pub struct InTenantSubtreeScopeFilter { /* private fields */ }Expand description
Tenant subtree scope filter — clamps a property to descendants of a single
root tenant via the tenant_closure table.
Compiles to (with respect_barriers = true, the default, and an empty
descendant_status):
property IN (SELECT descendant_id FROM tenant_closure WHERE ancestor_id = root_tenant_id AND barrier = 0)
With respect_barriers = false:
property IN (SELECT descendant_id FROM tenant_closure WHERE ancestor_id = root_tenant_id)
With a non-empty descendant_status (each value is the canonical
SMALLINT for a tenant status — see
tenant_resolver_sdk::TenantStatus::as_smallint):
... AND descendant_status IN (...)
Heads-up for tenants-style entities: When a property resolves
to the tenants row’s own primary key (via pep_properties::RESOURCE_ID),
the entity must declare the id column as a resolvable secured
property. Entities marked with #[secure(no_resource, ...)] will
fail-closed at scope resolution time.
Implementations§
Source§impl InTenantSubtreeScopeFilter
impl InTenantSubtreeScopeFilter
Sourcepub fn new(
property: impl Into<String>,
root_tenant_id: impl Into<ScopeValue>,
) -> Self
pub fn new( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, ) -> Self
Create a tenant subtree scope filter that respects barriers with no status filter.
Equivalent to
with_respect_barriers(property, root_tenant_id, true).
Sourcepub fn with_respect_barriers(
property: impl Into<String>,
root_tenant_id: impl Into<ScopeValue>,
respect_barriers: bool,
) -> Self
pub fn with_respect_barriers( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, respect_barriers: bool, ) -> Self
Create a tenant subtree scope filter with explicit barrier handling and no status filter.
Sourcepub fn with_descendant_status(
property: impl Into<String>,
root_tenant_id: impl Into<ScopeValue>,
respect_barriers: bool,
descendant_status: Vec<ScopeValue>,
) -> Self
pub fn with_descendant_status( property: impl Into<String>, root_tenant_id: impl Into<ScopeValue>, respect_barriers: bool, descendant_status: Vec<ScopeValue>, ) -> Self
Create a tenant subtree scope filter with explicit barrier handling and a (possibly empty) status filter on the descendants. An empty list is equivalent to “no status filter”.
Sourcepub fn root_tenant_id(&self) -> &ScopeValue
pub fn root_tenant_id(&self) -> &ScopeValue
The single root tenant ID at which the subtree is anchored.
Sourcepub fn respect_barriers(&self) -> bool
pub fn respect_barriers(&self) -> bool
Whether the SQL compilation should clamp the closure subquery
with AND barrier = 0 (i.e. stop at self-managed boundaries).
Sourcepub fn descendant_status(&self) -> &[ScopeValue]
pub fn descendant_status(&self) -> &[ScopeValue]
Status filter applied to the descendants reached via the closure.
Empty slice means “no status filter”; otherwise the SQL adds
AND descendant_status IN (...) to the closure subquery. Values
are expected to be SMALLINT-encoded statuses
(see tenant_resolver_sdk::TenantStatus::as_smallint).
Trait Implementations§
Source§impl Clone for InTenantSubtreeScopeFilter
impl Clone for InTenantSubtreeScopeFilter
Source§fn clone(&self) -> InTenantSubtreeScopeFilter
fn clone(&self) -> InTenantSubtreeScopeFilter
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more