Skip to main content

mobius_gateway/server/
policy.rs

1//! Operator-selected connection and resident-session capacity.
2
3use crate::Result;
4
5mobius::embedded_config! {
6    copy;
7/// Resource policy for accepted connections and active chats.
8#[derive(Debug, Clone, Copy, PartialEq, Eq)]
9pub struct ConnectionPolicy {
10    /// Maximum authenticated connections.
11    pub authenticated: usize,
12    /// Maximum connections still authenticating.
13    pub pre_authentication: usize,
14    /// Deadline covering the complete transport and authentication handshake.
15    pub authentication_timeout_seconds: u64,
16    /// Maximum connected, starting, or running chats.
17    pub active_sessions: usize,
18    /// Maximum unfinished uploads on each connection.
19    pub pending_uploads: usize,
20}
21    defaults = include_str!("policy.toml");
22}
23
24impl ConnectionPolicy {
25    /// Checks resource limits before opening listeners.
26    /// # Errors
27    /// Returns an error for zero limits or values exceeding the process safety budget.
28    pub fn validate(&self) -> Result<()> {
29        for (name, value) in [
30            ("authenticated", self.authenticated),
31            ("pre_authentication", self.pre_authentication),
32            ("active_sessions", self.active_sessions),
33            ("pending_uploads", self.pending_uploads),
34        ] {
35            crate::config::bounded(
36                &format!("connections.{name}"),
37                value,
38                1..=crate::config::MAX_CAPACITY,
39            )?;
40        }
41        crate::config::bounded(
42            "connections.authentication_timeout_seconds",
43            self.authentication_timeout_seconds,
44            1..=3_600,
45        )?;
46        Ok(())
47    }
48
49    pub(super) fn total(&self) -> usize {
50        self.authenticated.saturating_add(self.pre_authentication)
51    }
52}