pub fn record_first_invoke_grant(
profile_name: &str,
toolset_name: &str,
capability: &str,
destination: &str,
asset: &str,
amount_min_stroops: i64,
amount_max_stroops: i64,
process_uid: &str,
now_unix_ms: u64,
attestation_key: &[u8; 32],
binding: &AttestationBinding<'_>,
grant_store_path_override: GrantStorePathOverride,
) -> Result<ToolsetGrant, ToolsetRuntimeError>Expand description
Records a confirmed first-invoke grant after the operator approves a
ToolsetFirstInvokeGate pending approval.
Called by the CLI approve handler after verifying the attestation.
The grant is persisted to the grant store with the supplied attestation key.
Pass None for grant_store_path_override in production. Integration tests
pass Some(path) pointing to a tempfile::TempDir to avoid writing to the
real grant store.
ยงErrors
ToolsetRuntimeError::GrantStoreErroron grant store I/O failure.