RPC-only check client (CheckService + NamespaceService). It has no session
resolution; for HTTP middleware combine it with a
session::SessionResolver (see the axum module’s AuthState).
Result of CheckClient::content_change_check: whether the subject may
modify content, and the evaluation snapshot zookie to store with the new
content version.
Result of CheckClient::expand: the evaluation snapshot zookie, the
flattened leaf user ids, whether a public wildcard holds the relation, and
the usersets left opaque (e.g. ... parent pointers or references the
server could not resolve).
Result of CheckClient::list: the evaluation snapshot zookie and the
objects on which the subject holds the relation. Pass ts to a subsequent
check/list/read for a consistent snapshot.
Result of CheckClient::read: the evaluation snapshot zookie and the
raw stored tuples matching the filters. Rewrite rules are not applied —
use CheckClient::expand for the effective userset.
One Watch stream message. ts is the watermark: every change with commit
ts <= ts has been delivered. Empty updates is a heartbeat. A non-empty
batch is one atomic write committed at ts — never split across messages —
so any ts is a safe resume point (exclusive) for a later Watch.
Opens a gRPC channel with HTTP/2 keepalive (30s interval, 10s timeout,
pings while idle) so idle connections survive L4 idle-eviction (IPVS,
cloud LBs, NAT — nio #239). Used for both the check and the session
endpoint; pass None for an insecure channel (local dev only).