Skip to main content

OpenApiClassPolicy

Struct OpenApiClassPolicy 

Source
pub struct OpenApiClassPolicy { /* private fields */ }
Expand description

The static OpenAPI policy of one server, derived from its CodeModeConfig.

Implementations§

Source§

impl OpenApiClassPolicy

Source

pub fn from_config(config: &CodeModeConfig) -> Self

Derive the policy from the OpenAPI keys of config (table in the module docs).

Source

pub fn with_mode(self, class: UnifiedAction, mode: ClassMode) -> Self

Replace the mode of one class. Allowlist entries are normalized.

For a caller whose own config can say more than the openapi_* keys of CodeModeConfig — a read allowlist, an admin mode. Install the result with ValidationPipeline::with_openapi_class_policy.

Source

pub fn with_blocked_operations<I, S>(self, entries: I) -> Self
where I: IntoIterator<Item = S>, S: AsRef<str>,

Replace the blocked operations. Same entry forms as openapi_blocked_writes: an HTTP method name blocks the method, any other entry names an operation. A block applies in every class.

Source

pub fn with_blocked_paths<I, S>(self, patterns: I) -> Self
where I: IntoIterator<Item = S>, S: AsRef<str>,

Replace the blocked path patterns (same rules as openapi_blocked_paths).

Source

pub fn mode(&self, class: UnifiedAction) -> &ClassMode

The mode governing class.

Source

pub fn check_script( &self, info: &JavaScriptCodeInfo, registry: &OperationRegistry, ) -> Vec<PolicyViolation>

Check every API call of a parsed script. Returns one violation per refused call; an empty list means the script passes the static policy.

Source

pub fn check_request( &self, method: &str, path: &str, registry: &OperationRegistry, ) -> Result<(), PolicyViolation>

Check one request at execution time, after its path is resolved.

The validator classifies a dynamic path conservatively; this is the check that sees where the request actually goes. Any query string is ignored for matching. Violation messages name the method and class but never the path, which carries caller-supplied values.

§Errors

Returns the violation when the request is refused.

Trait Implementations§

Source§

impl Clone for OpenApiClassPolicy

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for OpenApiClassPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for OpenApiClassPolicy

One line naming each class’s mode and the block counts, for a startup log: read=allow_all write=deny_all delete=deny_all admin=deny_all blocked_operations=0 blocked_paths=0. Lists are counted, not printed.

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Send for T
where T: ?Sized,

Source§

impl<T> Sync for T
where T: ?Sized,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToSmolStr for T
where T: Display + ?Sized,

Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more