Expand description
Bounded application-supplied read-authorization contracts.
Application identity, roles, sessions, policy storage, and audit remain application concerns. This module owns only synchronous caller/surface decisions before IcyDB request construction.
Structs§
- Read
Authorization Context - Bounded context supplied to an application read-authorization guard.
Enums§
- Read
Authorization Decision - Complete application decision for one generated read invocation.
- Read
Authorization Surface - Generated read surface presented to an application authorization guard.
Constants§
- MAX_
READ_ AUTHORIZATION_ ALLOWLIST_ PRINCIPALS - Maximum principal count accepted by
allowlist.
Functions§
- allowlist
- Decide one read invocation against a fixed bounded principal allowlist.
Type Aliases§
- Read
Authorization Guard - Exact synchronous application guard accepted by generated read endpoints.