Skip to main content

CheckClient

Struct CheckClient 

Source
pub struct CheckClient { /* private fields */ }
Expand description

RPC-only check client (CheckService + NamespaceService). It has no session resolution; for HTTP middleware combine it with a session::SessionResolver (see the axum module’s AuthState).

Implementations§

Source§

impl CheckClient

Source

pub async fn create(uri: Uri) -> Result<Self, ConnectError>

Source

pub async fn create_with_tls( uri: Uri, tls_config: Option<ClientTlsConfig>, ) -> Result<Self, ConnectError>

Source

pub fn from_channel(channel: Channel) -> Self

Source

pub fn with_observe_check(self, f: ObserveCheckFn) -> Self

Sets an observe function called after every check RPC with (ns, obj, rel, user_id, duration, ok, is_error).

Source

pub fn with_observe_list(self, f: ObserveListFn) -> Self

Sets an observe function called after every list RPC with (ns, rel, user_id, duration, is_error).

Source

pub async fn check( &mut self, ns: Namespace, obj: Obj, rel: Rel, user_id: UserId, timestamp: Option<Timestamp>, ) -> Result<CheckResult, CallError>

Calls the check server’s Check API: may user_id — a principal; resolve session tokens to a principal client-side first (see crate::session) — exercise rel on ⟨ns, obj⟩? Evaluated at a snapshot at least as fresh as timestamp (a zookie from an earlier write/read); None accepts any current snapshot. An unauthorized user maps to CheckResult::Forbidden. A response without a principal is CallError::UnexpectedResponseFormat. Rel::IMPOSSIBLE short-circuits to a denial without an RPC.

Source

pub async fn list( &mut self, ns: Namespace, rel: Rel, user_id: UserId, timestamp: Option<Timestamp>, ) -> Result<ListResult, CallError>

Calls the check server’s List API: the objects in ns on which the user holds rel, with rewrite rules applied — the user→objects dual of Self::check. Same zookie semantics as check. The returned ts is the evaluation snapshot so callers can chain a subsequent check/list/read to the same point in time.

Source

pub async fn expand( &mut self, ns: Namespace, obj: Obj, rel: Rel, timestamp: Option<Timestamp>, ) -> Result<ExpandResult, ReadError>

Calls the check server’s Expand API (paper §2.4.5): the effective userset of ⟨ns, obj, rel⟩, including assignments only reachable through userset rewrite rules. Pass the ts returned by a previous call to evaluate several expansions against one consistent snapshot; None lets the server choose.

Source

pub async fn content_change_check( &mut self, ns: Namespace, obj: Obj, rel: Rel, user_id: UserId, ) -> Result<ContentChangeCheckResult, CallError>

Authorizes a content modification against the freshest snapshot (never a client-supplied zookie). Returns the evaluation zookie to store with the new content version.

Source

pub async fn watch( &mut self, ns: Namespace, start_ts: Timestamp, ) -> Result<WatchStream, CallError>

Starts a server-streaming tail of the changelog for ns (paper §2.4.6). Only changes committed after start_ts are delivered, oldest-first, interleaved with heartbeats (empty updates). Drop the stream to stop. Resume later by passing any previously received event’s ts as start_ts.

Source

pub async fn list_namespaces(&mut self) -> Result<Vec<NamespaceMeta>, ReadError>

Fetches the namespace configs the check server loaded: per namespace the declared relations and the rewrite kind of each. Schema metadata only — no tuples.

Source

pub async fn get_all( &mut self, ns: &Namespace, obj: &Obj, ) -> Result<ReadResult, ReadError>

Returns every stored tuple on ⟨ns, obj⟩ (all relations). Stored edges only — rewrites are not evaluated.

Source

pub async fn get_all_rel( &mut self, ns: &Namespace, obj: &Obj, rel: &Rel, ) -> Result<ReadResult, ReadError>

Returns stored tuples on ⟨ns, obj, rel⟩.

Source

pub async fn read_by_user( &mut self, ns: &Namespace, user: &User, rel: Option<Rel>, ) -> Result<ReadResult, ReadError>

Reverse-reads tuples in ns whose subject is user. rel None means all relations. Answered via the reverse index — no rewrites.

Source

pub async fn read_by_user_set( &mut self, ns: &Namespace, user_set: &UserSet, rel: Option<Rel>, ) -> Result<ReadResult, ReadError>

Reverse-reads tuples in ns whose subject is the userset. rel None means all relations.

Source

pub async fn read( &mut self, filters: Vec<ReadFilter>, ) -> Result<ReadResult, ReadError>

Returns stored tuples matching filters at any current snapshot.

Source

pub async fn read_with_timestamp( &mut self, ts: Timestamp, filters: Vec<ReadFilter>, ) -> Result<ReadResult, ReadError>

Returns stored tuples matching filters at a snapshot at least as fresh as ts. The returned ts is the snapshot the server used.

Source

pub async fn write( &mut self, add: Vec<Tuple>, del: Vec<Tuple>, precondition: Option<Timestamp>, ) -> Result<Timestamp, WriteError>

Commits add and del tuples atomically. precondition is an optional OCC zookie; None is an unconditional write. Returns the commit zookie for read-your-writes / chaining subsequent reads.

Source

pub async fn add_one(&mut self, tuple: Tuple) -> Result<Timestamp, WriteError>

Adds one tuple. Returns the commit zookie for read-your-writes.

Source

pub async fn add_many( &mut self, tuples: Vec<Tuple>, ) -> Result<Timestamp, WriteError>

Adds many tuples atomically. Returns the commit zookie.

Source

pub async fn add_parent( &mut self, ns: Namespace, obj: Obj, parent_ns: Namespace, parent_obj: Obj, ) -> Result<Timestamp, WriteError>

Adds an inheritance relationship using the quasi-standard relation parent: ns:obj#parent@parent_ns:parent_obj#.... Returns the commit zookie.

Source

pub async fn delete_one( &mut self, tuple: Tuple, ) -> Result<Timestamp, WriteError>

Deletes one tuple. Returns the commit zookie.

Trait Implementations§

Source§

impl Clone for CheckClient

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for CheckClient

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more