1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
//! [`PolicyDb`]: where a multi-statement policy evaluation runs.
//!
//! Most write paths run one main statement on a generic `sqlx::Executor`
//! and are fine with that. Create-policy evaluation is different: it may
//! issue one `EXISTS` probe per relation predicate, recursively, so it
//! needs an executor it can use more than once. A shared `&PgPool` can be
//! copied; a `&mut PgConnection` can only be reborrowed. This enum lets
//! one evaluator serve both.
//!
//! Which one a write uses is [`PolicyDb::of`]'s decision
//! (docs/design/procedure-isolation.md §4.1): inside an `@isolation`
//! procedure the policy reads run on the procedure's own transaction, so
//! the decision is made on the same snapshot as the write and never needs
//! a second pooled connection; everywhere else they run on the pool, as
//! they always have.
use crate::;
pub