pub struct ApprovalEngine { /* private fields */ }Expand description
In-memory (never persisted) approval state. One-time approvals are digest-bound and consumed exactly once under a mutex, including under concurrent requests. Session grants are narrow, expiring and revocable.
Implementations§
Source§impl ApprovalEngine
impl ApprovalEngine
pub fn new() -> Self
Sourcepub fn grant_once(&self, digest: [u8; 32]) -> Instant
pub fn grant_once(&self, digest: [u8; 32]) -> Instant
Record a one-time approval bound to an operation digest.
Sourcepub fn consume_once(&self, digest: [u8; 32]) -> Result<Instant, ApprovalError>
pub fn consume_once(&self, digest: [u8; 32]) -> Result<Instant, ApprovalError>
Consume a one-time approval atomically. Fails closed on expiry or a missing/mismatched digest.
Sourcepub fn grant_session(&self, key: SessionGrantKey) -> Instant
pub fn grant_session(&self, key: SessionGrantKey) -> Instant
Register a narrow session grant for an exact table set.
Sourcepub fn session_covers(&self, key: &SessionGrantKey) -> bool
pub fn session_covers(&self, key: &SessionGrantKey) -> bool
Does an unexpired session grant cover exactly this table set?
Sourcepub fn revoke_sessions(&self, filter: SessionRevokeFilter) -> usize
pub fn revoke_sessions(&self, filter: SessionRevokeFilter) -> usize
Revoke matching session grants. Empty filter fields match everything.
pub fn snapshot_sessions(&self) -> Vec<(SessionGrantKey, Instant)>
pub fn pending_one_shots(&self) -> usize
Trait Implementations§
Auto Trait Implementations§
impl !Freeze for ApprovalEngine
impl RefUnwindSafe for ApprovalEngine
impl Send for ApprovalEngine
impl Sync for ApprovalEngine
impl Unpin for ApprovalEngine
impl UnsafeUnpin for ApprovalEngine
impl UnwindSafe for ApprovalEngine
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Convert
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Convert
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
Convert
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
Convert
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more