pub struct CallerEnrollmentGate { /* private fields */ }Expand description
Immutable caller-enrollment policy for the built-in configuration gate.
Explicit actors are matched by their resolved actor id. The implicit
anonymous actor is governed separately by grant_unattributed, so a list
entry named local can never accidentally enroll an unattributed caller.
Implementations§
Source§impl CallerEnrollmentGate
impl CallerEnrollmentGate
Sourcepub fn new(granted_actors: Vec<String>, grant_unattributed: bool) -> Self
pub fn new(granted_actors: Vec<String>, grant_unattributed: bool) -> Self
Construct a deterministic enrollment policy.
Sourcepub fn with_write_denials(
granted_actors: Vec<String>,
grant_unattributed: bool,
deny_writes_for: Vec<String>,
) -> Self
pub fn with_write_denials( granted_actors: Vec<String>, grant_unattributed: bool, deny_writes_for: Vec<String>, ) -> Self
Add whole-ID, case-sensitive write restrictions after enrollment.
* matches zero or more characters, including :; every other
character is literal. No segment hierarchy or escape syntax applies.
An anonymous caller admitted by grant_unattributed is restricted if
its fallback ID local matches, independently of attributed enrollment.
Empty restrictions preserve Self::new’s behavior and fingerprint.
Invalid programmatic policy fails every check closed; config-file loaders
should call Self::validate_write_denials to report it before startup.
Sourcepub fn validate_write_denials(
patterns: &[String],
) -> Result<(), GateValidationError>
pub fn validate_write_denials( patterns: &[String], ) -> Result<(), GateValidationError>
Validate the bounded, literal-except-* pattern format without changing it.
Trait Implementations§
Source§impl Clone for CallerEnrollmentGate
impl Clone for CallerEnrollmentGate
Source§impl Debug for CallerEnrollmentGate
impl Debug for CallerEnrollmentGate
Source§impl Gate for CallerEnrollmentGate
impl Gate for CallerEnrollmentGate
Source§fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>
fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>
req, returning an allow/deny decision or a backend GateError.Source§fn impl_name(&self) -> &'static str
fn impl_name(&self) -> &'static str
std::any::type_name::<Self>().