Files
ECC/pi/core/skills/angular-developer/references/route-guards.md
T
Affaan MustafaandGitHub c70874fae9 feat(pi): curated pi/core skills+prompts profile, CI load test, and 2.2.2 release sync (#3264)
Adds a curated, Pi-native, skills+prompts-only profile at pi/core/ for downstream packagers that mirror GitHub Releases.

- manifests/pi-core.json: explicit include lists, per-item exclusion reasons, curation rules, safety allowlists; every root skill and command must be classified.
- scripts/build-pi-core.js regenerates pi/core deterministically (package.json from VERSION, LICENSE, README.md, CURATION.md, skills/, commands/); --check fails CI on drift. council is renamed ecc-council inside pi/core only.
- Safety checks: no callable endpoints outside the allowlist, no npx/curl|sh/pip install, no secrets, no absolute home paths, no symlinks, valid frontmatter, no duplicate names.
- CI: build + drift check and an offline Pi CLI load test of pi/core.
- Release: VERSION, package.json and pi/core/package.json at 2.2.2, CHANGELOG, tag-triggered release verification, and a two-week cadence in CONTRIBUTING.md.

pi/core: 123 of 293 skills and 24 of 94 commands; 35,006 characters of skill description text.
2026-09-29 20:24:05 -05:00

1.4 KiB

Route Guards

Route guards control whether a user can navigate to or leave a route.

Types of Guards

  • CanActivate: Can the user access this route? (e.g., Auth check).
  • CanActivateChild: Can the user access children of this route?
  • CanDeactivate: Can the user leave this route? (e.g., Unsaved changes).
  • CanMatch: Should this route even be considered for matching? (e.g., Feature flags). If it returns false, the router continues checking other routes.

Creating a Guard

Guards are typically functional since Angular 15.

export const authGuard: CanActivateFn = (route, state) => {
  const authService = inject(AuthService);
  const router = inject(Router);

  if (authService.isLoggedIn()) {
    return true;
  }

  // Redirect to login
  return router.parseUrl('/login');
};

Applying Guards

Add them to the route configuration as an array. They execute in order.

{
  path: 'admin',
  component: Admin,
  canActivate: [authGuard],
  canActivateChild: [adminChildGuard],
  canDeactivate: [unsavedChangesGuard]
}

Return Values

  • boolean: true to allow, false to block.
  • UrlTree or RedirectCommand: Redirect to a different route.
  • Observable or Promise: Resolves to the above types.

Security Note

Client-side guards are NOT a substitute for server-side security. Always verify permissions on the server.