pub struct OpenApiClassPolicy { /* private fields */ }Expand description
The static OpenAPI policy of one server, derived from its CodeModeConfig.
Implementations§
Source§impl OpenApiClassPolicy
impl OpenApiClassPolicy
Sourcepub fn from_config(config: &CodeModeConfig) -> OpenApiClassPolicy
pub fn from_config(config: &CodeModeConfig) -> OpenApiClassPolicy
Derive the policy from the OpenAPI keys of config (table in the
module docs).
Sourcepub fn with_mode(
self,
class: UnifiedAction,
mode: ClassMode,
) -> OpenApiClassPolicy
pub fn with_mode( self, class: UnifiedAction, mode: ClassMode, ) -> OpenApiClassPolicy
Replace the mode of one class. Allowlist entries are normalized.
For a caller whose own config can say more than the openapi_* keys
of CodeModeConfig — a read allowlist, an admin mode. Install the
result with
ValidationPipeline::with_openapi_class_policy.
Sourcepub fn with_blocked_operations<I, S>(self, entries: I) -> OpenApiClassPolicy
pub fn with_blocked_operations<I, S>(self, entries: I) -> OpenApiClassPolicy
Replace the blocked operations. Same entry forms as
openapi_blocked_writes: an HTTP method name blocks the method, any
other entry names an operation. A block applies in every class.
Sourcepub fn with_blocked_paths<I, S>(self, patterns: I) -> OpenApiClassPolicy
pub fn with_blocked_paths<I, S>(self, patterns: I) -> OpenApiClassPolicy
Replace the blocked path patterns (same rules as
openapi_blocked_paths).
Sourcepub fn mode(&self, class: UnifiedAction) -> &ClassMode
pub fn mode(&self, class: UnifiedAction) -> &ClassMode
The mode governing class.
Sourcepub fn check_script(
&self,
info: &JavaScriptCodeInfo,
registry: &OperationRegistry,
) -> Vec<PolicyViolation>
pub fn check_script( &self, info: &JavaScriptCodeInfo, registry: &OperationRegistry, ) -> Vec<PolicyViolation>
Check every API call of a parsed script. Returns one violation per refused call; an empty list means the script passes the static policy.
Sourcepub fn check_request(
&self,
method: &str,
path: &str,
registry: &OperationRegistry,
) -> Result<(), PolicyViolation>
pub fn check_request( &self, method: &str, path: &str, registry: &OperationRegistry, ) -> Result<(), PolicyViolation>
Check one request at execution time, after its path is resolved.
The validator classifies a dynamic path conservatively; this is the check that sees where the request actually goes. Any query string is ignored for matching. Violation messages name the method and class but never the path, which carries caller-supplied values.
§Errors
Returns the violation when the request is refused.
Trait Implementations§
Source§impl Clone for OpenApiClassPolicy
impl Clone for OpenApiClassPolicy
Source§fn clone(&self) -> OpenApiClassPolicy
fn clone(&self) -> OpenApiClassPolicy
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for OpenApiClassPolicy
impl Debug for OpenApiClassPolicy
Source§impl Display for OpenApiClassPolicy
One line naming each class’s mode and the block counts, for a startup
log: read=allow_all write=deny_all delete=deny_all admin=deny_all blocked_operations=0 blocked_paths=0. Lists are counted, not printed.
impl Display for OpenApiClassPolicy
One line naming each class’s mode and the block counts, for a startup
log: read=allow_all write=deny_all delete=deny_all admin=deny_all blocked_operations=0 blocked_paths=0. Lists are counted, not printed.
Auto Trait Implementations§
impl Freeze for OpenApiClassPolicy
impl RefUnwindSafe for OpenApiClassPolicy
impl Send for OpenApiClassPolicy
impl Sync for OpenApiClassPolicy
impl Unpin for OpenApiClassPolicy
impl UnsafeUnpin for OpenApiClassPolicy
impl UnwindSafe for OpenApiClassPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more