Skip to main content

Gate

Trait Gate 

Source
pub trait Gate:
    Send
    + Sync
    + Debug {
    // Required method
    fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>;

    // Provided methods
    fn check_mailbox_read(
        &self,
        _req: &GateRequest,
        _owner: &ActorRef,
    ) -> Result<GateDecision, GateError> { ... }
    fn impl_name(&self) -> &'static str { ... }
    fn configuration_fingerprint(&self) -> Option<&str> { ... }
}
Expand description

Authorization gate consulted before each verb dispatch.

Implementations return policy denials as decisions and infrastructure failures as errors. See crates/khive-gate/docs/api/gate-evaluation.md. Request arguments are submitted, pre-handler values. Canonicalization and kind hooks may rewrite them after this decision; policies requiring the effective values must be enforced by the handler after normalization.

Required Methods§

Source

fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>

Evaluate req, returning an allow/deny decision or a backend GateError.

Provided Methods§

Source

fn check_mailbox_read( &self, _req: &GateRequest, _owner: &ActorRef, ) -> Result<GateDecision, GateError>

Evaluate the separate capability to read another actor’s mailbox.

Ordinary request admission never grants this capability, including an AllowAllGate. Callers must also retain the result of Gate::check.

Source

fn impl_name(&self) -> &'static str

Return the audit backend name; defaults to std::any::type_name::<Self>().

Source

fn configuration_fingerprint(&self) -> Option<&str>

Return an opaque, deterministic fingerprint when this gate’s policy must participate in warm-daemon identity.

The default preserves the legacy identity of programmatically supplied gates whose configuration is managed outside khive. Built-in gates with construction-baked policy override this so a stale daemon can never serve requests under a different policy.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§