What a provider requires to answer one (realm, procedure): open (any
identified caller, the default) or UCAN-gated (the caller’s token must
verify against required_issuer). Mirrors macula_station_link.erl’s
own policy shape exactly — open | {ucan_required, Issuer} — where
Issuer there is the 32-byte Ed25519 public key the gate checks the
token’s signature against, not a DID string (the reference code passes
it straight to macula_ucan_nif:verify/2, whose second argument is a
raw public key).
Gating happens BEFORE a handler runs — see
crate::connection::Session::serve_one_call_gated — so a rejected
caller never reaches business logic, and an accepted caller’s handler
never sees the raw token either; the policy layer already did the only
thing that mattered with it.
Builds a UCAN-gated policy: a caller must present a token that
verifies (signature, exp, nbf) against issuer_public_key.
Equivalent to Erlang’s {ucan_required, issuer_public_key}.
Applies this policy to an inbound CALL’s ucan_token, returning
Ok(()) if the call is authorized to proceed to lookup/dispatch.
An open policy always passes; a gated policy requires ucan_token
to verify against required_issuer.