Skip to main content

Crate khive_gate

Crate khive_gate 

Source
Expand description

Validated authorization request, decision, obligation, audit, and gate interfaces.

Structs§

ActorRef
Caller identity with non-empty kind and id, validated on construction and deserialization.
AllowAllGate
Permissive gate — every request is allowed with no obligations.
AuditEvent
Structured audit record emitted once per gate consultation.
CallerEnrollmentGate
Immutable caller-enrollment policy for the built-in configuration gate.
GateContext
Per-request context — session, timing, transport source.
GateRequest
What the gate sees on every verb invocation.
MailboxReadGate
Immutable trusted-local owner/reader policy, composed with an existing gate.

Enums§

AuditDecision
The outcome field of an AuditEvent.
GateDecision
Gate decision: allow (with optional obligations) or deny (with reason).
GateError
Errors returned by crate::Gate::check.
GateValidationError
Validation error for gate wire types.
MailboxPolicyError
Malformed mailbox policy or selector. Labels are exact values, never namespaces.
Obligation
Policy instructions attached to an allow; only Audit has v0 runtime handling.
OperationAccess
Strongest caller-requested effect of a reviewed operation.

Constants§

CLASSIFIED_OPERATIONS
Exact reviewed names, including internal handlers and runtime pseudo-verbs. Sorted for lookup; unknown names must remain distinguishable from Write so the production registry census fails when a new handler needs review.
OPERATION_CLASSIFIER_VERSION
Revision of the reviewed classification contract, included in policy identity. Bump whenever a classification or the allowed-read contract changes.
RUNTIME_STAMPED_ACTOR_KINDS
Kind prefixes reserved by runtime event attribution and its identity fixtures.

Traits§

Gate
Authorization gate consulted before each verb dispatch.

Functions§

check_with_mailbox_policy
Compose ordinary admission with the separate, default-deny mailbox capability.
classify_operation
Classify an exact registered or pseudo-verb name. No prefix/category inference. A restricting gate must deny None, just as it denies explicit Write.
is_valid_mailbox_actor_label
Whether an exact mailbox actor label is eligible for explicit selection.
mailbox_read_owner
Validate a read selector and return its owner only for a delegated view.

Type Aliases§

GateRef
Shareable handle to a Gate impl.