Skip to main content

ScopeFilter

Enum ScopeFilter 

Source
#[non_exhaustive]
pub enum ScopeFilter { Eq(EqScopeFilter), In(InScopeFilter), InGroup(InGroupScopeFilter), InGroupSubtree(InGroupSubtreeScopeFilter), InTenantSubtree(InTenantSubtreeScopeFilter), }
Expand description

A single scope filter — a typed predicate on a named resource property.

The property name (e.g., "owner_tenant_id", "id") is an authorization concept. Mapping to DB columns is done by ScopableEntity::resolve_property().

Variants mirror the predicate types from the PDP response:

#[non_exhaustive]: this mirrors the PDP’s predicate set, which has already grown to five variants and will grow again. Without it, every new predicate is a breaking change for every downstream match. With it, a consumer must write a wildcard arm — and that arm must fail closed: a filter this build does not understand is a restriction it cannot apply, so treating it as “nothing to do” silently drops a narrowing term and widens the grant.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

Eq(EqScopeFilter)

Equality: property = value.

§

In(InScopeFilter)

Set membership: property IN (values).

§

InGroup(InGroupScopeFilter)

Group membership: property IN (SELECT resource_id FROM membership WHERE group_id IN (group_ids)).

§

InGroupSubtree(InGroupSubtreeScopeFilter)

Group subtree: property IN (SELECT resource_id FROM membership WHERE group_id IN (SELECT descendant_id FROM closure WHERE ancestor_id IN (ancestor_ids))).

§

InTenantSubtree(InTenantSubtreeScopeFilter)

Tenant subtree: property IN (SELECT descendant_id FROM tenant_closure WHERE ancestor_id = root_tenant_id).

Implementations§

Source§

impl ScopeFilter

Source

pub fn eq(property: impl Into<String>, value: impl Into<ScopeValue>) -> Self

Create an equality filter (property = value).

Source

pub fn in(property: impl Into<String>, values: Vec<ScopeValue>) -> Self

Create a set membership filter (property IN (values)).

Source

pub fn in_uuids(property: impl Into<String>, uuids: Vec<Uuid>) -> Self

Create a set membership filter from UUID values (convenience).

Source

pub fn in_group(property: impl Into<String>, group_ids: Vec<ScopeValue>) -> Self

Create a group membership filter.

Source

pub fn in_group_subtree( property: impl Into<String>, ancestor_ids: Vec<ScopeValue>, ) -> Self

Create a group subtree filter.

Source

pub fn in_tenant_subtree( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, respect_barriers: bool, descendant_status: Vec<ScopeValue>, ) -> Self

Create a tenant subtree filter rooted at a single ancestor tenant.

descendant_status is a (possibly empty) list of SMALLINT-encoded tenant statuses (see tenant_resolver_sdk::TenantStatus::as_smallint); when non-empty, the SQL adds AND descendant_status IN (...) to the closure subquery. Pass Vec::new() for “no status filter”.

Source

pub fn property(&self) -> &str

The authorization property name.

Source

pub fn values(&self) -> ScopeFilterValues<'_>

Collect direct-match values as a slice-like view for iteration.

For Eq, returns a single-element slice; for In, returns the values slice. For InGroup/InGroupSubtree/InTenantSubtree, returns empty — those are subquery parameters, not resource property values. The actual matching happens in SQL via [secure::scope_to_condition].

Write-path limitation: Because InTenantSubtree returns an empty slice here, in-memory helpers such as AccessScope::contains_uuid and AccessScope::all_uuid_values_for always return negative/empty results for this filter variant. Secure-insert paths that validate scope membership via these helpers cannot use InTenantSubtree as a substitute for allow_all() without an additional DB-backed tenant-membership check.

Source

pub fn is_representable_in_memory(&self) -> bool

Whether this filter can be decided from its values alone.

false for the three subquery variants, whose matching happens in SQL. ScopeFilter::values returns an empty view for those, which is indistinguishable from an In filter that genuinely has no values — so a caller deciding membership in memory reads “no match” for a filter that does grant access.

Check this first: a filter that is not representable in memory has to be resolved against the database, not treated as a negative.

Source

pub fn uuid_values(&self) -> Vec<Uuid>

Extract filter values as UUIDs, skipping non-UUID entries.

Useful when the caller knows the property holds UUID values (e.g., owner_tenant_id, id).

Trait Implementations§

Source§

impl Clone for ScopeFilter

Source§

fn clone(&self) -> ScopeFilter

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ScopeFilter

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for ScopeFilter

Source§

impl PartialEq for ScopeFilter

Source§

fn eq(&self, other: &ScopeFilter) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for ScopeFilter

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more