pub struct SubscriptionState {
pub manager: Arc<SubscriptionManager>,
pub lifecycle: Arc<dyn SubscriptionLifecycle>,
pub max_subscriptions_per_connection: Option<u32>,
pub remote_subscription_fields: Arc<HashMap<String, String>>,
pub domain_registry: Option<Arc<DomainRegistry>>,
pub strict_tenant_validation: bool,
pub authorizer: Option<Arc<dyn Authorizer>>,
pub tenant_status_source: Option<Arc<dyn TenantStatusSource>>,
pub subscription_policies: Arc<HashMap<String, SubscriptionPolicy>>,
pub live_subscription_policies: Option<LiveSubscriptionPolicies>,
pub identity_resolver: Option<Arc<IdentityResolver>>,
pub service_account_authenticator: Option<Arc<ServiceAccountAuthenticator>>,
}Expand description
State for subscription WebSocket handler.
Fields§
§manager: Arc<SubscriptionManager>Subscription manager.
lifecycle: Arc<dyn SubscriptionLifecycle>Lifecycle hooks.
max_subscriptions_per_connection: Option<u32>Maximum subscriptions per connection (None = unlimited).
remote_subscription_fields: Arc<HashMap<String, String>>Subscription fields owned by remote subgraphs.
Maps root subscription field name to the subgraph WebSocket URL.
Empty when federation is disabled or no remote subscription fields are declared.
domain_registry: Option<Arc<DomainRegistry>>Host-header → tenant-key domain registry. None until a host binary
installs one (mirrors AppState::domain_registry).
strict_tenant_validation: boolReject conflicting tenant sources (JWT vs X-Tenant-ID vs Host) on the
upgrade. Driven by schema.has_rls_configured(), mirroring the GraphQL
handler’s strict tenant validation.
Optional operation-level authorizer (#422). When set, each subscription is
authorized at establishment with OperationKind::Subscription, the
subscription field name, and the connection’s principal. None until a host
binary installs one (from Executor::config().authorizer).
tenant_status_source: Option<Arc<dyn TenantStatusSource>>Optional tenant-status source (M-tenant-ws-suspended). When set, a new
subscription whose resolved tenant is suspended is rejected, and event
delivery to a connection whose tenant is suspended is paused. None until
a host binary installs a multi-tenant registry.
subscription_policies: Arc<HashMap<String, SubscriptionPolicy>>Per-subscription-field row-visibility policies (#596), keyed by subscription
field name, resolved at mount time from the target entity’s compiled
subscription_policy. A subscription named here derives a server-owned owner
condition from the connection’s enriched identity at subscribe time — fail-closed
when the identity is unresolvable. A subscription with no policy keeps today’s
behavior (no back-compat break).
live_subscription_policies: Option<LiveSubscriptionPolicies>#611: live row-visibility policy source. When set (installed at mount from the
reload-aware executor ArcSwap), each new subscription is evaluated against the
current schema’s policies, so a policy added or tightened by a hot-reload takes
effect on the next subscribe rather than only on restart. None falls back to the
mount-time subscription_policies snapshot — the behavior tests and hosts that do
not wire a live source keep. Already-connected subscriptions keep their subscribe-time
boundary until they reconnect (layer-2, deferred; #611).
identity_resolver: Option<Arc<IdentityResolver>>Enriched-identity resolver (#539). When set, the connection’s SecurityContext
is enriched at subscribe time (only for policy-declaring subscriptions) so the
fraiseql.enriched.* owner field is server-resolved, never client-asserted.
None disables enrichment — a policy-declaring subscription then fails closed.
service_account_authenticator: Option<Arc<ServiceAccountAuthenticator>>Service-account authenticator (ADR-0018). Lets a daemon authenticate the /ws
upgrade with its secret on the api-key header — the same seam the GraphQL path
uses — so a service principal can hold a policy-scoped subscription.
Implementations§
Source§impl SubscriptionState
impl SubscriptionState
Sourcepub fn new(manager: Arc<SubscriptionManager>) -> Self
pub fn new(manager: Arc<SubscriptionManager>) -> Self
Create new subscription state.
