pub struct CheckClient { /* private fields */ }Expand description
RPC-only check client (CheckService + NamespaceService). It has no session
resolution; for HTTP middleware combine it with a
session::SessionResolver (see the axum module’s AuthState).
Implementations§
Source§impl CheckClient
impl CheckClient
pub async fn create(uri: Uri) -> Result<Self, ConnectError>
pub async fn create_with_tls( uri: Uri, tls_config: Option<ClientTlsConfig>, ) -> Result<Self, ConnectError>
pub fn from_channel(channel: Channel) -> Self
Sourcepub fn with_observe_check(self, f: ObserveCheckFn) -> Self
pub fn with_observe_check(self, f: ObserveCheckFn) -> Self
Sets an observe function called after every check RPC with (ns, obj, rel, user_id, duration, ok, is_error).
Sourcepub fn with_observe_list(self, f: ObserveListFn) -> Self
pub fn with_observe_list(self, f: ObserveListFn) -> Self
Sets an observe function called after every list RPC with (ns, rel, user_id, duration, is_error).
Sourcepub async fn check(
&mut self,
ns: Namespace,
obj: Obj,
rel: Rel,
user_id: UserId,
timestamp: Option<Timestamp>,
) -> Result<CheckResult, CallError>
pub async fn check( &mut self, ns: Namespace, obj: Obj, rel: Rel, user_id: UserId, timestamp: Option<Timestamp>, ) -> Result<CheckResult, CallError>
Calls the check server’s Check API: may user_id — a principal;
resolve session tokens to a principal client-side first (see
crate::session) — exercise rel on ⟨ns, obj⟩? Evaluated at a
snapshot at least as fresh as timestamp (a zookie from an earlier
write/read); None accepts any current snapshot. An unauthorized user
maps to CheckResult::Forbidden. A response without a principal is
CallError::UnexpectedResponseFormat. Rel::IMPOSSIBLE
short-circuits to a denial without an RPC.
Sourcepub async fn list(
&mut self,
ns: Namespace,
rel: Rel,
user_id: UserId,
timestamp: Option<Timestamp>,
) -> Result<ListResult, CallError>
pub async fn list( &mut self, ns: Namespace, rel: Rel, user_id: UserId, timestamp: Option<Timestamp>, ) -> Result<ListResult, CallError>
Calls the check server’s List API: the objects in ns on which the
user holds rel, with rewrite rules applied — the user→objects dual
of Self::check. Same zookie semantics as check. The returned
ts is the evaluation snapshot so callers can chain a subsequent
check/list/read to the same point in time.
Sourcepub async fn expand(
&mut self,
ns: Namespace,
obj: Obj,
rel: Rel,
timestamp: Option<Timestamp>,
) -> Result<ExpandResult, ReadError>
pub async fn expand( &mut self, ns: Namespace, obj: Obj, rel: Rel, timestamp: Option<Timestamp>, ) -> Result<ExpandResult, ReadError>
Calls the check server’s Expand API (paper §2.4.5): the effective
userset of ⟨ns, obj, rel⟩, including assignments only reachable
through userset rewrite rules. Pass the ts returned by a previous
call to evaluate several expansions against one consistent snapshot;
None lets the server choose.
Sourcepub async fn content_change_check(
&mut self,
ns: Namespace,
obj: Obj,
rel: Rel,
user_id: UserId,
) -> Result<ContentChangeCheckResult, CallError>
pub async fn content_change_check( &mut self, ns: Namespace, obj: Obj, rel: Rel, user_id: UserId, ) -> Result<ContentChangeCheckResult, CallError>
Authorizes a content modification against the freshest snapshot (never a client-supplied zookie). Returns the evaluation zookie to store with the new content version.
Sourcepub async fn watch(
&mut self,
ns: Namespace,
start_ts: Timestamp,
) -> Result<WatchStream, CallError>
pub async fn watch( &mut self, ns: Namespace, start_ts: Timestamp, ) -> Result<WatchStream, CallError>
Starts a server-streaming tail of the changelog for ns (paper
§2.4.6). Only changes committed after start_ts are delivered,
oldest-first, interleaved with heartbeats (empty updates). Drop the
stream to stop. Resume later by passing any previously received
event’s ts as start_ts.
Sourcepub async fn list_namespaces(&mut self) -> Result<Vec<NamespaceMeta>, ReadError>
pub async fn list_namespaces(&mut self) -> Result<Vec<NamespaceMeta>, ReadError>
Fetches the namespace configs the check server loaded: per namespace the declared relations and the rewrite kind of each. Schema metadata only — no tuples.
