Skip to main content

validate

Function validate 

Source
pub fn validate<'a>(
    request: &ControlObservationRequest<'_>,
    observation: &'a ControlObservation,
) -> Result<ControlAuthorityView<'a>, ControlAuthorityError>
Expand description

Match current request/context/target/call bound and exact caller-controller membership.

The caller qualifies actual provider authenticity, freshness and coherent custody. Policy performs no IO, record serialization, journal transition or scheduling. Other controllers, public/read visibility, Root paths and subnet-admin exceptions never substitute for the selected caller. Load still needs qualified snapshot-origin permissions and same-ID safety; controller membership is only one preflight component.

ยงErrors

Rejects changed request/context/target, excess calls and missing exact caller control.