/** Whether the reader may change a record, from the `permission` its read * carried. The levels are services/access.py's PERMISSION_RANK — viewer, * editor, admin, owner — and absent means the reader owns it: the server * labels a record only when it reached the reader through a share. This only * decides which controls a page shows; the server enforces the write. Kept in * one place so every page agrees, with each other and with the server, about * who can edit. */ export const WRITE_LEVELS: readonly string[] = ["editor", "admin", "owner"]; export function canWriteRecord(permission: string | undefined): boolean { return permission === undefined || WRITE_LEVELS.includes(permission); }