pub trait ScpResolver: Send + Sync {
// Required method
fn scps_for(&self, principal: &Principal) -> Option<Vec<String>>;
// Provided method
fn principal_org(&self, _account_id: &str) -> Option<(String, String)> { ... }
}Expand description
Abstraction over “given a principal, return the inherited SCP
documents that form the top-of-chain allow-list ceiling for the
principal’s account”. Implemented by fakecloud-organizations.
Returning None means SCPs do not apply (no org exists for this
fakecloud process, or the principal is the management account, or
the principal is a service-linked role, or the account is not
enrolled in the organization). Dispatch plumbs the returned slice
straight into IamPolicyEvaluator.
The ordered list puts root-OU-attached policies first, then each descendant OU down to the account’s parent, and account-direct attachments last — the evaluator treats each entry as a separate gate that must allow (intersection), matching AWS SCP semantics.
Required Methods§
Provided Methods§
Sourcefn principal_org(&self, _account_id: &str) -> Option<(String, String)>
fn principal_org(&self, _account_id: &str) -> Option<(String, String)>
aws:PrincipalOrgID and aws:PrincipalOrgPaths for a principal in
account_id: the organization ID and the account’s path
(o-xxx/r-xxx/ou-xxx/.../), or None when the account belongs to no
organization (AWS then omits both keys).
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".