1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
//! Token policy account components.
//!
//! Policies are the procedures that gate minting, burning, and transferring of tokens. The policy
//! state is owned by a single [`TokenPolicyManager`] component, which exposes four kinds of
//! policies:
//! - **mint** — gate mint operations
//! - **burn** — gate burn operations
//! - **send** — fired by the protocol's `on_before_asset_added_to_note` callback when the issuing
//! faucet's asset is added to a note (transfer "from" side)
//! - **receive** — fired by the protocol's `on_before_asset_added_to_account` callback when the
//! issuing faucet's asset is added to an account vault (transfer "to" side)
//!
//! The manager owns an `active_*_policy` slot per kind plus an `allowed_*_policies` map per kind
//! for set-time validation. Every policy is dispatched via `dyncall`, so it runs in its own memory
//! context behind the standard `call` ABI and cannot reach the dispatching faucet's procedure
//! locals. Mint and burn are dispatched by `exec`-invoked wrappers; send and receive are
//! dispatched by `invoke_send_policy` / `invoke_receive_policy` wrappers whose roots live in
//! the protocol-reserved callback slots, so the kernel `dyncall`s the wrapper, which applies the
//! pause check and then dispatches to the active policy.
//!
//! Authority for switching policies is provided by the separate
//! [`Authority`][crate::account::access::Authority] component, which must be installed on the
//! account alongside the policy manager. The masm helper `authority::assert_authorized` is
//! `exec`'d from `set_*_policy` to gate runtime policy changes.
//!
//! Storage-free policy components (e.g. [`MintAllowAll`], [`BurnOwnerOnly`],
//! [`TransferAllowAll`]) install a specific policy procedure on the account so that the
//! manager's `dyncall` can dispatch to it.
//!
//! Policies that may run through FPI and read mutable, security-sensitive state must set an
//! expiration delta in the same execution path that reads the state. This includes transfer
//! policies reached through asset callbacks and policies that read blocklists, allowlists, pause
//! flags, active policy roots, oracle values, risk parameters, or similar mutable data. The
//! built-in mutable transfer policies apply `miden::standards::expiration::apply_default`; custom
//! policies should call that helper or `tx::update_expiration_block_delta` directly with a custom
//! expiration delta. No expiration delta is required when a policy reads only immutable data or
//! when stale data is acceptable.
//!
//! A faucet constructs the manager via [`TokenPolicyManager::builder`], setting the required
//! `active_*_policy` for each kind (and optionally any number of reserved `allowed_*_policy`
//! entries), then passes the built manager directly to
//! [`miden_protocol::account::AccountBuilder::with_components`].
pub use ;
pub use ;
pub use ;
pub use ;