gatekeep-fluent 3.0.1

Fluent reason catalog adapter for gatekeep
Documentation

gatekeep

The soul selects her own society, Then shuts the door;

— Emily Dickinson, "Exclusion" (1890)

gatekeep is a code-first authorization engine for Rust. Policies are ordinary typed values, so the compiler and your tests can see the same rules that run in production. Evaluation is deterministic, and every decision includes the facts and policy clause that produced it.

It fits applications where Rust owns the authorization model. If policy needs to live outside the codebase or cross service and language boundaries, use a shared policy system instead.

A policy

use gatekeep::{condition, evaluate, policy, Effect, Fact, GatekeepResult, KnownFacts, StaticFactId};

struct CaseOwner;

impl Fact for CaseOwner {
    const ID: StaticFactId = StaticFactId::new("case_owner");
}

fn main() -> GatekeepResult<()> {
    let may_read = policy::grant((), condition::has::<CaseOwner>())
        .try_reason("not_case_owner")?;

    let facts = KnownFacts::new().with_present::<CaseOwner>();
    let decision = evaluate(&may_read, &facts);
    assert_eq!(decision.effect, Effect::Permit(()));

    Ok(())
}

Your application authenticates the request and supplies the facts. Gatekeep evaluates them. The same policy can authorize one request, become a SQL filter through gatekeep-sqlx, and leave a decision trace for audit.

For durable audit, gatekeep-sqlx writes complete decision events through Dovecote. The gatekeep-keepsake adapter reads relation state from Keepsake.

Install

cargo add gatekeep@3

Add only the adapters you need: gatekeep-axum, gatekeep-fluent, gatekeep-keepsake, and gatekeep-sqlx.

Start with the quickstart, read about graded outcomes, or browse the full documentation. The core API is on docs.rs.

Licensed under MIT OR Apache-2.0.