pub struct PlatformSecurityContext { /* private fields */ }Expand description
Identity for non-tenant, platform-scoped operations.
Never carries a tenant subject and is never passed to the tenant
PolicyEnforcer. This is a separate type from the tenant
SecurityContext by design (separation of mechanisms): “this call has no
tenant” is unrepresentable-as-a-tenant rather than encoded as a nil tenant
id. The wrapper is stable across authentication phases; only its
PlatformIdentity changes.
Implementations§
Source§impl PlatformSecurityContext
impl PlatformSecurityContext
Sourcepub fn new(identity: PlatformIdentity) -> Self
pub fn new(identity: PlatformIdentity) -> Self
Wrap a validated PlatformIdentity.
Sourcepub fn outbound_marker() -> Self
pub fn outbound_marker() -> Self
Construct a credential-free outbound plane marker.
This is not a validated identity. It exists so gear-layer code (e.g.
a PolicyEnforcer) can call a platform-plane contract method whose
signature takes a PlatformSecurityContext argument for compile-time
plane selection, without possessing — or being able to forge — a real
one. The marker carries no secret and is discarded by the generated
client: the actual platform credential is attached below the contract
layer from the process InternalTokenProvider, and the receiver
re-derives the real identity by validating that wire token
(cpt-cf-adr-two-plane-auth).
It MUST never be consulted for an authorization decision — its
PlatformIdentity is PlatformIdentity::OutboundMarker, a variant
no validation ever produces, so a consumer that mistakenly reads it
derives neither a caller name nor a peer that could be mistaken for one.
Sourcepub fn is_outbound_marker(&self) -> bool
pub fn is_outbound_marker(&self) -> bool
Whether this is the credential-free outbound marker, rather than a validated caller.
Sourcepub fn identity(&self) -> &PlatformIdentity
pub fn identity(&self) -> &PlatformIdentity
The validated platform identity backing this context.
Sourcepub fn into_identity(self) -> PlatformIdentity
pub fn into_identity(self) -> PlatformIdentity
Consume the context, returning the owned PlatformIdentity.
Trait Implementations§
Source§impl Clone for PlatformSecurityContext
impl Clone for PlatformSecurityContext
Source§fn clone(&self) -> PlatformSecurityContext
fn clone(&self) -> PlatformSecurityContext
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more