state is empty, so permissions survive F5.

Checking permissions at runtime

tienePermiso() is the single function used everywhere in the UI to check whether the current user can perform an action:
app/composables/useAuth.ts
If the module key is not present in misPermisos (because no permission row exists for this profile-module pair), the function returns false — deny by default.

Usage in pages

Use tienePermiso with v-if to conditionally render UI elements based on the current user’s permissions:
app/pages/seguridad/usuario.vue

Route protection

Each security page checks bitConsulta in its onMounted hook. If the user lacks view permission, they are redirected to / before the page renders:
This check is client-side only. API routes have their own server-side validation and return HTTP 401/403 for unauthorised requests regardless of the UI state.

Permissions matrix

Administrators configure permissions through the visual permissions matrix UI. Selecting a profile loads all modules as rows, each with five toggleable checkboxes. Saving posts the entire matrix to /api/permisos/guardar-matriz in a single request. If the profile being edited belongs to the currently logged-in user, cargarMisPermisos is called immediately after saving so the session reflects the changes without a logout. See Permissions matrix for the full walkthrough.

Example permissions layout

Module names in tienePermiso() are compared in uppercase, so tienePermiso('usuario', 'bitConsulta') and tienePermiso('USUARIO', 'bitConsulta') are equivalent.