Skip to main content

OutboundRequest

Struct OutboundRequest 

Source
#[non_exhaustive]
pub struct OutboundRequest<'a> { pub tool: &'a str, pub method: &'a str, pub path: &'a str, pub query: &'a [(String, String)], pub body: Option<&'a Value>, pub call_id: &'a str, pub phase: RequestPhase, }
Expand description

One outbound backend request, as it will be sent, handed to a RequestPolicy for inspection.

§The D-12 guarantee, stated as a guarantee

This struct has NO credential-bearing field, and it is constructed BEFORE the HttpAuthProvider runs on either HTTP surface. A policy implementation therefore cannot observe an outgoing credential — not because it is asked not to, but because the value it is handed was assembled before the credential existed. tests/request_policy.rs’s credential-scan row asserts this by searching every field for the configured secret.

Borrowed throughout (&'a str, &'a [_]): a server with no registered policy never constructs one, so the empty case adds no allocation.

Fields (Non-exhaustive)§

This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.
§tool: &'a str

The MCP tool whose tools/call produced this request.

Both shipped surfaces name a tool: the curated single-call surface passes the synthesized tool’s own name, and the Code Mode surface passes the label attached to the executor at synthesis (a script tool’s [[tools]] name, or execute_code for the generic Code Mode tool). On the Code Mode surface ONE tools/call may produce many outbound requests, and all of them carry that same label.

Empty ONLY when a caller drives a connector directly rather than through a synthesized handler — there is then no tool to name. A policy that keys on the tool name should treat the empty string as “unattributed”, never as a tool called "".

§method: &'a str

The HTTP method, upper-cased (GET, POST, …).

§path: &'a str

The FULLY RESOLVED request target: every path placeholder substituted and the configured base URL already joined on. The SDK appends no query string to it.

It is the resolved path and never the template, so an endpoint allowlist sees the URL as it will be sent. The query pairs the SDK will add are carried separately in Self::query.

§An author-written ? STAYS in path

“The SDK appends no query string” is about what the SDK adds, not about what a script author wrote. On the Code Mode surface, api.get('/search/current?string=x') puts a literal ?string=x in the path template, and the path floor deliberately permits ONE author-written ? (validate_resolved_target), so it reaches a policy INSIDE path and never appears in Self::query. A policy that must see or refuse every query pair therefore has to look for a ? in path as well as read query. The object form, api.get(path, { .. }), is what populates query.

§query: &'a [(String, String)]

The query pairs that will be appended to Self::path, EXCLUDING any pair the auth provider contributes.

An API-key-in-query credential is an auth contribution and is therefore absent here by construction — that omission is the D-12 guarantee, not an oversight.

Populated on BOTH surfaces. On the Code Mode surface that required moving the non-auth half of the remaining-body-to-query conversion above the hook (Phase 128 plan 09); without that move a policy written to inspect query pairs would have inspected an empty slice while the pairs that were about to be sent still sat in Self::body.

§body: Option<&'a Value>

The JSON request body, when one will be sent.

None for a GET-like request, whose remaining fields have already been converted into Self::query by the time the policy runs.

§call_id: &'a str

An opaque identifier for the tools/call that produced this request.

Stable across every request ONE tools/call makes. On the Code Mode surface a single execute_code run can send many requests, and all of them carry the same id, so a policy can budget a whole run (total bytes, request count, distinct endpoints) instead of seeing each request in isolation. A per-request cap alone lets a caller split free text across several requests that each fit under it. On the curated surface a tools/call is one request, so the id is simply unique per request.

Unique across calls within a process, and with overwhelming probability across restarts. It is NOT a secret and NOT a distributed trace id: it is generated here, never taken from the client, and it should not be put on the wire.

Empty ONLY when unattributed (a caller driving a connector directly rather than through a synthesized handler), the same convention as Self::tool. Treat the empty string as “no grouping”, never as one shared bucket.

§phase: RequestPhase

Whether this request is about to be SENT or is a validation-time preview.

RequestPhase::Validate marks a dry run: Code Mode’s validate_code asks the policy about the fully literal calls in a script before any approval token is issued, so a refusal reaches the model at validation instead of after it has been approved. Nothing is sent.

A stateless policy (an allowlist, a size cap) should ignore this: it gives the same answer in both phases, which is the point. A stateful policy (a request or byte budget, a rate limiter) MUST NOT charge a Validate request, or a script validated three times would spend its budget before it ran once.

Implementations§

Source§

impl<'a> OutboundRequest<'a>

Source

pub fn new( tool: &'a str, method: &'a str, path: &'a str, query: &'a [(String, String)], body: Option<&'a Value>, ) -> Self

Construct an OutboundRequest.

A constructor rather than a struct literal because the type is #[non_exhaustive]; this is also what lets an out-of-crate test build one to exercise a policy in isolation.

Source

pub fn with_phase(self, phase: RequestPhase) -> Self

Mark the request as a validation-time preview, see Self::phase.

Source

pub fn with_call_id(self, call_id: &'a str) -> Self

Attach the per-tools/call identifier, see Self::call_id.

A builder rather than a sixth parameter of Self::new, so existing callers of new keep compiling. The type is #[non_exhaustive], which is what makes adding the field itself additive.

Trait Implementations§

Source§

impl<'a> Clone for OutboundRequest<'a>

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<'a> Copy for OutboundRequest<'a>

Source§

impl<'a> Debug for OutboundRequest<'a>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl<'a> Freeze for OutboundRequest<'a>

§

impl<'a> RefUnwindSafe for OutboundRequest<'a>

§

impl<'a> Send for OutboundRequest<'a>

§

impl<'a> Sync for OutboundRequest<'a>

§

impl<'a> Unpin for OutboundRequest<'a>

§

impl<'a> UnsafeUnpin for OutboundRequest<'a>

§

impl<'a> UnwindSafe for OutboundRequest<'a>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AsOut<T> for T
where T: Copy,

Source§

fn as_out(&mut self) -> Out<'_, T>

Returns an out reference to self.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Send for T
where T: ?Sized,

Source§

impl<T> Sync for T
where T: ?Sized,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more