pub struct ReadScope { /* private fields */ }Expand description
High-performance event store with columnar storage What a read credential is allowed to see, enforced inside the store.
A read key is otherwise all-or-nothing: “let this tool read the store” and
“let this tool read every credential ever issued” are the same grant. That is
not theoretical — auth events carry session tokens whose value IS the
entity_id, so a routine query rendered live bearer tokens into an agent’s
context (#265). Redacting on write cannot fix it: the token is the lookup
key.
Deliberately not Deserialize. This must never be settable from a
request body, or a caller widens its own scope by omitting the field.
Allow-list, not deny-list, on purpose: a stream family added later is excluded until someone names it, so the failure mode of forgetting is a missing read rather than a leak.
Implementations§
Source§impl ReadScope
impl ReadScope
Sourcepub fn unrestricted() -> Self
pub fn unrestricted() -> Self
Everything in the tenant — the behaviour of every read before scopes.
Sourcepub fn allow_entity_prefixes<I, S>(prefixes: I) -> Self
pub fn allow_entity_prefixes<I, S>(prefixes: I) -> Self
Only entities whose id starts with one of prefixes.
An empty list denies everything, which is the safe reading of “scoped to nothing” and stops an accidentally-empty config granting full access.
Sourcepub fn is_unrestricted(&self) -> bool
pub fn is_unrestricted(&self) -> bool
True when this scope restricts nothing.