pub struct NamespaceResolver { /* private fields */ }Expand description
Resolver that authorizes callers and yields namespace-scoped engine access.
Implementations§
Source§impl NamespaceResolver
impl NamespaceResolver
Sourcepub fn from_config(config: NamespaceConfig, engine: Arc<Engine>) -> Self
pub fn from_config(config: NamespaceConfig, engine: Arc<Engine>) -> Self
Build a resolver from operator-supplied namespace configuration and the engine selected for this deployment.
Sourcepub fn from_parts(
mode: NamespaceMode,
engine: Option<Arc<Engine>>,
ownership: Arc<dyn WorkflowNamespaceSource>,
schedule_ownership: Arc<dyn ScheduleNamespaceSource>,
) -> Self
pub fn from_parts( mode: NamespaceMode, engine: Option<Arc<Engine>>, ownership: Arc<dyn WorkflowNamespaceSource>, schedule_ownership: Arc<dyn ScheduleNamespaceSource>, ) -> Self
Build a resolver from explicit parts for tests and alternate wiring.
Build a resolver that performs authorization and ownership checks only.
This constructor is intended for adapter-boundary unit tests that must prove denied operations do not reach any engine handle.
Sourcepub const fn mode(&self) -> &NamespaceMode
pub const fn mode(&self) -> &NamespaceMode
Inspect the configured namespace mode.
Sourcepub fn shutdown_engine(&self) -> Result<(), ServerError>
pub fn shutdown_engine(&self) -> Result<(), ServerError>
Shut down the engine owned by this resolver.
§Errors
Returns ServerError::Config when no engine is attached, or ServerError::EngineCall
when the engine rejects shutdown.
Sourcepub async fn verify_workflow_ownership(
&self,
namespace: &str,
workflow_id: &WorkflowId,
) -> Result<(), ServerError>
pub async fn verify_workflow_ownership( &self, namespace: &str, workflow_id: &WorkflowId, ) -> Result<(), ServerError>
Verify durable workflow ownership against the requested namespace.
NamespaceDenied means exactly one thing: the caller has no grant for
the requested namespace, and that is decided by Self::resolve before
this check runs. Workflow-level visibility misses are NotFound to
prevent existence leaks: when the caller’s requested namespace is
granted but the workflow’s recorded owner namespace is absent (unknown
workflow, or no recorded attribute) or different (owned by another
tenant), both cases return the identical not_found wire error with
the identical message, so a cross-tenant probe is byte-for-byte
indistinguishable from querying a workflow that never existed.
§Errors
Returns a ServerError::Wire not_found error when the workflow is
not visible in the requested namespace; ownership-source read failures
surface as their own typed errors.
Sourcepub async fn workflow_attribution(
&self,
namespace: &str,
workflow_id: &WorkflowId,
) -> Result<Option<WorkflowAttribution>, ServerError>
pub async fn workflow_attribution( &self, namespace: &str, workflow_id: &WorkflowId, ) -> Result<Option<WorkflowAttribution>, ServerError>
Read a workflow’s durable attribution scoped to one namespace.
Returns the recorded attribution only when the workflow’s recorded
owner namespace equals namespace. Foreign-owned and unknown workflows
both yield None (anti-existence-leak: callers must treat the two
cases identically and never disclose which one occurred).
This is the single read that serves both the namespace verdict and the workflow-type lookup at the streaming seam — one durable history read per workflow answers both questions.
§Errors
Returns ServerError when the underlying ownership data cannot be
read; callers must fail loudly rather than guessing.
Sourcepub async fn recorded_workflow_attribution(
&self,
workflow_id: &WorkflowId,
) -> Result<Option<WorkflowAttribution>, ServerError>
pub async fn recorded_workflow_attribution( &self, workflow_id: &WorkflowId, ) -> Result<Option<WorkflowAttribution>, ServerError>
Read a workflow’s recorded attribution WITHOUT scoping it to a namespace.
Self::workflow_attribution is the right read whenever the caller
already named the namespace it is asking about — it answers the scoped
question and hides everything else behind the anti-existence-leak
None. A fleet-wide SWEEP cannot use it: the sweep starts from a set of
workflow ids and does not yet know which namespace each belongs to, so
scoping first would require guessing the answer it is trying to read.
The grant filter is therefore the CALLER’s obligation here, and it is not
optional. Every use must drop entries the caller cannot access — see
CallerIdentity::can_access — before anything reaches a response body,
exactly as the enumeration reads do. Returning the raw attribution keeps
that filter visible at the sweep, rather than a scoped read silently
reporting None for a workflow the caller could in fact see.
None means the workflow recorded no owning namespace at all: an
unattributed run, not a denied one. The two are different facts and the
caller must not merge them.
§Errors
Returns ServerError when the underlying ownership data cannot be
read; callers must fail loudly rather than guessing.
Sourcepub async fn verify_schedule_ownership(
&self,
namespace: &str,
schedule_id: &ScheduleId,
) -> Result<(), ServerError>
pub async fn verify_schedule_ownership( &self, namespace: &str, schedule_id: &ScheduleId, ) -> Result<(), ServerError>
Verify durable schedule ownership against the requested namespace.
NamespaceDenied means exactly one thing: the caller has no grant for
the requested namespace, and that is decided by Self::resolve before
this check runs. Schedule-level visibility misses are NotFound to
prevent existence leaks: when the caller’s requested namespace is
granted but the schedule’s creation-recorded owner namespace is absent
(unknown schedule, or no recorded attribute) or different (owned by
another tenant), both cases return the identical not_found wire error
with the identical message, so a cross-tenant probe is byte-for-byte
indistinguishable from targeting a schedule that never existed.
§Errors
Returns a ServerError::Wire not_found error when the schedule is
not visible in the requested namespace; ownership-source read failures
surface as their own typed errors.
Trait Implementations§
Source§impl Clone for NamespaceResolver
impl Clone for NamespaceResolver
Source§fn clone(&self) -> NamespaceResolver
fn clone(&self) -> NamespaceResolver
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl !RefUnwindSafe for NamespaceResolver
impl !UnwindSafe for NamespaceResolver
impl Freeze for NamespaceResolver
impl Send for NamespaceResolver
impl Sync for NamespaceResolver
impl Unpin for NamespaceResolver
impl UnsafeUnpin for NamespaceResolver
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request