pub struct AuthzSet { /* private fields */ }Expand description
The resolved rights of one session: a principal plus the grants that
cover it. Every dispatch layer asks the same question:
AuthzSet::check.
Implementations§
Source§impl AuthzSet
impl AuthzSet
Sourcepub fn owner(principal: impl Into<String>) -> Self
pub fn owner(principal: impl Into<String>) -> Self
The implicit-superuser session: a local open with no principal
asserted (root@localhost). Every verb on every namespace.
Sourcepub fn restricted(principal: impl Into<String>, grants: Vec<Grant>) -> Self
pub fn restricted(principal: impl Into<String>, grants: Vec<Grant>) -> Self
A restricted session: only what the grants cover. Zero grants = nothing (fail closed).
pub fn principal(&self) -> &str
pub fn is_owner(&self) -> bool
pub fn allows(&self, verb: Verb, ns: &str) -> bool
Sourcepub fn check(&self, verb: Verb, ns: &str) -> Result<()>
pub fn check(&self, verb: Verb, ns: &str) -> Result<()>
The one enforcement question. The refusal names the verb, the
resource, and the principal — the pieces a granting admin needs.
(Once GRANT parses, the message will also spell the statement that
fixes it — not before, to avoid pointing at unshipped syntax.)
Sourcepub fn namespaces(&self, verb: Verb) -> GrantedNamespaces
pub fn namespaces(&self, verb: Verb) -> GrantedNamespaces
Which namespaces this set covers for verb (#324).
Self::allows answers “may I touch THIS one”, which a host serving
many principals can only turn into “which may I touch” by probing every
namespace it knows — O(namespaces) per principal per policy epoch,
where the grants themselves are the short list. This is that list.
Discloses nothing new: Grant’s fields are already public, and a
session can read its own rights. A grant on "*" (or one naming no
namespace, which means the same) answers GrantedNamespaces::All,
and so does the owner session.