Skip to main content

mkit_server/policy/
write.rs

1/// Write authorization policy (SPEC-TRANSPORT-CONNECT §7.5).
2/// Hooks compose with this policy under SPEC-SERVER §6.2.
3#[derive(Debug, Clone, Copy, PartialEq, Eq)]
4#[non_exhaustive]
5pub enum WritePolicy {
6    /// Authentication and the authorizer hook suffice; Single addressing only.
7    Open,
8    /// Require namespace ownership or an authority source; grants land in M2.
9    Owner,
10}
11
12/// How the authorizer composes with built-in policy (SPEC-SERVER §6.2,
13/// SPEC-TRANSPORT-CONNECT §7.5). Neither role overrides namespace denial.
14#[derive(Debug, Clone, Copy, Default, PartialEq, Eq)]
15#[non_exhaustive]
16pub enum AuthorizerRole {
17    /// An additional check that may deny an otherwise authorized write.
18    #[default]
19    Check,
20    /// The rule-3 authority source. It may authorize non-owners and deny owners.
21    Authority,
22}