@@ -41,7 +41,7 @@ import { loadKnowledgeConfig } from "@corbits/knowledge-engine/config";
4141// `app` is your Interchange createApp (Hono<TenantEnv>). Pass the same grant
4242// store + condition registry you give createApp/createRequireGrant.
4343mountKnowledgeEngine (app , {
44- config: loadKnowledgeConfig (), // or build the object yourself
44+ config: loadKnowledgeConfig (), // or build the object yourself
4545 grants: { grantStore , conditionRegistry },
4646});
4747```
@@ -72,19 +72,11 @@ import {
7272 loadKnowledgeConfig ,
7373} from " @corbits/knowledge-engine" ;
7474
75- const knowledge = createKnowledgePlane (loadKnowledgeConfig (), {
76- grantStore ,
77- conditionRegistry ,
78- });
75+ const knowledge = createKnowledgePlane (loadKnowledgeConfig ());
7976await knowledge .capture ({ tenantId , principalId , title , text });
8077await knowledge .close ();
8178```
8279
83- The grant config is required so the plane can evaluate capabilities on the paths
84- that check them — ` ask() ` does its own ` knowledge:search ` check internally,
85- precisely because an in-process caller never passes through the ` requireGrant `
86- route guard.
87-
8880` capture() ` and ` search() ` do ** not** check the capability grant. They apply
8981per-document visibility and block lists, which is not the same question. So if
9082the caller is acting on behalf of a user rather than as an operator, check it
@@ -104,8 +96,6 @@ const decision = await authorize(
10496if (decision .effect !== " allow" ) throw new Error (" not permitted" );
10597```
10698
107- Or just use ` ask() ` , which cannot be called without that check happening.
108-
10999Apply the knowledge/vector schema once (idempotent):
110100
111101``` ts
0 commit comments