pub enum PolicyDecision {
Permit,
Deny {
reason: String,
},
Malformed {
reason: String,
},
}Expand description
The answer.
Not a Result, on purpose: there is no error case. See the module docs on
why a policy layer that can fail open is not a policy layer.
Variants§
Permit
Deny
Refused, with a reason an operator can act on.
The reason is required. “Denied by policy” sends someone to read a policy set looking for which of forty rules fired, which is how an authorization layer becomes something people route around.
Malformed
The rules could not be evaluated, so nothing may be concluded from them — refused, but not by a rule.
A separate variant because the rules say no and the rules are
broken call for opposite responses, and while both were spelled
Deny the difference existed only inside a reason string. Nothing
could branch on it without matching on message text, which is how a
reworded sentence changes behaviour — so a deployment whose policy set
had begun erroring on every request read it as ordinary refusals and
spent an afternoon looking for the rule that fired.
It is still a refusal at the gate: an unevaluable rule may be exactly
the forbid that would have stopped this call. What changes is who is
told and what they are told to fix — the policy set, not the request.
Implementations§
Source§impl PolicyDecision
impl PolicyDecision
Sourcepub fn malformed(reason: impl Into<String>) -> Self
pub fn malformed(reason: impl Into<String>) -> Self
Refuse because the rules themselves could not be evaluated.
pub const fn is_permit(&self) -> bool
Sourcepub const fn is_malformed(&self) -> bool
pub const fn is_malformed(&self) -> bool
Whether this refusal is a defect in the rules rather than a rule firing. The distinction a boot-time check reads, and the one an operator’s alerting should treat as an incident.
Trait Implementations§
Source§impl Clone for PolicyDecision
impl Clone for PolicyDecision
Source§fn clone(&self) -> PolicyDecision
fn clone(&self) -> PolicyDecision
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for PolicyDecision
impl Debug for PolicyDecision
Source§impl<'de> Deserialize<'de> for PolicyDecision
impl<'de> Deserialize<'de> for PolicyDecision
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for PolicyDecision
Source§impl PartialEq for PolicyDecision
impl PartialEq for PolicyDecision
Source§impl Serialize for PolicyDecision
impl Serialize for PolicyDecision
impl StructuralPartialEq for PolicyDecision
Auto Trait Implementations§
impl Freeze for PolicyDecision
impl RefUnwindSafe for PolicyDecision
impl Send for PolicyDecision
impl Sync for PolicyDecision
impl Unpin for PolicyDecision
impl UnsafeUnpin for PolicyDecision
impl UnwindSafe for PolicyDecision
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more