Skip to content
Open
14 changes: 8 additions & 6 deletions docs/access-control/collections.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ export const CollectionWithAccessControl: CollectionConfig = {
read: () => {...},
update: () => {...},
delete: () => {...},
validate: () => {...},

// Auth-enabled Collections only
admin: () => {...},
Expand All @@ -53,12 +54,13 @@ export const CollectionWithAccessControl: CollectionConfig = {

The following options are available:

| Function | Allows/Denies Access |
| ------------ | -------------------------------------------------------------------- |
| **`create`** | Used in the `create` operation. [More details](#create). |
| **`read`** | Used in the `find` and `findByID` operations. [More details](#read). |
| **`update`** | Used in the `update` operation. [More details](#update). |
| **`delete`** | Used in the `delete` operation. [More details](#delete). |
| Function | Allows/Denies Access |
| -------------- | ----------------------------------------------------------------------------------------------------------------- |
| **`create`** | Used in the `create` operation. [More details](#create). |
| **`read`** | Used in the `find` and `findByID` operations. [More details](#read). |
| **`update`** | Used in the `update` operation. [More details](#update). |
| **`delete`** | Used in the `delete` operation. [More details](#delete). |
| **`validate`** | Optionally overrides `update` access for [on-demand validation](../validation/overview#access-control-and-hooks). |

If a Collection supports [`Authentication`](../authentication/overview), the following additional options are available:

Expand Down
12 changes: 7 additions & 5 deletions docs/access-control/fields.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ export const Posts: CollectionConfig = {
create: ({ req: { user } }) => { ... },
read: ({ req: { user } }) => { ... },
update: ({ req: { user } }) => { ... },
validate: ({ req: { user } }) => { ... },
},
// highlight-end
};
Expand All @@ -57,11 +58,12 @@ export const Posts: CollectionConfig = {

The following options are available:

| Function | Purpose |
| ------------ | ---------------------------------------------------------------------------------------------------------- |
| **`create`** | Allows or denies the ability to set a field's value when creating a new document. [More details](#create). |
| **`read`** | Allows or denies the ability to read a field's value. [More details](#read). |
| **`update`** | Allows or denies the ability to update a field's value [More details](#update). |
| Function | Purpose |
| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| **`create`** | Allows or denies the ability to set a field's value when creating a new document. [More details](#create). |
| **`read`** | Allows or denies the ability to read a field's value. [More details](#read). |
| **`update`** | Allows or denies the ability to update a field's value. [More details](#update). |
| **`validate`** | Optionally overrides `update` access for candidate field data during [on-demand validation](../validation/overview#access-control-and-hooks). |

### Create

Expand Down
10 changes: 6 additions & 4 deletions docs/access-control/globals.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ const GlobalWithAccessControl: GlobalConfig = {
access: {
read: ({ req: { user } }) => {...},
update: ({ req: { user } }) => {...},
validate: ({ req: { user } }) => {...},

// Version-enabled Globals only
readVersions: () => {...},
Expand All @@ -49,10 +50,11 @@ export default Header

The following options are available:

| Function | Allows/Denies Access |
| ------------ | --------------------------------------------------------------- |
| **`read`** | Used in the `findOne` Global operation. [More details](#read). |
| **`update`** | Used in the `update` Global operation. [More details](#update). |
| Function | Allows/Denies Access |
| -------------- | ----------------------------------------------------------------------------------------------------------------- |
| **`read`** | Used in the `findOne` Global operation. [More details](#read). |
| **`update`** | Used in the `update` Global operation. [More details](#update). |
| **`validate`** | Optionally overrides `update` access for [on-demand validation](../validation/overview#access-control-and-hooks). |

If a Global supports [Versions](../versions/overview), the following additional options are available:

Expand Down
10 changes: 7 additions & 3 deletions docs/access-control/overview.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,10 @@ Access Control determines what a user can and cannot do with any given Document,

Access Control functions are scoped to the _operation_, meaning you can have different rules for `create`, `read`, `update`, `delete`, etc. Access Control functions are executed _before_ any changes are made and _before_ any operations are completed. This allows you to determine if the user has the necessary permissions before fulfilling the request.

