pub struct CanwuViewer<'a> { /* private fields */ }Expand description
Restricted player/agent/observer API. It deliberately exposes no raw snapshot, event, boundary, domain-record, or audit-origin access.
Implementations§
Source§impl CanwuViewer<'_>
impl CanwuViewer<'_>
pub const fn principal(&self) -> &ObservationPrincipal
Sourcepub fn query_knowledge(
&self,
query: &KnowledgeQuery,
) -> Result<KnowledgeQueryResult, CanwuError>
pub fn query_knowledge( &self, query: &KnowledgeQuery, ) -> Result<KnowledgeQueryResult, CanwuError>
Queries only the holder selected by a bound person or institution principal. Public and diagnostic principals must use their separately named capabilities.
Sourcepub fn query_holder_knowledge(
&self,
holder: KnowledgeHolderRef,
query: &KnowledgeQuery,
) -> Result<KnowledgeQueryResult, CanwuError>
pub fn query_holder_knowledge( &self, holder: KnowledgeHolderRef, query: &KnowledgeQuery, ) -> Result<KnowledgeQueryResult, CanwuError>
Selects an existing holder under an explicit research/developer policy. Returned records remain the origin-free holder projection.
Sourcepub fn audit_knowledge_record(
&self,
holder: &KnowledgeHolderRef,
record: HolderKnowledgeRecordId,
) -> Result<KnowledgeRecord, CanwuError>
pub fn audit_knowledge_record( &self, holder: &KnowledgeHolderRef, record: HolderKnowledgeRecordId, ) -> Result<KnowledgeRecord, CanwuError>
Returns one audit-bearing stored record only for research/developer principals. Normal holder queries never expose origin evidence.
pub fn visible_changes_since(&self, since: SimTime) -> Vec<VisibleChange>
Sourcepub fn evaluation_traces(
&self,
subject: &EntityRef,
after: Option<BoundaryId>,
) -> Result<Vec<EvaluationTraceView>, CanwuError>
pub fn evaluation_traces( &self, subject: &EntityRef, after: Option<BoundaryId>, ) -> Result<Vec<EvaluationTraceView>, CanwuError>
Returns the holder-facing projection of the retained rule-evaluation
traces of subject that this principal may see, from boundaries after
after (every retained boundary when None), in boundary and
recording order.
Visibility follows the holder ledger that Self::query_knowledge
reads. A person or institution principal sees a trace when the subject
is its own entity, or when a knowledge publication to its ledger that
names the subject (as an entity target or, for a domain entity, as a
domain-record target) was visible before the trace was evaluated: in
an earlier boundary, or as a same-boundary publication in phase 4 of
the same boundary. A holder
therefore never gains the breakdowns of a subject evaluated before it
learned of it. Research and developer principals see every trace; a
public principal cannot read traces, as it cannot read a private
ledger.
Like holder knowledge views, the projection omits evidence. Term
evidence and the producing plugin and system stay on the trusted
BoundaryRecord::evaluation_traces read through Canwu::boundaries.