pub struct Decision {
pub allowed: bool,
pub reason: String,
pub obligations: Vec<String>,
}Expand description
The outcome of one Policy::evaluate call.
reason names the deciding rule by index ("allow (rule 0)" /
"deny (rule 2)") or the default decision ("default allow (read)"
/ "default deny"), so a 403 response body and the audit trail can
state exactly why.
Fields§
§allowed: boolWhether the request is allowed.
reason: StringThe deciding rule index or the default decision.
obligations: Vec<String>Obligations the enforcement point must honour on an allow —
the deciding allow rule’s Rule::obligations (e.g. "mask",
"audit"). Empty on a deny or the default decision. Advisory: the
engine carries them; the caller (PEP) interprets and acts on them
(e.g. "mask" ⇒ return the masked view). #[serde(default)] so
a decision serialized by an older peer still deserializes.
Implementations§
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Decision
impl<'de> Deserialize<'de> for Decision
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
impl Eq for Decision
impl StructuralPartialEq for Decision
Auto Trait Implementations§
impl Freeze for Decision
impl RefUnwindSafe for Decision
impl Send for Decision
impl Sync for Decision
impl Unpin for Decision
impl UnsafeUnpin for Decision
impl UnwindSafe for Decision
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more