pub enum AccessScope {
Platform,
Company(Uuid),
}Expand description
Per-request access scope, injected by the application’s auth middleware as an axum
Extension. Platform sees everything (a superadmin / root caller); Company(id) is
scoped to one tenant.
It governs two boundaries, and they must agree:
- row visibility — the SQL fence (
EntityRepoMeta::company_field), which decides which rows exist for this caller at all; - field visibility —
@privatefields, gated on the row’s@ownermatching.
§Deriving it
There must be exactly ONE answer to “who is the tenant” per request. Build this
from the authenticated principal — backbone_auth::company::CompanyContext, whose
company_id comes from a signed claim — never populate it independently:
let scope = AccessScope::Company(tenant_ctx.company_id);Two independently-populated identities can disagree under partial wiring, and the
failure is a silent cross-tenant read. Uuid rather than String so the fence and
the writer cannot drift on formatting.
Variants§
Platform
Full visibility — platform/root caller. No company fence is applied.
Company(Uuid)
Scoped to a single company (legal entity); only this company’s rows are visible.
Implementations§
Source§impl AccessScope
impl AccessScope
Sourcepub fn company(&self) -> Option<Uuid>
pub fn company(&self) -> Option<Uuid>
The company to fence queries by, or None for a platform caller.
Feed this to the ORM’s scoped read paths. Note None here means “platform, no
fence” — it is NOT the same as an absent AccessScope, which means the request was
never scoped and must be refused for a company-scoped entity.
Trait Implementations§
Source§impl Clone for AccessScope
impl Clone for AccessScope
impl Copy for AccessScope
Source§impl Debug for AccessScope
impl Debug for AccessScope
impl Eq for AccessScope
Source§impl PartialEq for AccessScope
impl PartialEq for AccessScope
impl StructuralPartialEq for AccessScope
Auto Trait Implementations§
impl Freeze for AccessScope
impl RefUnwindSafe for AccessScope
impl Send for AccessScope
impl Sync for AccessScope
impl Unpin for AccessScope
impl UnsafeUnpin for AccessScope
impl UnwindSafe for AccessScope
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more