Skip to main content

Module policy

Module policy 

Source
Expand description

The two explicitly-registered validation escape hatches (Phase 128, E1 + E2).

A config-declared inputSchema covers rules about ONE value. Two classes of rule it cannot express get a Rust seam here, so no team has to wrap or fork a toolkit internal:

  • E1 — RequestPolicy: a rule about what may LEAVE the server (a PHI policy, an endpoint allowlist, a per-session budget). It runs on both HTTP surfaces, BEFORE the outgoing credential exists.
  • E2 — ArgumentValidator: a rule about a COMBINATION of values (a parameter required only when another has a particular value, a code-list lookup). It runs strictly AFTER the declared schema check, so it never sees arguments the schema already refused.

Both are registered on a ToolkitHooks value and handed to an assembly entry point as a parameter. There is no builder-field accumulation, and the reason is structural rather than stylistic: ServerBuilderExt is implemented for CORE’s pmcp::ServerBuilder, whose fields are private, and a Rust extension trait cannot add a field to a foreign type. The two rejected alternatives are recorded on ToolkitHooks.

§What this module deliberately does NOT do

It contains no schema logic. The declared-schema check, the placeholder character floor and the value-free refusal renderer all live in core pmcp::server::schema_validation; these hooks sit around them.

Structs§

ArgumentRefusal
An ArgumentValidator’s refusal of one tools/call.
OutboundRequest
One outbound backend request, as it will be sent, handed to a RequestPolicy for inspection.
PolicyRefusal
A RequestPolicy’s refusal of one outbound request.
ReportLine
One rendered enforcement-report line.
ToolkitHooks
The registered E1 policy and E2 validators, passed as a PARAMETER to an assembly entry point.

Enums§

ReportLevel
The severity one render_validation_report line is emitted at.
RequestPhase
Whether an OutboundRequest is about to be sent or is only being previewed, see OutboundRequest::phase.

Traits§

ArgumentValidator
A per-tool rule about a COMBINATION of argument values, run strictly AFTER the declared inputSchema check (Phase 128, E2).
RequestPolicy
A rule about what may LEAVE the server, consulted before every outbound backend request on both HTTP surfaces (Phase 128, E1 / D-12).

Functions§

emit_validation_report
Emit the enforcement report ONCE per server, at startup (Phase 128, D-07).
render_validation_report
Render what this server actually enforces, as the lines emit_validation_report logs (Phase 128, D-07).