pub struct Policy {
pub id: &'static str,
pub rules: &'static [Rule],
}Expand description
A named set of rules that must all pass for access.
Policies are defined as const values and attached to service methods
via the #[policy] macro.
Fields§
§id: &'static strUnique identifier for this policy (e.g. “harness.manage”).
rules: &'static [Rule]Rules that must all pass. AND logic.
Implementations§
Source§impl Policy
impl Policy
Sourcepub fn evaluate(&self, caller: &Caller) -> Result<(), PolicyError>
pub fn evaluate(&self, caller: &Caller) -> Result<(), PolicyError>
Evaluate all rules against the caller. Returns Ok(()) if all pass,
or Err(PolicyError) on the first failing rule.
Sourcepub fn evaluate_with(
&self,
resolver: &dyn PermissionResolver,
caller: &Caller,
) -> Result<(), PolicyError>
pub fn evaluate_with( &self, resolver: &dyn PermissionResolver, caller: &Caller, ) -> Result<(), PolicyError>
Evaluate all rules against the caller using a custom permission resolver.
Rule::UserHasPermission checks are delegated to resolver, while other
rule types keep their current built-in behavior.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for Policy
impl RefUnwindSafe for Policy
impl Send for Policy
impl Sync for Policy
impl Unpin for Policy
impl UnsafeUnpin for Policy
impl UnwindSafe for Policy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::Request