Skip to main content

ResourcePolicy

Trait ResourcePolicy 

Source
pub trait ResourcePolicy<E: Send + Sync + 'static>: Send + Sync {
    // Required method
    fn can<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        action: ResourceAction,
        entity: &'life1 E,
        ctx: &'life2 AuthContext,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait;

    // Provided methods
    fn resource_type() -> &'static str
       where Self: Sized { ... }
    fn create_permission() -> &'static str
       where Self: Sized { ... }
    fn read_permission() -> &'static str
       where Self: Sized { ... }
    fn list_permission() -> &'static str
       where Self: Sized { ... }
    fn update_permission() -> &'static str
       where Self: Sized { ... }
    fn patch_permission() -> &'static str
       where Self: Sized { ... }
    fn delete_permission() -> &'static str
       where Self: Sized { ... }
    fn restore_permission() -> &'static str
       where Self: Sized { ... }
    fn explicitly_disabled_actions(&self) -> Vec<ResourceAction> { ... }
}
Expand description

Determines whether the caller described by auth_ctx may perform action on entity.

Return true to permit, false to deny. Use PermissionGuard to convert this into a Result<(), AccessDenied> suitable for HTTP handlers.

§Static permission string methods

The resource_type() and *_permission() associated functions return the permission string identifiers used by RBAC systems. They have a where Self: Sized bound so they can only be called in generic contexts (not through dyn ResourcePolicy), which is intentional — the strings are known at compile time and used by code generators and RBAC setup code.

ⓘ
// Generated usage:
let required = OrderResourcePolicy::update_permission(); // "orders:update"
rbac.require_permission(ctx, required)?;

Required Methods§

Source

fn can<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, action: ResourceAction, entity: &'life1 E, ctx: &'life2 AuthContext, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Provided Methods§

Source

fn resource_type() -> &'static str
where Self: Sized,

The resource type name used in permission strings.

Default: "resource". Override per entity, e.g. "orders".

Source

fn create_permission() -> &'static str
where Self: Sized,

Permission string required to create this resource.

Source

fn read_permission() -> &'static str
where Self: Sized,

Permission string required to read/fetch this resource.

Source

fn list_permission() -> &'static str
where Self: Sized,

Permission string required to list this resource.

Source

fn update_permission() -> &'static str
where Self: Sized,

Permission string required to fully update this resource.

Source

fn patch_permission() -> &'static str
where Self: Sized,

Permission string required to partially patch this resource.

Source

fn delete_permission() -> &'static str
where Self: Sized,

Permission string required to delete this resource.

Source

fn restore_permission() -> &'static str
where Self: Sized,

Permission string required to restore a soft-deleted resource.

Source

fn explicitly_disabled_actions(&self) -> Vec<ResourceAction>

Optional: deny specific actions for all callers (e.g. hard-delete disabled).

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§

Source§

impl<E: Send + Sync + 'static> ResourcePolicy<E> for DenyAllResourcePolicy<E>

Source§

impl<E: Send + Sync + 'static> ResourcePolicy<E> for PermitAllResourcePolicy<E>

Source§

impl<E: Send + Sync + 'static> ResourcePolicy<E> for RoleRequiredPolicy<E>