Sourcepub async fn get_all(
&mut self,
ns: &Namespace,
obj: &Obj,
) -> Result<ReadResult, ReadError>
pub async fn get_all( &mut self, ns: &Namespace, obj: &Obj, ) -> Result<ReadResult, ReadError>
Returns every stored tuple on ⟨ns, obj⟩ (all relations). Stored edges only — rewrites are not evaluated.
Sourcepub async fn get_all_rel(
&mut self,
ns: &Namespace,
obj: &Obj,
rel: &Rel,
) -> Result<ReadResult, ReadError>
pub async fn get_all_rel( &mut self, ns: &Namespace, obj: &Obj, rel: &Rel, ) -> Result<ReadResult, ReadError>
Returns stored tuples on ⟨ns, obj, rel⟩.
Sourcepub async fn read_by_user(
&mut self,
ns: &Namespace,
user: &User,
rel: Option<Rel>,
) -> Result<ReadResult, ReadError>
pub async fn read_by_user( &mut self, ns: &Namespace, user: &User, rel: Option<Rel>, ) -> Result<ReadResult, ReadError>
Reverse-reads tuples in ns whose subject is user. rel None
means all relations. Answered via the reverse index — no rewrites.
Sourcepub async fn read_by_user_set(
&mut self,
ns: &Namespace,
user_set: &UserSet,
rel: Option<Rel>,
) -> Result<ReadResult, ReadError>
pub async fn read_by_user_set( &mut self, ns: &Namespace, user_set: &UserSet, rel: Option<Rel>, ) -> Result<ReadResult, ReadError>
Reverse-reads tuples in ns whose subject is the userset. rel
None means all relations.
Sourcepub async fn read(
&mut self,
filters: Vec<ReadFilter>,
) -> Result<ReadResult, ReadError>
pub async fn read( &mut self, filters: Vec<ReadFilter>, ) -> Result<ReadResult, ReadError>
Returns stored tuples matching filters at any current snapshot.
Sourcepub async fn read_with_timestamp(
&mut self,
ts: Timestamp,
filters: Vec<ReadFilter>,
) -> Result<ReadResult, ReadError>
pub async fn read_with_timestamp( &mut self, ts: Timestamp, filters: Vec<ReadFilter>, ) -> Result<ReadResult, ReadError>
Returns stored tuples matching filters at a snapshot at least as
fresh as ts. The returned ts is the snapshot the server used.
Sourcepub async fn write(
&mut self,
add: Vec<Tuple>,
del: Vec<Tuple>,
precondition: Option<Timestamp>,
) -> Result<Timestamp, WriteError>
pub async fn write( &mut self, add: Vec<Tuple>, del: Vec<Tuple>, precondition: Option<Timestamp>, ) -> Result<Timestamp, WriteError>
Commits add and del tuples atomically. precondition is an
optional OCC zookie; None is an unconditional write. Returns the
commit zookie for read-your-writes / chaining subsequent reads.
Sourcepub async fn add_one(&mut self, tuple: Tuple) -> Result<Timestamp, WriteError>
pub async fn add_one(&mut self, tuple: Tuple) -> Result<Timestamp, WriteError>
Adds one tuple. Returns the commit zookie for read-your-writes.
Sourcepub async fn add_many(
&mut self,
tuples: Vec<Tuple>,
) -> Result<Timestamp, WriteError>
pub async fn add_many( &mut self, tuples: Vec<Tuple>, ) -> Result<Timestamp, WriteError>
Adds many tuples atomically. Returns the commit zookie.
Sourcepub async fn add_parent(
&mut self,
ns: Namespace,
obj: Obj,
parent_ns: Namespace,
parent_obj: Obj,
) -> Result<Timestamp, WriteError>
pub async fn add_parent( &mut self, ns: Namespace, obj: Obj, parent_ns: Namespace, parent_obj: Obj, ) -> Result<Timestamp, WriteError>
Adds an inheritance relationship using the quasi-standard relation
parent: ns:obj#parent@parent_ns:parent_obj#.... Returns the commit
zookie.
Sourcepub async fn delete_one(
&mut self,
tuple: Tuple,
) -> Result<Timestamp, WriteError>
pub async fn delete_one( &mut self, tuple: Tuple, ) -> Result<Timestamp, WriteError>
Deletes one tuple. Returns the commit zookie.
Trait Implementations§
Source§impl Clone for CheckClient
impl Clone for CheckClient
Auto Trait Implementations§
impl !Freeze for CheckClient
impl !RefUnwindSafe for CheckClient
impl !UnwindSafe for CheckClient
impl Send for CheckClient
impl Sync for CheckClient
impl Unpin for CheckClient
impl UnsafeUnpin for CheckClient
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request