// lib/rbac.js export function can(user, perm) { const set = new Set(user?.permissions || []); return set.has(perm); } export function inRole(user, ...roles) { return roles.includes(user?.role); }