Skip to main content

Module sandbox_capability

Module sandbox_capability 

Source
Expand description

Sandbox session capabilities: what the manager mints and the agent verifies.

Lives here because both sides need identical rules, and a mismatch between minting and verification is a security bug that only shows up as “it works” until it does not.

A capability is scoped to one session and one operation class. Provider ids and hostnames are guessable, so neither is authorisation.

Structs§

SandboxCapabilityClaims
The claims an agent checks before doing anything.
SandboxSessionIdentity
What the agent knows about itself, established at session start.

Enums§

SandboxOperationClass
What a capability permits. Deliberately coarse: a class, not a method list, so adding a method cannot silently widen an already-minted capability.