Sourcepub fn with_subscription_policies(
self,
policies: Arc<HashMap<String, SubscriptionPolicy>>,
) -> Self
pub fn with_subscription_policies( self, policies: Arc<HashMap<String, SubscriptionPolicy>>, ) -> Self
Install the per-subscription row-visibility policies (#596). Typically built by
build_subscription_policies from the compiled schema at mount time. Used as the
fallback when no live source (with_live_subscription_policies) is installed.
Sourcepub fn with_live_subscription_policies(
self,
live: Option<LiveSubscriptionPolicies>,
) -> Self
pub fn with_live_subscription_policies( self, live: Option<LiveSubscriptionPolicies>, ) -> Self
Install the live row-visibility policy source (#611). When set, each new subscription
is evaluated against the current schema’s policies, so a hot-reloaded policy applies
on the next subscribe rather than only on restart. None keeps the mount-time
snapshot behavior.
Sourcepub fn with_service_account_authenticator(
self,
authenticator: Option<Arc<ServiceAccountAuthenticator>>,
) -> Self
pub fn with_service_account_authenticator( self, authenticator: Option<Arc<ServiceAccountAuthenticator>>, ) -> Self
Install the service-account authenticator (ADR-0018) so a daemon can authenticate
the /ws upgrade with its secret on the api-key header.
Sourcepub fn with_identity_resolver(
self,
resolver: Option<Arc<IdentityResolver>>,
) -> Self
pub fn with_identity_resolver( self, resolver: Option<Arc<IdentityResolver>>, ) -> Self
Install the enriched-identity resolver (#539) used to derive row-visibility owner
boundaries at subscribe time. None leaves policy-declaring subscriptions
fail-closed (refused).
Sourcepub fn with_tenant_status_source(
self,
source: Option<Arc<dyn TenantStatusSource>>,
) -> Self
pub fn with_tenant_status_source( self, source: Option<Arc<dyn TenantStatusSource>>, ) -> Self
Install the tenant-status source (M-tenant-ws-suspended). When set, new
subscriptions for a suspended tenant are rejected and event delivery to a
suspended tenant is paused. Typically the TenantExecutorRegistry.
Install the operation-level authorizer (#422). When set, every subscription is
authorized at establishment; a Deny (or any policy error) rejects the
subscription with a FORBIDDEN GraphQL-WS error. Typically populated from
Executor::config().authorizer.
Sourcepub fn with_tenant_context(
self,
domain_registry: Arc<DomainRegistry>,
strict_tenant_validation: bool,
) -> Self
pub fn with_tenant_context( self, domain_registry: Arc<DomainRegistry>, strict_tenant_validation: bool, ) -> Self
Install the tenant-resolution context — the Host-header domain registry
and strict-validation flag — so the subscription upgrade dispatches the
tenant key the same way the GraphQL handler does (JWT tenant_id >
X-Tenant-ID header > Host domain, with cross-source conflict rejection
when strict_tenant_validation is set). See
crate::routes::graphql::TenantKeyResolver.
Sourcepub fn with_lifecycle(self, lifecycle: Arc<dyn SubscriptionLifecycle>) -> Self
pub fn with_lifecycle(self, lifecycle: Arc<dyn SubscriptionLifecycle>) -> Self
Set lifecycle hooks.
Sourcepub const fn with_max_subscriptions(self, max: Option<u32>) -> Self
pub const fn with_max_subscriptions(self, max: Option<u32>) -> Self
Set maximum subscriptions per connection.
Sourcepub fn with_remote_subscription_fields(
self,
fields: HashMap<String, String>,
) -> Self
pub fn with_remote_subscription_fields( self, fields: HashMap<String, String>, ) -> Self
Set remote subscription fields (federation passthrough).
Maps subscription field names to the owning subgraph’s WebSocket URL.
Trait Implementations§
Source§impl Clone for SubscriptionState
impl Clone for SubscriptionState
Source§fn clone(&self) -> SubscriptionState
fn clone(&self) -> SubscriptionState
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl !RefUnwindSafe for SubscriptionState
impl !UnwindSafe for SubscriptionState
impl Freeze for SubscriptionState
impl Send for SubscriptionState
impl Sync for SubscriptionState
impl Unpin for SubscriptionState
impl UnsafeUnpin for SubscriptionState
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more