Expand description
Deployment namespace and write policy (SPEC-TRANSPORT-CONNECT §7.5).
Structs§
- Accepted
Schemes - The owner schemes a deployment accepts, as advertised in
GetServerInfo’sgrant_schemes(§4). A statement signed under any other scheme fails verification. - Grant
Config - Grant verification settings for a Multi/Owner deployment.
- Grant
Settings - A deployment’s validated write-grant inputs, kept apart from the
GrantConfigbuilt from them so an adapter’s configuration can be compared and re-built (aGrantConfigholds no equality). - RefPolicy
- The deployment’s ref rules (
crate::pipeline::PipelineConfig::ref_policy). - RefRule
- One rule: every ref its pattern matches. Overlapping rules all apply.
- Relying
Party - A
WebAuthnrelying party a deployment acceptswebauthn-p256assertions for (§4.3 rule 4): its id, whose SHA-256 the authenticator puts inauthenticatorData, and the origins aclientDataJSONfrom it may name.
Enums§
- Authorizer
Role - How the authorizer composes with built-in policy (SPEC-SERVER §6.2, SPEC-TRANSPORT-CONNECT §7.5). Neither role overrides namespace denial.
- Namespace
Policy - Namespaces served for writes (SPEC-TRANSPORT-CONNECT §7.5). A denial cannot be overridden by an authorizer (SPEC-SERVER §6.2).
- Write
Policy - Write authorization policy (SPEC-TRANSPORT-CONNECT §7.5). Hooks compose with this policy under SPEC-SERVER §6.2.
Functions§
- parse_
grant_ schemes - Parse the accepted owner schemes (
--grant-schemes, the WorkerGRANT_SCHEMESvar): comma-separated SPEC-WRITE-GRANTS §4 tokens. The value must not be blank and may not contain a blank entry. Which tokens exist ismkit-attest’s to say. - parse_
namespace_ allowlist - Parse a namespace allowlist file (the native
--namespace-allowlistfile and the WorkerNAMESPACE_ALLOWLISTvar): namespaces separated by newlines or commas, each in its canonical form (ed25519-<64 hex>or0x<40 hex>).#starts a comment that runs to the end of its line; blank entries are ignored. The file is security configuration, not a secret. - parse_
relying_ parties - Parse the Worker
WEBAUTHN_RPSvar: entries (parse_relying_party) separated by;or newlines. A blank entry and a duplicate id are refused, so a stray separator never silently drops a relying party. - parse_
relying_ party - Parse one relying-party entry,
id=origin[,origin...], split on the first=(origins never contain a bare=before their id ends, but may contain one later, for example in a query-like native-app origin). The id and origin rules aremkit-attest’s (RelyingParty::new).