Skip to main content

Module policy

Module policy 

Source
Expand description

Domain policy — enforces pure business rules that govern whether CRUD operations are valid for a given entity state.

DomainPolicy<E> is intentionally free of authentication context. It answers questions like “is this entity in a state that allows deletion?” or “is this transition valid?”. Identity-based rules live in backbone-auth::resource_policy::ResourcePolicy<E>.

Policies are composable via AllOfPolicy / AnyOfPolicy.

§Example

ⓘ
use backbone_core::policy::{DomainPolicy, PolicyDecision};

struct OrderCancelPolicy;

#[async_trait::async_trait]
impl DomainPolicy<Order> for OrderCancelPolicy {
    async fn can_delete(&self, entity: &Order) -> PolicyDecision {
        if entity.status == OrderStatus::Delivered {
            Err("cannot cancel a delivered order".into())
        } else {
            Ok(true)
        }
    }
}

Structs§

AllOfPolicy
Combines multiple policies with AND semantics: all policies must permit an operation.
AnyOfPolicy
Combines multiple policies with OR semantics: any policy permitting is sufficient.
DenyAllPolicy
Denies every operation — useful for protecting deprecated endpoints.
NotPolicy
Inverts a policy.
PermitAllPolicy
Permits every operation — useful as the generated default. Replace with a real policy in your custom decorator.
PolicyContext
Contextual information available to custom policies that need it.

Enums§

PolicyOutcome
Legacy outcome type — retained for code that uses it directly. Prefer PolicyDecision (Result<bool, String>) in new code.

Traits§

DomainPolicy
Core domain policy trait — governs whether CRUD operations are valid for a given entity E based on entity state alone (no auth context).

Type Aliases§

PolicyDecision
The result of a policy evaluation.