[On-demand validation](../validation/overview#access-control-and-hooks) uses its own first-class
`validate` operation for collection, global, and field access control. Its access policy falls back
to the corresponding `update` function unless `validate` is configured explicitly.

There are many use cases for Access Control, including:

- Allowing anyone `read` access to all posts
Expand Down Expand Up @@ -45,9 +49,9 @@ const defaultPayloadAccess = ({ req: { payload, user } }) => {

<Banner type="warning">
**Important:** By default, all [Local API](../local-api/overview) operations
respect Access Control based on the passed `user`. Set
`overrideAccess: true` only when the operation should entirely bypass
Access Control. See [Local API Access Control](../local-api/access-control).
respect Access Control based on the passed `user`. Set `overrideAccess: true`
only when the operation should entirely bypass Access Control. See [Local API
Access Control](../local-api/access-control).
</Banner>

## Base Access Control
Expand Down
4 changes: 3 additions & 1 deletion docs/configuration/localization.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ Localization is one of the most important features of a modern CMS. It allows yo

With Localization, you can begin to serve personalized content to your users based on their specific language preferences, such as a multilingual website or multi-site application. There are no limits to the number of locales you can add to your Payload project.

You can also [validate one or more locales without saving](../validation/overview).

To configure Localization, use the `localization` key in your [Payload Config](./overview):

```ts
Expand Down Expand Up @@ -95,7 +97,7 @@ The locale codes do not need to be in any specific format. It's up to you to def

| Option | Description |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **`code`** \* | Unique code to identify the language throughout the APIs for `locale` and `fallbackLocale` |
| **`code`** \* | Unique code to identify the language throughout the APIs for `locale` and `fallbackLocale`. |
| **`label`** | A string to use for the selector when choosing a language, or an object keyed on the i18n keys for different languages in use. |
| **`rtl`** | A boolean that when true will make the admin UI display in Right-To-Left. |
| **`fallbackLocale`** | The code for this language to fallback to when properties of a document are not present. This can be a single locale or array of locales. |
Expand Down
10 changes: 7 additions & 3 deletions docs/hooks/collections.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,9 @@ The following arguments are provided to the `beforeOperation` hook:

### beforeValidate

Runs during the `create` and `update` operations. This hook allows you to add or format data before the incoming data is validated server-side.
Runs during the `create`, `update`, and `validate` operations. This hook allows you to add or format data before the incoming data is validated server-side.

On-demand validation runs this hook with `operation: 'validate'` without saving the candidate. Use the `operation` argument to skip external calls and other side effects that should only run when data is saved.

Please do note that this does not run before client-side validation. If you render a custom field component in your front-end and provide it with a `validate` function, the order that validations will run in is:

Expand Down Expand Up @@ -133,15 +135,17 @@ The following arguments are provided to the `beforeValidate` hook:

### beforeChange

Immediately before validation, beforeChange hooks will run during create and update operations. At this stage, the data should be treated as unvalidated user input. There is no guarantee that required fields exist or that fields are in the correct format. As such, using this data for side effects requires manual validation. You can optionally modify the shape of the data to be saved.
Immediately before validation, beforeChange hooks run during `create`, `update`, and `validate` operations. At this stage, treat the data as unvalidated user input. Required fields can be missing, and fields can have an incorrect format. You can modify the data before Payload validates it.

On-demand validation runs this hook with `operation: 'validate'` but does not run `afterChange`. Use the `operation` argument to skip external calls and other side effects that should only run when data is saved.

```ts
import type { CollectionBeforeChangeHook } from 'payload'

export const requireTitleOnUpdate: CollectionBeforeChangeHook = async ({
data, // Partial<T> — changed fields only
originalDoc, // Full doc before changes (defined on update)
operation, // 'create' | 'update'
operation, // 'create' | 'update' | 'validate'
}) => {
// Need the id? Don't expect it in `data`.
const id = operation === 'update' ? originalDoc.id : undefined
Expand Down
Loading
Loading