pub struct StandingAuthority {
pub id: AuthorityId,
pub holder: Holder,
pub basis: String,
pub ceiling: Spend,
pub max_draws: Option<u32>,
pub expires_at: Option<Timestamp>,
}Expand description
What somebody authorized, and how far it goes.
Issued once and thereafter immutable: the ceiling a person agreed to must not be editable under them, or the record of what they agreed to is worth nothing. Changing a ceiling means revoking this authority and issuing another, which leaves both on the record.
Fields§
§id: AuthorityId§holder: HolderOn whose behalf it may be drawn: the principal a run must act for.
A run acting under a delegation chain holds as the chain’s owner,
the person it descends from; a run the plane started for itself with
no chain holds as its tenant; a served caller that presented no chain
holds nothing — see holder_of. Without it, knowing an id would be
enough: any run in the tenant could spend a mandate somebody else
signed, and an id a peer supplied could name one.
basis: StringWhy this exists, in the issuer’s terms — an approval reference, a mandate id, a ticket.
Required, and required to be non-empty. An authority with no stated basis is a ceiling nobody can trace to a decision, which is the thing an audit asks for first.
ceiling: SpendThe total this authority is good for, across every draw.
max_draws: Option<u32>How many draws it permits, if the issuer bounded that too.
Separate from the ceiling because they bound different abuses: a spend ceiling stops one large wrong charge, a draw count stops a thousand small ones that never reach it.
expires_at: Option<Timestamp>When it stops being drawable, if it expires.
Evaluated against the run’s journaled clock, never an ambient one, so a replay reaches the same verdict as the live run did.
Implementations§
Source§impl StandingAuthority
impl StandingAuthority
Sourcepub fn new(
id: impl Into<String>,
holder: Holder,
basis: impl Into<String>,
ceiling: Spend,
) -> Self
pub fn new( id: impl Into<String>, holder: Holder, basis: impl Into<String>, ceiling: Spend, ) -> Self
Issue an authority for ceiling to holder, stating why it exists.
Sourcepub const fn expires_at(self, at: Timestamp) -> Self
pub const fn expires_at(self, at: Timestamp) -> Self
Stop it being drawable after at.
Sourcepub fn validate(&self) -> Result<(), AuthorityError>
pub fn validate(&self) -> Result<(), AuthorityError>
Whether the declaration is well formed.
§Errors
AuthorityError::Malformed for an empty id, holder or basis, or a ceiling of
nothing. A zero ceiling is refused rather than treated as unlimited: the
two readings are opposite, and a format that guesses between them is one
whose meaning changes under you.
Trait Implementations§
Source§impl Clone for StandingAuthority
impl Clone for StandingAuthority
Source§impl Debug for StandingAuthority
impl Debug for StandingAuthority
Source§impl<'de> Deserialize<'de> for StandingAuthority
impl<'de> Deserialize<'de> for StandingAuthority
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for StandingAuthority
Source§impl PartialEq for StandingAuthority
impl PartialEq for StandingAuthority
Source§impl Serialize for StandingAuthority
impl Serialize for StandingAuthority
impl StructuralPartialEq for StandingAuthority
Auto Trait Implementations§
impl Freeze for StandingAuthority
impl RefUnwindSafe for StandingAuthority
impl Send for StandingAuthority
impl Sync for StandingAuthority
impl Unpin for StandingAuthority
impl UnsafeUnpin for StandingAuthority
impl UnwindSafe for StandingAuthority
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more