pub struct RunAs {
pub roles: Vec<String>,
pub scopes: Vec<String>,
pub tenant: Option<String>,
}Expand description
The least-privilege authority ceiling a function’s fraiseql_query bridge
writes run under (#594) — the function’s run_as.
This is the same authority model scheduled sources use
([fraiseql_core::schema::RunAs], docs/architecture/sources.md:88-109), applied
to event-dispatched functions: a ceiling the function can never exceed. A
FunctionDefinition with no run_as runs fail-closed — its host’s
fraiseql_query executes under an anonymous system_job identity with no
roles/scopes/tenant, so RLS and field-authorization deny every write until an
operator grants a ceiling. Granting authority is a deliberate act, never a
default.
It is a distinct type from the core RunAs so the base fraiseql-functions
crate (used by the CLI, codegen, and authoring) need not depend on
fraiseql-core; the two share an identical JSON shape and the wiring layer
(host-live) converts to a SecurityContext via [FunctionDefinition::identity].
Fields§
§roles: Vec<String>Roles granted to the function’s background write identity (the RBAC ceiling).
scopes: Vec<String>Scopes granted to the function’s background write identity.
tenant: Option<String>The single tenant this function’s bridge writes are scoped to, if any. Unset ⇒ global/system (NULL tenant).
Trait Implementations§
Source§impl<'de> Deserialize<'de> for RunAs
impl<'de> Deserialize<'de> for RunAs
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for RunAs
impl StructuralPartialEq for RunAs
Auto Trait Implementations§
impl Freeze for RunAs
impl RefUnwindSafe for RunAs
impl Send for RunAs
impl Sync for RunAs
impl Unpin for RunAs
impl UnsafeUnpin for RunAs
impl UnwindSafe for RunAs
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more