Skip to main content

Module policy

Module policy 

Source
Expand description

Deployment namespace and write policy (SPEC-TRANSPORT-CONNECT §7.5).

Structs§

AcceptedSchemes
The owner schemes a deployment accepts, as advertised in GetServerInfo’s grant_schemes (§4). A statement signed under any other scheme fails verification.
GrantConfig
Grant verification settings for a Multi/Owner deployment.
GrantSettings
A deployment’s validated write-grant inputs, kept apart from the GrantConfig built from them so an adapter’s configuration can be compared and re-built (a GrantConfig holds no equality).
RefPolicy
The deployment’s ref rules (crate::pipeline::PipelineConfig::ref_policy).
RefRule
One rule: every ref its pattern matches. Overlapping rules all apply.
RelyingParty
A WebAuthn relying party a deployment accepts webauthn-p256 assertions for (§4.3 rule 4): its id, whose SHA-256 the authenticator puts in authenticatorData, and the origins a clientDataJSON from it may name.

Enums§

AuthorizerRole
How the authorizer composes with built-in policy (SPEC-SERVER §6.2, SPEC-TRANSPORT-CONNECT §7.5). Neither role overrides namespace denial.
NamespacePolicy
Namespaces served for writes (SPEC-TRANSPORT-CONNECT §7.5). A denial cannot be overridden by an authorizer (SPEC-SERVER §6.2).
WritePolicy
Write authorization policy (SPEC-TRANSPORT-CONNECT §7.5). Hooks compose with this policy under SPEC-SERVER §6.2.

Functions§

parse_grant_schemes
Parse the accepted owner schemes (--grant-schemes, the Worker GRANT_SCHEMES var): comma-separated SPEC-WRITE-GRANTS §4 tokens. The value must not be blank and may not contain a blank entry. Which tokens exist is mkit-attest’s to say.
parse_namespace_allowlist
Parse a namespace allowlist file (the native --namespace-allowlist file and the Worker NAMESPACE_ALLOWLIST var): namespaces separated by newlines or commas, each in its canonical form (ed25519-<64 hex> or 0x<40 hex>). # starts a comment that runs to the end of its line; blank entries are ignored. The file is security configuration, not a secret.
parse_relying_parties
Parse the Worker WEBAUTHN_RPS var: entries (parse_relying_party) separated by ; or newlines. A blank entry and a duplicate id are refused, so a stray separator never silently drops a relying party.
parse_relying_party
Parse one relying-party entry, id=origin[,origin...], split on the first = (origins never contain a bare = before their id ends, but may contain one later, for example in a query-like native-app origin). The id and origin rules are mkit-attest’s (RelyingParty::new).