pub struct AccessManager { /* private fields */ }Expand description
Access Manager.
Manages agent permissions, enforces security boundaries, and maintains an audit log of all security-relevant actions.
§Usage
let mut access = AccessManager::new();
// Create permissions for a new agent
access.set_permissions(AgentPermissions::for_new_agent("code-agent"));
// Assign agent to a workspace
access.assign_workspace("code-agent", "project-alpha");
// Check permissions with sandbox enforcement
if access.can_access_path_in_workspace(&agent_id, "code-agent", "/workspace/file.rs", Some("project-alpha")) {
// allow file access within workspace
}
// Check if agent can access a specific workspace
if access.can_access_workspace("code-agent", "project-alpha") {
// allow workspace access
}Access Manager — least-privilege security for agents.
Implementations§
Source§impl AccessManager
impl AccessManager
Sourcepub fn with_max_audit_entries(max_audit_entries: usize) -> Self
pub fn with_max_audit_entries(max_audit_entries: usize) -> Self
Creates a new access manager with custom settings.
§Arguments
max_audit_entries- Maximum audit log size (oldest entries are pruned)
Sourcepub fn with_audit_log_path(self, path: PathBuf) -> Self
pub fn with_audit_log_path(self, path: PathBuf) -> Self
Configure an audit log file path for persistence.
Spawns a background tokio task that reads from a bounded channel and appends audit entries to the file. Uses a bounded channel of capacity 1000 to provide backpressure.
Sourcepub fn can_use_tool(&mut self, agent_name: &str, tool: &str) -> bool
pub fn can_use_tool(&mut self, agent_name: &str, tool: &str) -> bool
Checks if an agent is allowed to use a specific tool.
Logs the access decision to the audit log.
Sourcepub fn can_access_path(&mut self, agent_name: &str, path: &str) -> bool
pub fn can_access_path(&mut self, agent_name: &str, path: &str) -> bool
Checks if an agent is allowed to access a specific path.
Enforces both allowed_paths and denied_paths rules. A path is only allowed if it matches an allowed pattern AND does not match any denied pattern.
Logs the access decision to the audit log.
Sourcepub fn can_access_network(&mut self, agent_name: &str) -> bool
pub fn can_access_network(&mut self, agent_name: &str) -> bool
Checks if an agent is allowed to make network requests.
Logs the access decision to the audit log.
Sourcepub fn can_execute_for(&self, agent_name: &str, duration_secs: u64) -> bool
pub fn can_execute_for(&self, agent_name: &str, duration_secs: u64) -> bool
Checks if an agent can execute for the given duration (in seconds).
Returns true if unlimited (max_execution_time_secs = 0) or if the requested duration is within the limit.
Sourcepub fn can_use_memory(&self, agent_name: &str, memory_mb: u64) -> bool
pub fn can_use_memory(&self, agent_name: &str, memory_mb: u64) -> bool
Checks if an agent can use the specified amount of memory (in MB).
Returns true if unlimited (max_memory_mb = 0) or if the requested memory is within the limit.
Sourcepub fn can_fork(&self, agent_name: &str) -> bool
pub fn can_fork(&self, agent_name: &str) -> bool
Checks if an agent can fork (spawn sub-agents).
Sourcepub fn get_permissions(&self, agent_name: &str) -> Option<&AgentPermissions>
pub fn get_permissions(&self, agent_name: &str) -> Option<&AgentPermissions>
Gets the permission set for an agent.
Returns None if no permissions are defined for the agent.
Sourcepub fn get_or_create_permissions(
&mut self,
agent_name: &str,
) -> &mut AgentPermissions
pub fn get_or_create_permissions( &mut self, agent_name: &str, ) -> &mut AgentPermissions
Gets the permission set for an agent, creating a default one if needed.
Useful for dynamically creating permissions on first access.
Sourcepub fn set_permissions(&mut self, permissions: AgentPermissions)
pub fn set_permissions(&mut self, permissions: AgentPermissions)
Sets the permissions for an agent.
Overwrites any existing permissions for this agent.
Sourcepub fn update_permissions(
&mut self,
agent_name: &str,
update: PermissionUpdate,
) -> Result<()>
pub fn update_permissions( &mut self, agent_name: &str, update: PermissionUpdate, ) -> Result<()>
Updates permissions for an agent using a partial update.
Creates default permissions if the agent doesn’t exist. Only updates fields that are Some() in the update.
Sourcepub fn remove_permissions(&mut self, agent_name: &str)
pub fn remove_permissions(&mut self, agent_name: &str)
Removes permissions for an agent.
After removal, all access by this agent will be denied.
Sourcepub fn list_agents(&self) -> Vec<String>
pub fn list_agents(&self) -> Vec<String>
Lists all agents with defined permissions.
Sourcepub fn audit_log(&self) -> &[AuditEntry]
pub fn audit_log(&self) -> &[AuditEntry]
Gets the full audit log.
Returns entries in chronological order (oldest first).
Sourcepub fn audit_log_recent(&self, limit: usize) -> Vec<AuditEntry>
pub fn audit_log_recent(&self, limit: usize) -> Vec<AuditEntry>
Gets recent audit log entries.
§Arguments
limit- Maximum number of entries to return (from the end)
Sourcepub fn audit_log_for_agent(&self, agent_name: &str) -> Vec<AuditEntry>
pub fn audit_log_for_agent(&self, agent_name: &str) -> Vec<AuditEntry>
Gets audit log entries for a specific agent.
