Skip to main content

NamespaceResolver

Struct NamespaceResolver 

Source
pub struct NamespaceResolver { /* private fields */ }
Expand description

Resolver that authorizes callers and yields namespace-scoped engine access.

Implementations§

Source§

impl NamespaceResolver

Source

pub fn from_config(config: NamespaceConfig, engine: Arc<Engine>) -> Self

Build a resolver from operator-supplied namespace configuration and the engine selected for this deployment.

Source

pub fn from_parts( mode: NamespaceMode, engine: Option<Arc<Engine>>, ownership: Arc<dyn WorkflowNamespaceSource>, schedule_ownership: Arc<dyn ScheduleNamespaceSource>, ) -> Self

Build a resolver from explicit parts for tests and alternate wiring.

Source

pub fn authorization_only( mode: NamespaceMode, ownership: impl WorkflowNamespaceSource + 'static, schedule_ownership: impl ScheduleNamespaceSource + 'static, ) -> Self

Build a resolver that performs authorization and ownership checks only.

This constructor is intended for adapter-boundary unit tests that must prove denied operations do not reach any engine handle.

Source

pub const fn mode(&self) -> &NamespaceMode

Inspect the configured namespace mode.

Source

pub fn shutdown_engine(&self) -> Result<(), ServerError>

Shut down the engine owned by this resolver.

§Errors

Returns ServerError::Config when no engine is attached, or ServerError::EngineCall when the engine rejects shutdown.

Source

pub async fn verify_workflow_ownership( &self, namespace: &str, workflow_id: &WorkflowId, ) -> Result<(), ServerError>

Verify durable workflow ownership against the requested namespace.

NamespaceDenied means exactly one thing: the caller has no grant for the requested namespace, and that is decided by Self::resolve before this check runs. Workflow-level visibility misses are NotFound to prevent existence leaks: when the caller’s requested namespace is granted but the workflow’s recorded owner namespace is absent (unknown workflow, or no recorded attribute) or different (owned by another tenant), both cases return the identical not_found wire error with the identical message, so a cross-tenant probe is byte-for-byte indistinguishable from querying a workflow that never existed.

§Errors

Returns a ServerError::Wire not_found error when the workflow is not visible in the requested namespace; ownership-source read failures surface as their own typed errors.

Source

pub async fn workflow_attribution( &self, namespace: &str, workflow_id: &WorkflowId, ) -> Result<Option<WorkflowAttribution>, ServerError>

Read a workflow’s durable attribution scoped to one namespace.

Returns the recorded attribution only when the workflow’s recorded owner namespace equals namespace. Foreign-owned and unknown workflows both yield None (anti-existence-leak: callers must treat the two cases identically and never disclose which one occurred).

This is the single read that serves both the namespace verdict and the workflow-type lookup at the streaming seam — one durable history read per workflow answers both questions.

§Errors

Returns ServerError when the underlying ownership data cannot be read; callers must fail loudly rather than guessing.

Source

pub async fn recorded_workflow_attribution( &self, workflow_id: &WorkflowId, ) -> Result<Option<WorkflowAttribution>, ServerError>

Read a workflow’s recorded attribution WITHOUT scoping it to a namespace.

Self::workflow_attribution is the right read whenever the caller already named the namespace it is asking about — it answers the scoped question and hides everything else behind the anti-existence-leak None. A fleet-wide SWEEP cannot use it: the sweep starts from a set of workflow ids and does not yet know which namespace each belongs to, so scoping first would require guessing the answer it is trying to read.

The grant filter is therefore the CALLER’s obligation here, and it is not optional. Every use must drop entries the caller cannot access — see CallerIdentity::can_access — before anything reaches a response body, exactly as the enumeration reads do. Returning the raw attribution keeps that filter visible at the sweep, rather than a scoped read silently reporting None for a workflow the caller could in fact see.

None means the workflow recorded no owning namespace at all: an unattributed run, not a denied one. The two are different facts and the caller must not merge them.

§Errors

Returns ServerError when the underlying ownership data cannot be read; callers must fail loudly rather than guessing.

Source

pub async fn verify_schedule_ownership( &self, namespace: &str, schedule_id: &ScheduleId, ) -> Result<(), ServerError>

Verify durable schedule ownership against the requested namespace.

NamespaceDenied means exactly one thing: the caller has no grant for the requested namespace, and that is decided by Self::resolve before this check runs. Schedule-level visibility misses are NotFound to prevent existence leaks: when the caller’s requested namespace is granted but the schedule’s creation-recorded owner namespace is absent (unknown schedule, or no recorded attribute) or different (owned by another tenant), both cases return the identical not_found wire error with the identical message, so a cross-tenant probe is byte-for-byte indistinguishable from targeting a schedule that never existed.

§Errors

Returns a ServerError::Wire not_found error when the schedule is not visible in the requested namespace; ownership-source read failures surface as their own typed errors.

Trait Implementations§

Source§

impl Clone for NamespaceResolver

Source§

fn clone(&self) -> NamespaceResolver

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoMaybeUndefined<T> for T

Source§

fn into_maybe_undefined(self) -> MaybeUndefined<T>

Converts this value into a three-state builder argument.
Source§

impl<T> IntoOption<T> for T

Source§

fn into_option(self) -> Option<T>

Converts this value into an optional builder argument.
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more