Skip to main content

PolicyDecision

Enum PolicyDecision 

Source
pub enum PolicyDecision {
    Allow,
    Deny {
        reason: String,
    },
    Mutate {
        headers: Vec<(String, String)>,
        body: Option<Vec<u8>>,
    },
}
Expand description

Outcome of a single policy evaluation.

See the module docs for why this is a flat enum instead of Result<(), String>. The TL;DR: callers need to branch on three normal outcomes (Allow / Deny / Mutate), and the host must not conflate “policy said no” with “engine exploded”.

Variants§

§

Allow

Proceed with the request, no changes. The default for 99% of successful policy evaluations.

§

Deny

Refuse the request. The host MUST forward reason to the structured log and should surface it to the client when the engine is trusted (the Cedar and CEL refs produce reasons safe for 403 bodies — custom engines must document their own guarantees).

Fields

§reason: String

Human-readable explanation produced by the policy author. Example: "principal lacks scope posts:write on posts/123".

§

Mutate

Proceed, but apply response-side obligations on the way out.

The host applies these after the handler runs — header injection before headers flush, body substitution before the response hits the wire. Both fields are optional; a Mutate with neither headers nor body is legal (a no-op, but engines may emit it during composition) and the host treats it as Allow.

Fields

§headers: Vec<(String, String)>

Headers to append to (not replace) the outbound response. Empty vec = no header changes. Same-key duplicates are permitted — the host appends them in order.

§body: Option<Vec<u8>>

Replacement body. Some(bytes) overwrites the handler’s body wholesale; None leaves it untouched. Engines that only redact fields typically emit Some with the rewritten JSON.

Implementations§

Source§

impl PolicyDecision

Source

pub fn deny(reason: impl Into<String>) -> Self

Convenience: a Deny with the given reason, owning the string.

Source

pub fn is_allowed(&self) -> bool

true for Allow and for Mutate (both proceed). false for Deny. Useful for middleware that only needs the gate decision and handles mutation elsewhere.

Trait Implementations§

Source§

impl Clone for PolicyDecision

Source§

fn clone(&self) -> PolicyDecision

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for PolicyDecision

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl PartialEq for PolicyDecision

Source§

fn eq(&self, other: &PolicyDecision) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Eq for PolicyDecision

Source§

impl StructuralPartialEq for PolicyDecision

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.