Sourcepub fn denied_actions(&self) -> Vec<&AuditEntry>
pub fn denied_actions(&self) -> Vec<&AuditEntry>
Searches audit log for denied actions.
Sourcepub fn rbac_manager(&self) -> &RbacManager
pub fn rbac_manager(&self) -> &RbacManager
Returns a reference to the RBAC manager (for HitL approvals).
Sourcepub fn rbac_manager_mut(&mut self) -> &mut RbacManager
pub fn rbac_manager_mut(&mut self) -> &mut RbacManager
Returns a mutable reference to the RBAC manager (for HitL approvals).
Sourcepub fn register_workspace_path(
&mut self,
workspace_name: &str,
workspace_path: PathBuf,
)
pub fn register_workspace_path( &mut self, workspace_name: &str, workspace_path: PathBuf, )
Registers a workspace path.
This is used to report which paths belong to each workspace.
§Arguments
workspace_name- Name of the workspaceworkspace_path- Absolute path to the workspace directory
Sourcepub fn assign_workspace(
&mut self,
agent_name: &str,
workspace_name: &str,
) -> bool
pub fn assign_workspace( &mut self, agent_name: &str, workspace_name: &str, ) -> bool
Sourcepub fn get_workspace_for_agent(&self, agent_name: &str) -> Option<String>
pub fn get_workspace_for_agent(&self, agent_name: &str) -> Option<String>
Gets the workspace name that an agent is assigned to.
§Returns
Some(workspace_name) if assigned, None if the agent is not assigned to any workspace
Sourcepub fn get_workspace_path(&self, workspace_name: &str) -> Option<&PathBuf>
pub fn get_workspace_path(&self, workspace_name: &str) -> Option<&PathBuf>
Sourcepub fn list_workspaces(&self) -> Vec<String>
pub fn list_workspaces(&self) -> Vec<String>
Lists all registered workspaces.
Sourcepub fn list_agents_in_workspace(&self, workspace_name: &str) -> Vec<String>
pub fn list_agents_in_workspace(&self, workspace_name: &str) -> Vec<String>
Lists all agents assigned to a specific workspace.
Sourcepub fn can_access_workspace(
&self,
agent_name: &str,
workspace_name: &str,
) -> bool
pub fn can_access_workspace( &self, agent_name: &str, workspace_name: &str, ) -> bool
Sourcepub fn is_path_in_workspace(&self, workspace_name: &str, path: &str) -> bool
pub fn is_path_in_workspace(&self, workspace_name: &str, path: &str) -> bool
Checks if a path is within a workspace’s directory.
This performs a canonical path comparison to ensure the path is a descendant of the workspace directory.
§Arguments
workspace_name- Name of the workspacepath- Path to check (absolute or relative)
§Returns
true if the path is within the workspace, false otherwise
Sourcepub fn can_access_path_in_workspace(
&mut self,
agent_id: &AgentId,
agent_name: &str,
path: &str,
workspace: Option<&str>,
) -> bool
pub fn can_access_path_in_workspace( &mut self, agent_id: &AgentId, agent_name: &str, path: &str, workspace: Option<&str>, ) -> bool
Full sandbox check: RBAC → path allowed? → within workspace?
This is the main method for enforcing sandbox boundaries. It checks:
- RBAC - does the agent’s role allow the action?
- Path permissions - is the path in the agent’s allowed_paths?
- Workspace boundary - is the path within the assigned workspace?
If any check fails, the access is denied and logged as “sandbox violation” if the path would be valid but outside the workspace boundary.
§Arguments
agent_name- Name of the agentpath- Path to accessworkspace- Workspace context (if agent is assigned to one)
§Returns
true if all checks pass, false otherwise
Check whether an agent can access a path within its workspace.
Verifies RBAC permissions, path allow/deny lists, and workspace boundary.
§Arguments
agent_id- The agent’s unique identifieragent_name- Human-readable agent name for permission lookuppath- The path to check access forworkspace- Optional explicit workspace name
Sourcepub fn unassign_workspace(&mut self, agent_name: &str) -> Option<String>
pub fn unassign_workspace(&mut self, agent_name: &str) -> Option<String>
Unassigns an agent from its workspace (if any).
The agent will no longer be sandboxed to any workspace.
Sourcepub fn remove_workspace(&mut self, workspace_name: &str)
pub fn remove_workspace(&mut self, workspace_name: &str)
Removes a workspace and unassigns all agents from it.
All agents assigned to this workspace will have their assignments cleared.
Sourcepub fn clear_audit_log(&mut self)
pub fn clear_audit_log(&mut self)
Clears the audit log.
Sourcepub fn validate_permissions(&self, perms: &AgentPermissions) -> Vec<String>
pub fn validate_permissions(&self, perms: &AgentPermissions) -> Vec<String>
Validates a permission set for correctness.
Returns a list of warnings about the permissions.
Trait Implementations§
Source§impl Clone for AccessManager
impl Clone for AccessManager
Source§fn clone(&self) -> AccessManager
fn clone(&self) -> AccessManager
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for AccessManager
impl Debug for AccessManager
Auto Trait Implementations§
impl Freeze for AccessManager
impl RefUnwindSafe for AccessManager
impl Send for AccessManager
impl Sync for AccessManager
impl Unpin for AccessManager
impl UnsafeUnpin for AccessManager
impl UnwindSafe for AccessManager
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<R, P> ReadPrimitive<R> for P
impl<R, P> ReadPrimitive<R> for P
Source§fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
ReadEndian::read_from_little_endian().Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.