// Copyright The OpenTelemetry Authors
// SPDX-License-Identifier: Apache-2.0
//! The [`DenyReason`] categories an authorizer returns on a deny.
/// Why a request was denied.
///
/// Coarse and scheme-agnostic so it is safe to use as a low-cardinality metric
/// label. Scheme-specific detail (`invalid_aud`, `expired`, a service-account
/// name, an IP, ...) belongs in the decision's `detail` field (see
/// [`AuthzDecision`](super::AuthzDecision)) for logs, or in an authorizer's own
/// metrics -- never inflate this enum with per-request values.