pub fn validate<'a>(
request: &SnapshotReadRequest<'_>,
observation: &'a SnapshotReadObservation,
) -> Result<SnapshotReadView<'a>, SnapshotReadError>Expand description
Match exact current request/context/target/call bound and snapshot visibility permission.
The caller qualifies input authenticity, actual fresh observations and custody. Public or explicit viewer membership can admit read-only evidence without a controller projection; unknown controllers cannot satisfy the controller path. No status visibility, Root proxy or serialized Proven flag is considered. Policy performs no IO, provider invocation, serialization, journal transitions or scheduling.
ยงErrors
Rejects identity/call mismatches, unobserved necessary controllers and absent caller access.