pub struct IamAction {
pub service: &'static str,
pub action: &'static str,
pub resource: String,
}Expand description
One IAM action that the dispatch layer should evaluate against the caller’s effective policy set.
Produced by crate::service::AwsService::iam_action_for on services
that opt into enforcement. The resource is a fully-qualified AWS ARN
built from request.principal.account_id so multi-account isolation
(#381) becomes a state-partitioning change rather than a cross-cutting
rewrite.
Fields§
§service: &'static strIAM service prefix, e.g. "s3", "sqs", "iam".
action: &'static strAWS action name, e.g. "GetObject", "SendMessage".
resource: StringFully-qualified ARN of the target resource.
Implementations§
Source§impl IamAction
impl IamAction
Sourcepub fn action_string(&self) -> String
pub fn action_string(&self) -> String
Compose the canonical service:Action string the evaluator
matches against.
Sourcepub fn pass_role(role_arn: impl Into<String>) -> Self
pub fn pass_role(role_arn: impl Into<String>) -> Self
iam:PassRole on role_arn: the authorization AWS requires of the
caller whenever a request hands a role to a service (Lambda’s Role,
a Scheduler target’s RoleArn, an S3 replication Role, …). It is
evaluated in addition to the operation’s own action, and the service
supplies the iam:PassedToService / iam:AssociatedResourceArn
condition keys via pass_role_condition_keys.
Sourcepub fn is_pass_role(&self) -> bool
pub fn is_pass_role(&self) -> bool
True for the iam:PassRole action built by IamAction::pass_role.
Trait Implementations§
impl Eq for IamAction
impl StructuralPartialEq for IamAction
Auto Trait Implementations§
impl Freeze for IamAction
impl RefUnwindSafe for IamAction
impl Send for IamAction
impl Sync for IamAction
impl Unpin for IamAction
impl UnsafeUnpin for IamAction
impl UnwindSafe for IamAction
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.