Skip to main content

Module guards

Module guards 

Source
Expand description

Bounded application-supplied read-authorization contracts.

Application identity, roles, sessions, policy storage, and audit remain application concerns. This module owns only synchronous caller/surface decisions before IcyDB request construction.

Structs§

ReadAuthorizationContext
Bounded context supplied to an application read-authorization guard.

Enums§

ReadAuthorizationDecision
Complete application decision for one generated read invocation.
ReadAuthorizationSurface
Generated read surface presented to an application authorization guard.

Constants§

MAX_READ_AUTHORIZATION_ALLOWLIST_PRINCIPALS
Maximum principal count accepted by allowlist.

Functions§

allowlist
Decide one read invocation against a fixed bounded principal allowlist.

Type Aliases§

ReadAuthorizationGuard
Exact synchronous application guard accepted by generated read endpoints.