Skip to main content

InTenantSubtreeScopeFilter

Struct InTenantSubtreeScopeFilter 

Source
pub struct InTenantSubtreeScopeFilter { /* private fields */ }
Expand description

Tenant subtree scope filter — clamps a property to descendants of a single root tenant via the tenant_closure table.

Compiles to (with respect_barriers = true, the default, and an empty descendant_status): property IN (SELECT descendant_id FROM tenant_closure WHERE ancestor_id = root_tenant_id AND barrier = 0)

With respect_barriers = false: property IN (SELECT descendant_id FROM tenant_closure WHERE ancestor_id = root_tenant_id)

With a non-empty descendant_status (each value is the canonical SMALLINT for a tenant status — see tenant_resolver_sdk::TenantStatus::as_smallint): ... AND descendant_status IN (...)

Heads-up for tenants-style entities: When a property resolves to the tenants row’s own primary key (via pep_properties::RESOURCE_ID), the entity must declare the id column as a resolvable secured property. Entities marked with #[secure(no_resource, ...)] will fail-closed at scope resolution time.

Implementations§

Source§

impl InTenantSubtreeScopeFilter

Source

pub fn new( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, ) -> Self

Create a tenant subtree scope filter that respects barriers with no status filter.

Equivalent to with_respect_barriers(property, root_tenant_id, true).

Source

pub fn with_respect_barriers( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, respect_barriers: bool, ) -> Self

Create a tenant subtree scope filter with explicit barrier handling and no status filter.

Source

pub fn with_descendant_status( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, respect_barriers: bool, descendant_status: Vec<ScopeValue>, ) -> Self

Create a tenant subtree scope filter with explicit barrier handling and a (possibly empty) status filter on the descendants. An empty list is equivalent to “no status filter”.

Source

pub fn property(&self) -> &str

The authorization property name.

Source

pub fn root_tenant_id(&self) -> &ScopeValue

The single root tenant ID at which the subtree is anchored.

Source

pub fn respect_barriers(&self) -> bool

Whether the SQL compilation should clamp the closure subquery with AND barrier = 0 (i.e. stop at self-managed boundaries).

Source

pub fn descendant_status(&self) -> &[ScopeValue]

Status filter applied to the descendants reached via the closure.

Empty slice means “no status filter”; otherwise the SQL adds AND descendant_status IN (...) to the closure subquery. Values are expected to be SMALLINT-encoded statuses (see tenant_resolver_sdk::TenantStatus::as_smallint).

Trait Implementations§

Source§

impl Clone for InTenantSubtreeScopeFilter

Source§

fn clone(&self) -> InTenantSubtreeScopeFilter

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for InTenantSubtreeScopeFilter

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for InTenantSubtreeScopeFilter

Source§

impl PartialEq for InTenantSubtreeScopeFilter

Source§

fn eq(&self, other: &InTenantSubtreeScopeFilter) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for InTenantSubtreeScopeFilter

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more