Skip to main content

Rule

Struct Rule 

Source
pub struct Rule {
    pub effect: Effect,
    pub actions: Vec<ActionPattern>,
    pub when: BTreeMap<String, Vec<String>>,
    pub obligations: Vec<String>,
}
Expand description

One ordered policy rule: an Effect, the actions it covers, and a conjunction of subject-attribute conditions.

Deserializes from the JSON shape fixed in authorization-attributes.md §4, e.g. { "effect": "allow", "actions": ["write"], "when": { "access": ["write", "admin"] } }. Unknown JSON fields are ignored (forward-compatible: a newer policy vocabulary still parses here; unrecognised extensions are inert rather than a boot failure).

when semantics (§4):

  • The map is a conjunction: every listed key must match.
  • A value list means the subject has any of these values (["write", "admin"] = write OR admin). An empty value list never matches.
  • A !-prefixed value negates: it matches when the subject does not have that value (including when the subject lacks the attribute entirely).
  • An empty when map matches every authenticated subject.
  • Keys resolve against Claims::attrs, except the reserved pseudo-attributes sub and email (from the verified claims) and entity (the resource entity passed to Policy::evaluate), which always resolve from those sources and cannot be shadowed by an identically-named attrs entry.
  • A key prefixed resource. resolves against the resource attributes passed to Policy::evaluate_with_resource (record- level attributes, e.g. resource.sensitivity), and a key prefixed env. against the environment attributes passed to Policy::evaluate_with_context (request-time / network context, e.g. env.hour), each with the prefix stripped — so a deployment can gate on properties of the specific record or the request context. Under a call that does not supply them every such key resolves empty, so the rule never matches a positive value (and a !-negated value always matches). Both namespaces are disjoint from subject attributes, so a subject can never spoof either through its token.
  • A when value of $sub or $email is a template: it resolves to the caller’s sub / email before comparison, so a rule can compare an attribute to the caller’s own identity — e.g. { "resource.owner": ["$sub"] } matches when the record’s owner is the caller (the ownership pattern). Any other value (including one merely containing $) is a literal.

Fields§

§effect: Effect

Whether a match allows or denies the request.

§actions: Vec<ActionPattern>

The derived actions this rule covers ("*" = all).

§when: BTreeMap<String, Vec<String>>

Conjunction over subject attributes; empty matches everyone.

§obligations: Vec<String>

Obligations the enforcement point must honour when this rule allows — advisory instructions the engine carries but does not interpret (e.g. "mask" ⇒ return the masked view, "audit" ⇒ write an audit record). Short lowercase tokens, like attribute values. Empty by default; ignored on a deny rule (a denial is a 403, not a conditional allow). Surfaced on the Decision of the deciding rule so the caller can act on them.

Trait Implementations§

Source§

impl Clone for Rule

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Rule

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for Rule

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for Rule

Source§

impl PartialEq for Rule

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for Rule

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for Rule

Auto Trait Implementations§

§

impl Freeze for Rule

§

impl RefUnwindSafe for Rule

§

impl Send for Rule

§

impl Sync for Rule

§

impl Unpin for Rule

§

impl UnsafeUnpin for Rule

§

impl UnwindSafe for Rule

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.