Skip to main content

RoleDef

Struct RoleDef 

Source
pub struct RoleDef {
    pub name: String,
    pub keys: Vec<String>,
    pub labels: Vec<String>,
    pub visible_where: Option<PropPredicate>,
    pub namespaces: Option<Vec<String>>,
    pub write: Option<WriteScope>,
}
Expand description

A named RBAC role: resolves to a node-visibility mask at query time.

keys and labels both default to empty when absent from JSON, so a schema snippet that names only labels is valid.

The resolved mask is the union of:

  • all nodes whose key appears in keys (unknown keys silently ignored), and
  • all nodes carrying any label in labels (resolved live against the current graph — new nodes of an allowed label are immediately visible without re-applying the schema).

An empty union (no keys, no matching label nodes) = empty mask = sees nothing.

write: None (or absent from JSON) = read-only role, v1 behavior, backward compatible with any client that does not know about write scopes.

Fields§

§name: String§keys: Vec<String>

Explicit node keys always visible to the role.

§labels: Vec<String>

All nodes carrying any of these labels are visible (resolved live).

§visible_where: Option<PropPredicate>

Optional property test that narrows the label leg only.

Absent = the role is exactly what it was before version 3: every node of an allowed label. Present = a node of an allowed label is visible only when it also passes the predicate. keys is an administrative grant and is never narrowed by it.

A predicate with no labels is refused at apply_schema: it would narrow nothing, and silently granting the key leg under a name that reads like a restriction is the wrong way to be wrong.

§namespaces: Option<Vec<String>>

Namespaces this role may read.

Absent = unscoped, which is exactly the behaviour every role had before version 4, so no existing role changes meaning. Some(list) restricts:

visible = ( keys ∪ { n : label(n) ∈ labels ∧ visible_where(n) } )
          ∩ { n : ns(n) ∈ namespaces }

The namespace leg intersects keys too, unlike visible_where, which narrows only the label leg. A namespace is a tenancy boundary, and an explicitly named key in another tenant’s namespace is a mistake rather than an administrative grant — apply_schema rejects a role whose keys name a live node outside its namespaces, naming both the key and its namespace.

Some([]) is rejected at apply time: a role that sees nothing is written by omitting keys and labels, not by closing the namespace leg.

§write: Option<WriteScope>

Absent or null = read-only role (v1 behavior, backward compatible).

Implementations§

Source§

impl RoleDef

Source

pub fn sees_namespace(&self, namespace: &str) -> bool

Whether namespace is inside this role’s namespace binding.

true for every namespace when the role is unscoped — absent namespaces means the intersection is skipped entirely.

Trait Implementations§

Source§

impl Clone for RoleDef

Source§

fn clone(&self) -> RoleDef

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for RoleDef

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for RoleDef

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl PartialEq for RoleDef

Source§

fn eq(&self, other: &RoleDef) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for RoleDef

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for RoleDef

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> ArchivePointee for T

Source§

type ArchivedMetadata = ()

The archived version of the pointer metadata for this type.
Source§

fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata

Converts some archived metadata to the pointer metadata for itself.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> LayoutRaw for T

Source§

fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>

Returns the layout of the type.
Source§

impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
where T: SharedNiching<N1, N2>, N1: Niching<T>, N2: Niching<T>,

Source§

unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool

Returns whether the given value has been niched. Read more
Source§

fn resolve_niched(out: Place<NichedOption<T, N1>>)

Writes data to out indicating that a T is niched.
Source§

impl<T> Pointee for T

Source§

type Metadata = ()

The metadata type for pointers and references to this type.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.