pub struct CallerEnrollmentGate { /* private fields */ }Expand description
Immutable caller-enrollment policy for the built-in configuration gate.
Explicit actors are matched by their resolved actor id. The implicit
anonymous actor is governed separately by grant_unattributed, so a list
entry named local can never accidentally enroll an unattributed caller.
Implementations§
Source§impl CallerEnrollmentGate
impl CallerEnrollmentGate
Sourcepub fn new(
granted_actors: Vec<String>,
grant_unattributed: bool,
) -> CallerEnrollmentGate
pub fn new( granted_actors: Vec<String>, grant_unattributed: bool, ) -> CallerEnrollmentGate
Construct a deterministic enrollment policy.
Sourcepub fn with_write_denials(
granted_actors: Vec<String>,
grant_unattributed: bool,
deny_writes_for: Vec<String>,
) -> CallerEnrollmentGate
pub fn with_write_denials( granted_actors: Vec<String>, grant_unattributed: bool, deny_writes_for: Vec<String>, ) -> CallerEnrollmentGate
Add whole-ID, case-sensitive write restrictions after enrollment.
* matches zero or more characters, including :; every other
character is literal. No segment hierarchy or escape syntax applies.
An anonymous caller admitted by grant_unattributed is restricted if
its fallback ID local matches, independently of attributed enrollment.
Empty restrictions preserve Self::new’s behavior and fingerprint.
Invalid programmatic policy fails every check closed; config-file loaders
should call Self::validate_write_denials to report it before startup.
Sourcepub fn validate_write_denials(
patterns: &[String],
) -> Result<(), GateValidationError>
pub fn validate_write_denials( patterns: &[String], ) -> Result<(), GateValidationError>
Validate the bounded, literal-except-* pattern format without changing it.
Trait Implementations§
Source§impl Clone for CallerEnrollmentGate
impl Clone for CallerEnrollmentGate
Source§fn clone(&self) -> CallerEnrollmentGate
fn clone(&self) -> CallerEnrollmentGate
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for CallerEnrollmentGate
impl Debug for CallerEnrollmentGate
Source§impl Gate for CallerEnrollmentGate
impl Gate for CallerEnrollmentGate
Source§fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>
fn check(&self, req: &GateRequest) -> Result<GateDecision, GateError>
req, returning an allow/deny decision or a backend GateError.Source§fn impl_name(&self) -> &'static str
fn impl_name(&self) -> &'static str
std::any::type_name::<Self>().Source§fn configuration_fingerprint(&self) -> Option<&str>
fn configuration_fingerprint(&self) -> Option<&str>
Source§fn check_mailbox_read(
&self,
_req: &GateRequest,
_owner: &ActorRef,
) -> Result<GateDecision, GateError>
fn check_mailbox_read( &self, _req: &GateRequest, _owner: &ActorRef, ) -> Result<GateDecision, GateError>
Auto Trait Implementations§
impl Freeze for CallerEnrollmentGate
impl RefUnwindSafe for CallerEnrollmentGate
impl Send for CallerEnrollmentGate
impl Sync for CallerEnrollmentGate
impl Unpin for CallerEnrollmentGate
impl UnsafeUnpin for CallerEnrollmentGate
impl UnwindSafe for CallerEnrollmentGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more