Skip to main content

Module openapi_policy

Module openapi_policy 

Source
Expand description

Static class policy for OpenAPI Code Mode.

Every OpenAPI policy key in CodeModeConfig is enforced here, without a PolicyEvaluator. A configured evaluator (Cedar, AVP) runs AFTER this gate and can only narrow its verdict, never widen it.

Before this module the static gate looked at HTTP methods only and left every other key — the write allowlist, the read switch, deletes, blocked paths, catalog classes, admin — to the evaluator. Under NoopPolicyEvaluator those keys were inert, and a non-empty write allowlist widened to allow-all.

§Classes

Each API call gets one UnifiedAction class:

  1. The declared category of the matching [[code_mode.operations]] entry (see OperationRegistry::lookup_entry). A category that is not read, write, delete or admin is refused, never guessed.
  2. Otherwise the HTTP method: GET/HEAD/OPTIONS are read, POST/PUT/PATCH are write, DELETE is delete.

A call whose path is only known at run time keeps the stricter of the two, so a catalog entry cannot relax a path the validator cannot see. The run-time half of the check is OpenApiClassPolicy::check_request, which sees the resolved path.

§Modes, derived from the existing keys

ClassMode
readopenapi_reads_enabled ? allow_all : deny_all
write!openapi_allow_writes → deny_all; non-empty openapi_allowed_writes → allowlist; else allow_all
delete!openapi_allow_deletes → deny_all; non-empty openapi_allowed_deletes → allowlist; else allow_all
adminalways deny_all (no key enables it)

openapi_blocked_writes blocks every call it names, in any class. An entry that is an HTTP method name ("POST") blocks that method; any other entry is an operation ("POST /users", "POST:/users/{id}" or a catalog id). openapi_blocked_paths blocks every call whose path falls under one of its patterns (* matches any run of characters; a pattern with no * blocks the path itself and everything below it). Both comparisons ignore case.

The write and delete rules mirror CodeModeConfig::to_openapi_server_entity’s write_mode, so the static gate and the Cedar entity describe the same policy.

§Scope

SDK-backed Code Mode (sdk_operations) issues no HTTP calls and is not classified here.

Structs§

ClassPolicyHttpExecutor
An HttpExecutor that re-checks every request against the static class policy once its path is resolved, then delegates.
OpenApiClassPolicy
The static OpenAPI policy of one server, derived from its CodeModeConfig.

Enums§

ClassMode
How one class of operations is governed.