pub struct ScopeConstraint { /* private fields */ }Expand description
A conjunction (AND) of scope filters — one access path.
All filters within a constraint must match simultaneously for a row to be accessible via this path.
Implementations§
Source§impl ScopeConstraint
impl ScopeConstraint
Sourcepub fn try_new(filters: Vec<ScopeFilter>) -> Result<Self, EmptyScopeConstraint>
pub fn try_new(filters: Vec<ScopeFilter>) -> Result<Self, EmptyScopeConstraint>
Create a new scope constraint from a non-empty list of filters.
§Errors
Returns EmptyScopeConstraint if filters is empty. Rejecting here is
what keeps a predicate-free constraint from reaching a consumer at all:
the policy compiler builds one of these from whatever predicates a PDP
returned, and a decision that produced none would otherwise widen into
an allow-all grant instead of failing closed.
Sourcepub fn new(filters: Vec<ScopeFilter>) -> Self
pub fn new(filters: Vec<ScopeFilter>) -> Self
Create a new scope constraint from a list of filters known to be non-empty.
§Panics
Panics if filters is empty. Prefer ScopeConstraint::try_new
wherever the list is derived from input rather than written out in
place; this exists for literals and test fixtures, where an empty list
is a bug in the caller rather than a condition to handle.
Sourcepub fn filters(&self) -> &[ScopeFilter]
pub fn filters(&self) -> &[ScopeFilter]
The filters in this constraint (AND-ed together).
Trait Implementations§
Source§impl Clone for ScopeConstraint
impl Clone for ScopeConstraint
Source§fn clone(&self) -> ScopeConstraint
fn clone(&self) -> ScopeConstraint
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more