pub struct RoleDef {
pub name: String,
pub keys: Vec<String>,
pub labels: Vec<String>,
pub visible_where: Option<PropPredicate>,
pub namespaces: Option<Vec<String>>,
pub write: Option<WriteScope>,
}Expand description
A named RBAC role: resolves to a node-visibility mask at query time.
keys and labels both default to empty when absent from JSON, so a
schema snippet that names only labels is valid.
The resolved mask is the union of:
- all nodes whose key appears in
keys(unknown keys silently ignored), and - all nodes carrying any label in
labels(resolved live against the current graph — new nodes of an allowed label are immediately visible without re-applying the schema).
An empty union (no keys, no matching label nodes) = empty mask = sees nothing.
write: None (or absent from JSON) = read-only role, v1 behavior, backward
compatible with any client that does not know about write scopes.
Fields§
§name: String§keys: Vec<String>Explicit node keys always visible to the role.
labels: Vec<String>All nodes carrying any of these labels are visible (resolved live).
visible_where: Option<PropPredicate>Optional property test that narrows the label leg only.
Absent = the role is exactly what it was before version 3: every node of
an allowed label. Present = a node of an allowed label is visible only
when it also passes the predicate. keys is an administrative grant and
is never narrowed by it.
A predicate with no labels is refused at apply_schema: it would narrow
nothing, and silently granting the key leg under a name that reads like
a restriction is the wrong way to be wrong.
namespaces: Option<Vec<String>>Namespaces this role may read.
Absent = unscoped, which is exactly the behaviour every role had before
version 4, so no existing role changes meaning. Some(list) restricts:
visible = ( keys ∪ { n : label(n) ∈ labels ∧ visible_where(n) } )
∩ { n : ns(n) ∈ namespaces }The namespace leg intersects keys too, unlike
visible_where, which narrows only the label leg.
A namespace is a tenancy boundary, and an explicitly named key in another
tenant’s namespace is a mistake rather than an administrative grant —
apply_schema rejects a role whose keys name a live node outside its
namespaces, naming both the key and its namespace.
Some([]) is rejected at apply time: a role that sees nothing is written
by omitting keys and labels, not by closing the namespace leg.
write: Option<WriteScope>Absent or null = read-only role (v1 behavior, backward compatible).
Implementations§
Trait Implementations§
Source§impl<'de> Deserialize<'de> for RoleDef
impl<'de> Deserialize<'de> for RoleDef
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl StructuralPartialEq for RoleDef
Auto Trait Implementations§
impl Freeze for RoleDef
impl RefUnwindSafe for RoleDef
impl Send for RoleDef
impl Sync for RoleDef
impl Unpin for RoleDef
impl UnsafeUnpin for RoleDef
impl UnwindSafe for RoleDef
Blanket Implementations§
Source§impl<T> ArchivePointee for T
impl<T> ArchivePointee for T
Source§type ArchivedMetadata = ()
type ArchivedMetadata = ()
Source§fn pointer_metadata(
_: &<T as ArchivePointee>::ArchivedMetadata,
) -> <T as Pointee>::Metadata
fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> LayoutRaw for T
impl<T> LayoutRaw for T
Source§fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
Source§impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
Source§unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
Source§fn resolve_niched(out: Place<NichedOption<T, N1>>)
fn resolve_niched(out: Place<NichedOption<T, N1>>)
out indicating that a T is niched.