pub struct Rule {
pub effect: Effect,
pub actions: Vec<ActionPattern>,
pub when: BTreeMap<String, Vec<String>>,
pub obligations: Vec<String>,
}Expand description
One ordered policy rule: an Effect, the actions it covers, and a
conjunction of subject-attribute conditions.
Deserializes from the JSON shape fixed in
authorization-attributes.md §4, e.g.
{ "effect": "allow", "actions": ["write"], "when": { "access": ["write", "admin"] } }.
Unknown JSON fields are ignored (forward-compatible: a newer
policy vocabulary still parses here; unrecognised extensions are
inert rather than a boot failure).
when semantics (§4):
- The map is a conjunction: every listed key must match.
- A value list means the subject has any of these values
(
["write", "admin"]= write OR admin). An empty value list never matches. - A
!-prefixed value negates: it matches when the subject does not have that value (including when the subject lacks the attribute entirely). - An empty
whenmap matches every authenticated subject. - Keys resolve against
Claims::attrs, except the reserved pseudo-attributessubandemail(from the verified claims) andentity(the resource entity passed toPolicy::evaluate), which always resolve from those sources and cannot be shadowed by an identically-namedattrsentry. - A key prefixed
resource.resolves against the resource attributes passed toPolicy::evaluate_with_resource(record- level attributes, e.g.resource.sensitivity), and a key prefixedenv.against the environment attributes passed toPolicy::evaluate_with_context(request-time / network context, e.g.env.hour), each with the prefix stripped — so a deployment can gate on properties of the specific record or the request context. Under a call that does not supply them every such key resolves empty, so the rule never matches a positive value (and a!-negated value always matches). Both namespaces are disjoint from subject attributes, so a subject can never spoof either through its token. - A
whenvalue of$subor$emailis a template: it resolves to the caller’ssub/emailbefore comparison, so a rule can compare an attribute to the caller’s own identity — e.g.{ "resource.owner": ["$sub"] }matches when the record’s owner is the caller (the ownership pattern). Any other value (including one merely containing$) is a literal.
Fields§
§effect: EffectWhether a match allows or denies the request.
actions: Vec<ActionPattern>The derived actions this rule covers ("*" = all).
when: BTreeMap<String, Vec<String>>Conjunction over subject attributes; empty matches everyone.
obligations: Vec<String>Obligations the enforcement point must honour when this rule
allows — advisory instructions the engine carries but does
not interpret (e.g. "mask" ⇒ return the masked view,
"audit" ⇒ write an audit record). Short lowercase tokens, like
attribute values. Empty by default; ignored on a deny rule
(a denial is a 403, not a conditional allow). Surfaced on the
Decision of the deciding rule so the caller can act on them.