/** * Whether a caller may act on resources belonging to `targetUserId`: either the * caller owns them, or the caller is a privileged (allow-listed) user. */ export const isOwnerOrPrivileged = ( callerUserId: number, targetUserId: number, privileged: boolean, ) => privileged || callerUserId === targetUserId;