pub struct ExplainArgs { /* private fields */ }Expand description
Arguments for the unified policy explain verb (basil-1zx.3).
One command, two sources of truth for the same subject/op/key → allow/deny question:
- Default (offline dry-run,
basil-4vf): loads ONLY the catalog + policy JSON (no sealed bundle, no backend, no socket), builds the realPdp, and evaluates the proposed tuple through the SAME matcher enforcement uses. It NEVER performs the op, reads a secret, or talks to a backend: safe to run anywhere, before rollout.--effectivepreviews every grant for the subject. --live: queries the RUNNING broker’s serving generation over the global--socket(needs theexplainadmin permission). The offline config-override paths are irrelevant here, and--effectiveis offline-only.
What the PDP matches on: authorization binds to a registered subject. The offline tool evaluates that subject name directly; Unix uid/gid resolution is covered by the loader and runtime actor-resolution tests.
Implementations§
Source§impl ExplainArgs
impl ExplainArgs
Sourcepub const fn is_live(&self) -> bool
pub const fn is_live(&self) -> bool
True when --live was given: query the running broker rather than files.
Trait Implementations§
Source§impl Args for ExplainArgs
impl Args for ExplainArgs
Source§fn augment_args<'b>(__clap_app: Command) -> Command
fn augment_args<'b>(__clap_app: Command) -> Command
Source§fn augment_args_for_update<'b>(__clap_app: Command) -> Command
fn augment_args_for_update<'b>(__clap_app: Command) -> Command
Append to
Command so it can instantiate self via
FromArgMatches::update_from_arg_matches_mut Read moreSource§impl Debug for ExplainArgs
impl Debug for ExplainArgs
Source§impl FromArgMatches for ExplainArgs
impl FromArgMatches for ExplainArgs
Source§fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>
fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>
Source§fn from_arg_matches_mut(
__clap_arg_matches: &mut ArgMatches,
) -> Result<Self, Error>
fn from_arg_matches_mut( __clap_arg_matches: &mut ArgMatches, ) -> Result<Self, Error>
Source§fn update_from_arg_matches(
&mut self,
__clap_arg_matches: &ArgMatches,
) -> Result<(), Error>
fn update_from_arg_matches( &mut self, __clap_arg_matches: &ArgMatches, ) -> Result<(), Error>
Assign values from
ArgMatches to self.Source§fn update_from_arg_matches_mut(
&mut self,
__clap_arg_matches: &mut ArgMatches,
) -> Result<(), Error>
fn update_from_arg_matches_mut( &mut self, __clap_arg_matches: &mut ArgMatches, ) -> Result<(), Error>
Assign values from
ArgMatches to self.Auto Trait Implementations§
impl Freeze for ExplainArgs
impl RefUnwindSafe for ExplainArgs
impl Send for ExplainArgs
impl Sync for ExplainArgs
impl Unpin for ExplainArgs
impl UnsafeUnpin for ExplainArgs
impl UnwindSafe for ExplainArgs
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::Request