mkit_server/policy/write.rs
1/// Write authorization policy (SPEC-TRANSPORT-CONNECT §7.5).
2/// Hooks compose with this policy under SPEC-SERVER §6.2.
3#[derive(Debug, Clone, Copy, PartialEq, Eq)]
4#[non_exhaustive]
5pub enum WritePolicy {
6 /// Authentication and the authorizer hook suffice; Single addressing only.
7 Open,
8 /// Require namespace ownership or an authority source; grants land in M2.
9 Owner,
10}
11
12/// How the authorizer composes with built-in policy (SPEC-SERVER §6.2,
13/// SPEC-TRANSPORT-CONNECT §7.5). Neither role overrides namespace denial.
14#[derive(Debug, Clone, Copy, Default, PartialEq, Eq)]
15#[non_exhaustive]
16pub enum AuthorizerRole {
17 /// An additional check that may deny an otherwise authorized write.
18 #[default]
19 Check,
20 /// The rule-3 authority source. It may authorize non-owners and deny owners.
21 Authority,
22}