1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
//! Realtime-seam adapter over the shared subscription row-visibility policy (#596).
//!
//! The policy type and its derivation live in `fraiseql-core`
//! ([`fraiseql_core::schema::SubscriptionPolicy`] → [`OwnerCondition`]) so this realtime
//! entity-stream seam and the graphql `/ws` seam consume **identical** semantics — a
//! divergence (e.g. `bypass_roles` honored on one path but not the other) would itself
//! be a visibility bypass. This module only *adapts* the seam-neutral [`OwnerCondition`]
//! to the realtime delivery matcher's [`FieldFilter`] and defines the per-subscription
//! [`OwnerEnforcement`] state the delivery pipeline consults.
//!
//! # Fail-closed on a dormant seam
//!
//! This realtime subsystem is **not assembled by any production binary** (see #605).
//! The one property that must survive is fail-closed-by-construction: a policy-declaring
//! entity can never come up deliver-all by accident. So delivery denies a policy
//! entity's events to any subscription that did not resolve an explicit
//! [`OwnerEnforcement`] (`Bypass` or `Scoped`) at subscribe time — even a future
//! assembler who skips the subscribe-time wiring cannot leak rows.
pub use ;
use ;
/// Per-subscription row-visibility enforcement for a policy-declaring entity (#596).
///
/// Resolved at subscribe time from the entity's [`SubscriptionPolicy`] and the
/// connection's enriched identity, and stored on the subscription so the delivery
/// pipeline can enforce it without re-deriving.
/// Map a derived [`OwnerCondition`] to the realtime seam's [`OwnerEnforcement`], or a
/// refusal reason.
///
/// # Errors
///
/// Returns the refusal reason when the condition is [`OwnerCondition::Refuse`] — the
/// subscribe path turns this into an error and does not register the subscription
/// (fail-closed).