pub struct Scope { /* private fields */ }Expand description
A read scope: what a handle may see, as a descriptor rather than a mask.
A Scope names its legs — a role, a namespace, an explicit key allow-list —
and resolves them to a NodeMask per read. It is the live-read
analogue of AsOfScope, and resolves its role leg
through the same GraphDb::mask_for_role, so a role name means one thing
on both.
§Never widens
Present legs are intersected; an absent leg contributes nothing. A scope
with no legs at all is refused by Scope::new rather than treated as
unscoped — an empty scope must never be the accident that widens a caller to
everything.
§Never stale
Resolution happens on every read, not once at construction. The role leg
goes through RoleMaskCache, keyed on commit_seq; the keys leg is
cached on this Scope under a [StoreStamp], which is commit_seq plus
the identity of the store that commit belongs to — a Scope is the caller’s
and can be carried to another store or held across a reload, neither of
which a sequence number can detect. Either way a read after a write
rebuilds, so a scoped handle held across a write cannot serve the allow-list
it had before — a key created since is visible, a key deleted since is not.
That is a security property, not a freshness nicety.
Mode is hard-coded MaskMode::Omit. MaskMode::Stub discloses node
existence and belongs only to full-token client masks.
Implementations§
Source§impl Scope
impl Scope
Sourcepub fn new(
role: Option<String>,
namespace: Option<String>,
keys: Option<Vec<String>>,
) -> Result<Scope>
pub fn new( role: Option<String>, namespace: Option<String>, keys: Option<Vec<String>>, ) -> Result<Scope>
Build a scope from the legs that are present.
At least one leg is required: Scope::new(None, None, None) is
GraphError::QueryError, never
an unscoped handle.
keys: Some(vec![]) is a leg — it narrows to nothing, which is safe.
An unknown role is not detected here; it surfaces from
Scope::resolve, which is where a store exists to check it against.
Sourcepub fn resolve<F: Fs>(&self, db: &GraphDb<F>) -> Result<NodeMask>
pub fn resolve<F: Fs>(&self, db: &GraphDb<F>) -> Result<NodeMask>
Resolve every present leg against db and intersect the results.
Returns Err when a role leg names no defined role, or when
roles.json was corrupt at open — the same refusals
GraphDb::mask_for_role makes, unchanged.
Sourcepub fn intersect(&self, other: &Scope) -> Scope
pub fn intersect(&self, other: &Scope) -> Scope
Return a scope seeing only what both self and other see.
Legs accumulate rather than replace: two role legs are both resolved and intersected, and two key lists are intersected as strings. The result starts with a cold cache, which costs one rebuild and cannot be wrong.
Trait Implementations§
Source§impl Clone for Scope
impl Clone for Scope
Source§fn clone(&self) -> Scope
fn clone(&self) -> Scope
Carries the resolved keys leg across, cache included: it is stamped
with the store and the commit it was built against, so a clone can serve
it only against that same store while that commit is still current.
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl !Freeze for Scope
impl RefUnwindSafe for Scope
impl Send for Scope
impl Sync for Scope
impl Unpin for Scope
impl UnsafeUnpin for Scope
impl UnwindSafe for Scope
Blanket Implementations§
Source§impl<T> ArchivePointee for T
impl<T> ArchivePointee for T
Source§type ArchivedMetadata = ()
type ArchivedMetadata = ()
Source§fn pointer_metadata(
_: &<T as ArchivePointee>::ArchivedMetadata,
) -> <T as Pointee>::Metadata
fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> LayoutRaw for T
impl<T> LayoutRaw for T
Source§fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
Source§impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
Source§unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
Source§fn resolve_niched(out: Place<NichedOption<T, N1>>)
fn resolve_niched(out: Place<NichedOption<T, N1>>)
out indicating that a T is niched.