Skip to main content

khive_gate/
gate.rs

1use std::sync::Arc;
2
3use crate::{ActorRef, GateDecision, GateError, GateRequest};
4
5/// Authorization gate consulted before each verb dispatch.
6///
7/// Implementations return policy denials as decisions and infrastructure failures as errors. See
8/// `crates/khive-gate/docs/api/gate-evaluation.md`.
9/// Request arguments are submitted, pre-handler values. Canonicalization and
10/// kind hooks may rewrite them after this decision; policies requiring the
11/// effective values must be enforced by the handler after normalization.
12pub trait Gate: Send + Sync + std::fmt::Debug {
13    /// Evaluate `req`, returning an allow/deny decision or a backend [`GateError`].
14    fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>;
15
16    /// Evaluate the separate capability to read another actor's mailbox.
17    ///
18    /// Ordinary request admission never grants this capability, including an
19    /// [`AllowAllGate`]. Callers must also retain the result of [`Gate::check`].
20    fn check_mailbox_read(
21        &self,
22        _req: &GateRequest,
23        _owner: &ActorRef,
24    ) -> Result<GateDecision, GateError> {
25        Ok(GateDecision::deny("mailbox_read_not_granted"))
26    }
27
28    /// Return the audit backend name; defaults to `std::any::type_name::<Self>()`.
29    fn impl_name(&self) -> &'static str {
30        std::any::type_name::<Self>()
31    }
32
33    /// Return an opaque, deterministic fingerprint when this gate's policy
34    /// must participate in warm-daemon identity.
35    ///
36    /// The default preserves the legacy identity of programmatically supplied
37    /// gates whose configuration is managed outside khive. Built-in gates with
38    /// construction-baked policy override this so a stale daemon can never
39    /// serve requests under a different policy.
40    fn configuration_fingerprint(&self) -> Option<&str> {
41        None
42    }
43}
44
45/// Shareable handle to a `Gate` impl.
46pub type GateRef = Arc<dyn Gate>;
47
48/// Permissive gate — every request is allowed with no obligations.
49///
50/// This runtime default is for trusted local use. See
51/// `crates/khive-gate/docs/api/gate-evaluation.md`.
52#[derive(Clone, Debug, Default)]
53pub struct AllowAllGate;
54
55impl Gate for AllowAllGate {
56    fn check(&self, _req: &GateRequest) -> Result<GateDecision, GateError> {
57        Ok(GateDecision::allow())
58    }
59
60    fn impl_name(&self) -> &'static str {
61        "AllowAllGate"
62    }
63}