use super::capability::{overwrites, reads_path};
use super::locus::{self, write_locus};
use crate::engine::facet::{Profile, Scale};
pub(crate) fn read_content_verdict(path: &str) -> crate::verdict::Verdict {
let cap = reads_path(path, Scale::Single, "reads a redirect source");
crate::engine::bridge::project(&Profile::of(vec![cap]))
}
pub(crate) fn read_tree_verdict(path: &str) -> crate::verdict::Verdict {
let cap = reads_path(path, Scale::Unbounded, "reads a tree of files");
crate::engine::bridge::project(&Profile::of(vec![cap]))
}
pub(crate) fn write_target_verdict(path: &str) -> crate::verdict::Verdict {
let cap = overwrites(write_locus(path), Scale::Single, false);
crate::engine::bridge::project(&Profile::of(vec![cap]))
}
pub(crate) fn rebind_is_stricter_than_write(path: &str) -> bool {
let rebind = overwrites(locus::rebind_locus(path), Scale::Single, false);
let refused = !crate::engine::bridge::project(&Profile::of(vec![rebind])).is_allowed();
refused && write_target_verdict(path).is_allowed()
}
pub(crate) fn worst_path_element(value: &str, judge: fn(&str) -> crate::verdict::Verdict, split_list: bool) -> crate::verdict::Verdict {
let mut worst = judge(value);
if split_list && value.contains(':') && !value.contains("://") {
for element in value.split(':').filter(|s| !s.is_empty()) {
worst = worst.combine(judge(element));
}
}
worst
}
pub(super) fn runs_modules_from(dirs: &[String]) -> impl Iterator<Item = super::Capability> + '_ {
use super::capability::executes;
use crate::engine::facet::ExecutionTrust;
dirs.iter()
.map(|dir| executes(super::classify_locus(dir), ExecutionTrust::CallerFile, "loads and runs modules from this directory"))
}