Expand description
Static class policy for OpenAPI Code Mode.
Every OpenAPI policy key in CodeModeConfig is enforced here, without a
PolicyEvaluator. A configured evaluator (Cedar,
AVP) runs AFTER this gate and can only narrow its verdict, never widen it.
Before this module the static gate looked at HTTP methods only and left
every other key — the write allowlist, the read switch, deletes, blocked
paths, catalog classes, admin — to the evaluator. Under
NoopPolicyEvaluator those keys were inert,
and a non-empty write allowlist widened to allow-all.
§Classes
Each API call gets one UnifiedAction class:
- The declared
categoryof the matching[[code_mode.operations]]entry (seeOperationRegistry::lookup_entry). A category that is notread,write,deleteoradminis refused, never guessed. - Otherwise the HTTP method: GET/HEAD/OPTIONS are
read, POST/PUT/PATCH arewrite, DELETE isdelete.
A call whose path is only known at run time keeps the stricter of the two,
so a catalog entry cannot relax a path the validator cannot see. The
run-time half of the check is OpenApiClassPolicy::check_request, which
sees the resolved path.
§Modes, derived from the existing keys
| Class | Mode |
|---|---|
| read | openapi_reads_enabled ? allow_all : deny_all |
| write | !openapi_allow_writes → deny_all; non-empty openapi_allowed_writes → allowlist; else allow_all |
| delete | !openapi_allow_deletes → deny_all; non-empty openapi_allowed_deletes → allowlist; else allow_all |
| admin | always deny_all (no key enables it) |
openapi_blocked_writes blocks every call it names, in any class. An entry
that is an HTTP method name ("POST") blocks that method; any other entry
is an operation ("POST /users", "POST:/users/{id}" or a catalog id).
openapi_blocked_paths blocks every call whose path falls under one of its
patterns (* matches any run of characters; a pattern with no * blocks
the path itself and everything below it). Both comparisons ignore case.
The write and delete rules mirror
CodeModeConfig::to_openapi_server_entity’s write_mode, so the static
gate and the Cedar entity describe the same policy.
§Scope
SDK-backed Code Mode (sdk_operations) issues no HTTP calls and is not
classified here.
Structs§
- Class
Policy Http Executor - An
HttpExecutorthat re-checks every request against the static class policy once its path is resolved, then delegates. - Open
ApiClass Policy - The static OpenAPI policy of one server, derived from its
CodeModeConfig.
Enums§
- Class
Mode - How one class of operations is governed.