Expand description
Validated authorization request, decision, obligation, audit, and gate interfaces.
Structs§
- Actor
Ref - Caller identity with non-empty
kindandid, validated on construction and deserialization. - Allow
AllGate - Permissive gate — every request is allowed with no obligations.
- Audit
Event - Structured audit record emitted once per gate consultation.
- Caller
Enrollment Gate - Immutable caller-enrollment policy for the built-in configuration gate.
- Gate
Context - Per-request context — session, timing, transport source.
- Gate
Request - What the gate sees on every verb invocation.
- Mailbox
Read Gate - Immutable trusted-local owner/reader policy, composed with an existing gate.
Enums§
- Audit
Decision - The outcome field of an
AuditEvent. - Gate
Decision - Gate decision: allow (with optional obligations) or deny (with reason).
- Gate
Error - Errors returned by
crate::Gate::check. - Gate
Validation Error - Validation error for gate wire types.
- Mailbox
Policy Error - Malformed mailbox policy or selector. Labels are exact values, never namespaces.
- Obligation
- Policy instructions attached to an allow; only
Audithas v0 runtime handling. - Operation
Access - Strongest caller-requested effect of a reviewed operation.
Constants§
- CLASSIFIED_
OPERATIONS - Exact reviewed names, including internal handlers and runtime pseudo-verbs. Sorted for lookup; unknown names must remain distinguishable from Write so the production registry census fails when a new handler needs review.
- OPERATION_
CLASSIFIER_ VERSION - Revision of the reviewed classification contract, included in policy identity. Bump whenever a classification or the allowed-read contract changes.
- RUNTIME_
STAMPED_ ACTOR_ KINDS - Kind prefixes reserved by runtime event attribution and its identity fixtures.
Traits§
- Gate
- Authorization gate consulted before each verb dispatch.
Functions§
- check_
with_ mailbox_ policy - Compose ordinary admission with the separate, default-deny mailbox capability.
- classify_
operation - Classify an exact registered or pseudo-verb name. No prefix/category inference.
A restricting gate must deny
None, just as it denies explicit Write. - is_
valid_ mailbox_ actor_ label - Whether an exact mailbox actor label is eligible for explicit selection.
- mailbox_
read_ owner - Validate a read selector and return its owner only for a delegated view.
Type Aliases§
- GateRef
- Shareable handle to a
Gateimpl.