Skip to main content

Crate nio_client

Crate nio_client 

Source

Modules§

auth
memo
Request-scoped memoization of check and list decisions — the port of nioclient-go’s request memo (option 1 of the client-cache design).
session
Token -> principal resolution with an L1 cache tier — the port of the normative resolver in nio’s check_client/src/session.rs (issue #243/#245).

Structs§

CheckClient
RPC-only check client (CheckService + NamespaceService). It has no session resolution; for HTTP middleware combine it with a session::SessionResolver (see the axum module’s AuthState).
ConnectError
ContentChangeCheckResult
Result of CheckClient::content_change_check: whether the subject may modify content, and the evaluation snapshot zookie to store with the new content version.
ExpandResult
Result of CheckClient::expand: the evaluation snapshot zookie, the flattened leaf user ids, whether a public wildcard holds the relation, and the usersets left opaque (e.g. ... parent pointers or references the server could not resolve).
ListResult
Result of CheckClient::list: the evaluation snapshot zookie and the objects on which the subject holds the relation. Pass ts to a subsequent check/list/read for a consistent snapshot.
Namespace
Ns is a collection of objects.
NamespaceMeta
Schema metadata for one namespace loaded by check.
Obj
Obj is an object.
ParseError
ReadFilter
One TupleSet filter for the Read API (paper §2.4.2 / §2.4.3). Build with ReadFilter::by_object, ReadFilter::by_user, or ReadFilter::by_user_set.
ReadResult
Result of CheckClient::read: the evaluation snapshot zookie and the raw stored tuples matching the filters. Rewrite rules are not applied — use CheckClient::expand for the effective userset.
Rel
Rel is a relation (or computed permission) on an object.
RelationMeta
Schema metadata for one relation (name + rewrite kind). kind is one of this | computed | tuple_to | union.
Timestamp
Opaque client-side zookie. Wire value is standard Base64 of [epoch:u8][millis:u48 BE] (7 bytes). Treat as opaque: store and echo only; do not invent.
Tuple
A relationship edge for Write (add or delete) and Read results.
UserId
UserId is a principal’s ID: a positive 64-bit integer (nio #301).
UserSet
UserSet names the set of users holding rel on ⟨ns, obj⟩.
WatchEvent
One Watch stream message. ts is the watermark: every change with commit ts <= ts has been delivered. Empty updates is a heartbeat. A non-empty batch is one atomic write committed at ts — never split across messages — so any ts is a safe resume point (exclusive) for a later Watch.
WatchStream
A server-streaming changelog tail for one namespace. Call Self::recv until it returns Ok(None); drop the stream to stop watching.
WatchUpdate
One tuple change within an atomic write. deleted true = tombstone.

Enums§

Condition
User
The subject of a tuple: one principal, a public wildcard, or a userset.

Functions§

connect_channel
Opens a gRPC channel with HTTP/2 keepalive (30s interval, 10s timeout, pings while idle) so idle connections survive L4 idle-eviction (IPVS, cloud LBs, NAT — nio #239). Used for both the check and the session endpoint; pass None for an insecure channel (local dev only).

Type Aliases§

ObserveCheckFn
ObserveListFn