# FBasePermission

- Human documentation: [https://docs.univer.ai/reference/facade/base-permission](https://docs.univer.ai/reference/facade/base-permission)

- Agent Markdown: [https://docs.univer.ai/reference/facade/base-permission.md](https://docs.univer.ai/reference/facade/base-permission.md)

- Requested language: `en-US`

- Content language: `en-US`

- Documentation version: `1.0.0-rc.0`

- Source: [facade/base-permission.mdx](https://github.com/dream-num/documentation/blob/dev/content/reference/facade/base-permission.mdx)

---

Command-backed permissions for one Base unit.

## Access

Access through:

* [`FBase.getPermission()`](https://docs.univer.ai/reference/facade/base.md#getpermission)

## Setup

Register [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) or a preset that includes it. In plugin mode, import `@univerjs-pro/bases/facade`. Additional methods below require their listed plugin packages. See [Facade setup](https://docs.univer.ai/guides/bases/getting-started/facade.md).

## `@univerjs-pro/bases`

### `FBasePermission.canEdit`

Returns whether the whole Base is currently editable.

```typescript
canEdit(): boolean
```

**Returns**

Whether Base editing is allowed.

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)

### `FBasePermission.getPoint`

Returns the current value of one Base unit permission.

```typescript
getPoint(action: BaseUnitPermissionAction): boolean
```

**Parameters**

* `action` — Required. Unit permission action to query.

**Returns**

Whether the action is currently allowed.

**Examples**

```ts
import { UnitAction } from '@univerjs/protocol'

const base = univerAPI.getActiveBase()
const canExport = base?.getPermission().getPoint(UnitAction.Export) ?? false
console.log(canExport)
```

**Types:** [`BaseUnitPermissionAction`](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/services/base-permission-point.d.ts)

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)

### `FBasePermission.setEditable`

Enables or disables editing for the whole Base.

```typescript
setEditable(editable?: boolean): Promise<void>
```

**Parameters**

* `editable` — Optional. Default: `true`. Whether editing is allowed. Defaults to true.

**Returns**

Resolves after the permission command finishes.

**Examples**

```ts
const base = univerAPI.getActiveBase()
if (!base) throw new Error('No active Base.')
await base.getPermission().setEditable()
```

**Types:** [`Promise`](https://unpkg.com/@typescript/typescript-darwin-arm64@7.0.2/lib/lib.es5.d.ts)

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)

### `FBasePermission.setObjectPermissions`

Creates or updates child-object edit policies in this unit; policy: null removes protection and restores inheritance.

Requires Authz support and objectPermissionTypes configured for every target type. File and parent restrictions
still apply. Use the exported permission object ID helpers, not raw object IDs or server permission IDs.
The batch must be nonempty, contain distinct objects, and belong to this unit; file-wide policies are excluded.
Other targets use getBaseFieldPermissionObjectId, getBaseRecordPermissionObjectId, getBaseViewPermissionObjectId, and getBaseDashboardPermissionObjectId.

edit: 'all' allows Unit editors, 'owner' restricts editing to the object owner, and 'members' selects existing
Unit collaborators. Pass their collaborator records from the member service; this does not invite new users.
Use strategies: \[] for the default Edit strategy; child-object strategies support only UnitAction.Edit.

Authz writes execute per object and can partially succeed. Inspect failed before retrying only those objects.
refreshError means writes finished but permission readback failed; do not retry succeeded objects for that error.
Successful binding changes share one undo entry; existing remote policy edits are not undoable.

```typescript
setObjectPermissions(changes: IObjectPermissionChange[]): Promise<IObjectPermissionBatchResult>
```

**Parameters**

* `changes` — Required. Permission object IDs and policies to apply.

**Returns**

Successful object IDs, per-object failures, and optional readback error.

**Throws**

Invalid batches or unsupported object types are rejected before Authz writes.

**Examples**

Set owner/member editing and remove protection in one batch

```ts
import type { ICollaborator } from '@univerjs/protocol'
import { getBaseTablePermissionObjectId } from '@univerjs-pro/bases'

// selectedMembers comes from the existing Unit collaborator picker/service.
async function applyPermissions(selectedMembers: ICollaborator[]) {
  if (!selectedMembers.length) throw new Error('Select at least one Unit collaborator.')
  const base = univerAPI.getActiveBase()
  if (!base) throw new Error('No active base.')
  const objectIds = base
    .getTables()
    .slice(0, 3)
    .map((table) => getBaseTablePermissionObjectId(table.getId()))
  if (objectIds.length < 3) throw new Error('This example requires three tables.')
  const result = await base.getPermission().setObjectPermissions([
    { objectId: objectIds[0], policy: { edit: 'owner', collaborators: [], strategies: [] } },
    {
      objectId: objectIds[1],
      policy: { edit: 'members', collaborators: selectedMembers, strategies: [] },
    },
    { objectId: objectIds[2], policy: null },
  ])
  // A policy creates protection if absent, or updates the existing policy when already configured.
  for (const failure of result.failed) {
    console.error(failure.objectId, failure.error)
  }
  if (result.refreshError) {
    console.error(result.refreshError)
  }
  return result
}
```

**Types:** [`IObjectPermissionBatchResult`](https://unpkg.com/@univerjs/core@1.0.0-rc.0/lib/types/services/permission/object-permission.service.d.ts) · [`Promise`](https://unpkg.com/@typescript/typescript-darwin-arm64@7.0.2/lib/lib.es5.d.ts) · [`IObjectPermissionChange`](https://unpkg.com/@univerjs/core@1.0.0-rc.0/lib/types/services/permission/object-permission.service.d.ts)

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)

### `FBasePermission.setPoint`

Sets one Base unit permission through the command system.

Supported actions are Edit, Copy, Export, and Comment. Await the returned promise before
reading the new value or performing an action that depends on it.

```typescript
setPoint(action: BaseUnitPermissionAction, value: boolean): Promise<void>
```

**Parameters**

* `action` — Required. Unit permission action to update.
* `value` — Required. Whether the action is allowed.

**Returns**

Resolves after the permission command finishes.

**Examples**

Disable copying while keeping the Base editable

```ts
import { UnitAction } from '@univerjs/protocol'

const base = univerAPI.getActiveBase()
if (!base) throw new Error('No active Base.')
await base.getPermission().setPoint(UnitAction.Copy, false)
```

**Types:** [`Promise`](https://unpkg.com/@typescript/typescript-darwin-arm64@7.0.2/lib/lib.es5.d.ts) · [`BaseUnitPermissionAction`](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/services/base-permission-point.d.ts)

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)

### `FBasePermission.setReadOnly`

Makes the whole Base read-only.

```typescript
setReadOnly(): Promise<void>
```

**Returns**

Resolves after the permission command finishes.

**Examples**

```ts
const base = univerAPI.getActiveBase()
if (!base) throw new Error('No active Base.')
await base.getPermission().setReadOnly()
```

**Types:** [`Promise`](https://unpkg.com/@typescript/typescript-darwin-arm64@7.0.2/lib/lib.es5.d.ts)

**Package:** [`@univerjs-pro/bases`](https://docs.univer.ai/reference/packages/plugins/univerjs-pro/bases.md) · [Type definitions](https://unpkg.com/@univerjs-pro/bases@1.0.0-rc.0/lib/types/facade/f-base-permission.d.ts)
