#[non_exhaustive]pub struct CodeModeSection {Show 23 fields
pub enabled: bool,
pub server_id: Option<String>,
pub allow_writes: bool,
pub allow_deletes: bool,
pub allow_ddl: bool,
pub require_limit: bool,
pub max_limit: Option<u64>,
pub blocked_tables: Vec<String>,
pub sensitive_columns: Vec<String>,
pub auto_approve_levels: Vec<String>,
pub token_ttl_seconds: Option<u64>,
pub token_secret: Option<String>,
pub allow_inline_token_secret_for_dev: bool,
pub limits: Option<CodeModeLimits>,
pub description_notice: Option<String>,
pub read_mode: Option<ClassModeName>,
pub write_mode: Option<ClassModeName>,
pub delete_mode: Option<ClassModeName>,
pub admin_mode: Option<ClassModeName>,
pub allowed_operations: Vec<String>,
pub blocked_operations: Vec<String>,
pub blocked_paths: Vec<String>,
pub operations: Vec<OperationDecl>,
}Expand description
[code_mode] section — code-mode policy + complexity limits.
The toolkit uses unprefixed field names (REF-01 invariant); the mapping
to pmcp_code_mode::CodeModeConfig’s prefixed names (sql_allow_writes,
etc.) is handled by Plan 06’s executor wiring.
§Keys by backend
The SQL keys (allow_writes, allow_deletes, allow_ddl, require_limit,
max_limit, blocked_tables, sensitive_columns) apply to a SQL server.
The operation-class keys (read_mode, write_mode, delete_mode,
admin_mode, allowed_operations, blocked_operations, blocked_paths,
[[code_mode.operations]]) apply to an OpenAPI server (one with a
[backend]). ServerConfig::validate refuses a key set on the wrong kind
of server, because it would otherwise be silently ignored.
#[non_exhaustive] since 0.4: build one with Default and assign fields.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.enabled: boolMaster enable flag for code-mode.
server_id: Option<String>Server identifier used by AVP / Cedar policy resolution.
allow_writes: boolWhether INSERT / UPDATE / MERGE statements are allowed.
allow_deletes: boolWhether DELETE statements are allowed.
allow_ddl: boolWhether DDL (CREATE / ALTER / DROP) is allowed.
require_limit: boolWhether SELECT queries must declare a LIMIT.
max_limit: Option<u64>Maximum allowed LIMIT value.
blocked_tables: Vec<String>Table names blocked from any query (denylist).
sensitive_columns: Vec<String>table.column strings stripped from query output.
auto_approve_levels: Vec<String>Risk levels eligible for auto-approval (e.g. ["low"]).
token_ttl_seconds: Option<u64>Token TTL, in seconds, for HMAC-signed approval tokens.
token_secret: Option<String>Secret reference (e.g. "${CODE_MODE_SECRET}") for HMAC signing — resolved
at runtime by SecretsProvider. NEVER a raw secret value (review R6 +
T-83-04-04 in the plan threat model).
allow_inline_token_secret_for_dev: boolPer Phase 83 review R9: inline token_secret = "raw-string" is REJECTED
by default to prevent secrets from being committed to source-controlled
configs. Set this flag to true ONLY in dev/test configs where the
operator explicitly accepts the risk. NEVER set this in a committed
production config — production must use the env:VAR_NAME syntax that
resolves at runtime through SecretsProvider.
limits: Option<CodeModeLimits>[code_mode.limits] — query-complexity caps.
description_notice: Option<String>Operator text appended to BOTH the validate_code and execute_code tool
descriptions, after the SDK’s own.
The place to tell the model what this deployment enforces that its own tool descriptions cannot know: “responses are de-identified”, “queries over 100 rows are refused”, “paths under /admin are blocked”. The model reads a tool’s description before it calls the tool, so a rule stated here is followed instead of discovered through a refusal.
Appended verbatim after a blank line. Unset (the default) leaves both descriptions exactly as the SDK writes them.
read_mode: Option<ClassModeName>OpenAPI: how read operations are governed. Default allow_all.
write_mode: Option<ClassModeName>OpenAPI: how write operations (POST/PUT/PATCH unless the catalog
says otherwise) are governed. Default deny_all.
delete_mode: Option<ClassModeName>OpenAPI: how delete operations are governed. Default deny_all.
admin_mode: Option<ClassModeName>OpenAPI: how admin operations (only ever declared in
[[code_mode.operations]]) are governed. Default deny_all.
allowed_operations: Vec<String>OpenAPI: the operations an allowlist class admits. Each entry is a
catalog id or an operation ("GET /items/{id}"). Required, and
non-empty, when any class is allowlist.
blocked_operations: Vec<String>OpenAPI: operations refused in every class and mode. An HTTP method
name ("PATCH") blocks the method. Required, and non-empty, when any
class is blocklist.
blocked_paths: Vec<String>OpenAPI: path patterns refused in every class (* matches any run of
characters; a pattern without * covers the path and everything below
it). Case is ignored.
operations: Vec<OperationDecl>OpenAPI: [[code_mode.operations]] — the operation catalog. Its
category classifies a call before the HTTP method does.
Implementations§
Source§impl CodeModeSection
impl CodeModeSection
Sourcepub fn sql_keys_set(&self) -> Vec<&'static str>
pub fn sql_keys_set(&self) -> Vec<&'static str>
The SQL-only keys this section sets, by config name.
Sourcepub fn class_keys_set(&self) -> Vec<&'static str>
pub fn class_keys_set(&self) -> Vec<&'static str>
The OpenAPI operation-class keys this section sets, by config name.
Sourcepub fn class_modes(&self) -> [(OperationCategory, ClassModeName); 4]
pub fn class_modes(&self) -> [(OperationCategory, ClassModeName); 4]
The effective mode of each class: [read, write, delete, admin],
with the defaults applied (read allow_all, the rest deny_all).
Trait Implementations§
Source§impl Clone for CodeModeSection
impl Clone for CodeModeSection
Source§impl Debug for CodeModeSection
impl Debug for CodeModeSection
Source§impl Default for CodeModeSection
impl Default for CodeModeSection
Source§impl<'de> Deserialize<'de> for CodeModeSection
impl<'de> Deserialize<'de> for CodeModeSection
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for CodeModeSection
Source§impl PartialEq for CodeModeSection
impl PartialEq for CodeModeSection
Source§impl Serialize for CodeModeSection
impl Serialize for CodeModeSection
impl StructuralPartialEq for CodeModeSection
Auto Trait Implementations§
impl Freeze for CodeModeSection
impl RefUnwindSafe for CodeModeSection
impl Send for CodeModeSection
impl Sync for CodeModeSection
impl Unpin for CodeModeSection
impl UnsafeUnpin for CodeModeSection
impl UnwindSafe for CodeModeSection
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more