Skip to main content

CanwuViewer

Struct CanwuViewer 

Source
pub struct CanwuViewer<'a> { /* private fields */ }
Expand description

Restricted player/agent/observer API. It deliberately exposes no raw snapshot, event, boundary, domain-record, or audit-origin access.

Implementations§

Source§

impl CanwuViewer<'_>

Source

pub const fn principal(&self) -> &ObservationPrincipal

Source

pub fn query_knowledge( &self, query: &KnowledgeQuery, ) -> Result<KnowledgeQueryResult, CanwuError>

Queries only the holder selected by a bound person or institution principal. Public and diagnostic principals must use their separately named capabilities.

Source

pub fn query_holder_knowledge( &self, holder: KnowledgeHolderRef, query: &KnowledgeQuery, ) -> Result<KnowledgeQueryResult, CanwuError>

Selects an existing holder under an explicit research/developer policy. Returned records remain the origin-free holder projection.

Source

pub fn audit_knowledge_record( &self, holder: &KnowledgeHolderRef, record: HolderKnowledgeRecordId, ) -> Result<KnowledgeRecord, CanwuError>

Returns one audit-bearing stored record only for research/developer principals. Normal holder queries never expose origin evidence.

Source

pub fn visible_changes_since(&self, since: SimTime) -> Vec<VisibleChange>

Source

pub fn evaluation_traces( &self, subject: &EntityRef, after: Option<BoundaryId>, ) -> Result<Vec<EvaluationTraceView>, CanwuError>

Returns the holder-facing projection of the retained rule-evaluation traces of subject that this principal may see, from boundaries after after (every retained boundary when None), in boundary and recording order.

Visibility follows the holder ledger that Self::query_knowledge reads. A person or institution principal sees a trace when the subject is its own entity, or when a knowledge publication to its ledger that names the subject (as an entity target or, for a domain entity, as a domain-record target) was visible before the trace was evaluated: in an earlier boundary, or as a same-boundary publication in phase 4 of the same boundary. A holder therefore never gains the breakdowns of a subject evaluated before it learned of it. Research and developer principals see every trace; a public principal cannot read traces, as it cannot read a private ledger.

Like holder knowledge views, the projection omits evidence. Term evidence and the producing plugin and system stay on the trusted BoundaryRecord::evaluation_traces read through Canwu::boundaries.

Auto Trait Implementations§

§

impl<'a> !RefUnwindSafe for CanwuViewer<'a>

§

impl<'a> !Send for CanwuViewer<'a>

§

impl<'a> !Sync for CanwuViewer<'a>

§

impl<'a> !UnwindSafe for CanwuViewer<'a>

§

impl<'a> Freeze for CanwuViewer<'a>

§

impl<'a> Unpin for CanwuViewer<'a>

§

impl<'a> UnsafeUnpin for CanwuViewer<'a>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.