Skip to main content

Capability

Enum Capability 

Source
#[non_exhaustive]
pub enum Capability { ReadBalance, ProposeTransaction, SuggestDestination, ObserveEvent, SignPayment, ReadRules, SignRuleCreate, }
Expand description

A wallet capability that a toolset may declare in its manifest.

#[non_exhaustive] so that future releases can add capability kinds without a breaking change to downstream consumers that match on the enum.

There is deliberately no SignTransaction variant. Signing is not grantable as a flat capability — the sign-transaction token in a manifest is refused with ToolsetFormatError::BareSignTransactionForbidden.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

ReadBalance

Read the account balance of the agent’s configured account.

Maps to the read-balance token.

§

ProposeTransaction

Propose a transaction for user review (but not sign or submit it).

Maps to the propose-transaction token.

§

SuggestDestination

Suggest a destination address for a payment.

Maps to the suggest-destination token.

§

ObserveEvent

Observe a ledger event (streaming / webhook subscription).

Maps to the observe-event token.

§

SignPayment

Sign and submit a classic payment transaction (signing-adjacent; gated).

Maps to the sign-payment token.

§Inert at declaration

Declaring sign-payment in a toolset manifest confers NOTHING at parse time or install time — unlike the ungated capabilities above, which immediately grant their matrix tool at dispatch. This capability is INERT until the wallet’s first-invoke gate queues an out-of-band user approval and, after the operator approves, converts it into a runtime grant stored in the grant store.

The first-invoke gate fires on every invocation where no current, matching grant exists (first call, expired grant, novel destination / asset / amount-bucket).

Even with a current grant, the per-action payment approval fires unconditionally for every toolset-routed payment. sign-payment NEVER replaces per-action approval; it is an additive first-invoke consent layered before it.

§

ReadRules

Read the agent’s own context rules (spending-limit budgets, expiry, signer/policy counts) via the read-only rules-observability tools.

Maps to the read-rules token. Separately grantable from read-balance: rule visibility and balance visibility are distinct concerns, so a toolset must request each independently.

§

SignRuleCreate

Install an agent-proposed context rule on-chain (signing-adjacent; gated).

Maps to the sign-rule-create token.

§Inert at declaration

Same posture as Capability::SignPayment: declaring sign-rule-create confers NOTHING at parse or install time. This capability is INERT until the wallet’s first-invoke gate queues an out-of-band operator approval and, after the operator approves, converts it into a runtime grant.

Even with a current grant, the per-proposal RuleProposalSimulated attestation fires unconditionally for every toolset-routed stellar_rule_create_commit call. sign-rule-create NEVER replaces that per-action approval; it is an additive first-invoke consent layered before it — same relationship sign-payment has to the per-action PaymentSimulated approval.

Implementations§

Source§

impl Capability

Source

pub fn is_key_touching(self) -> bool

Returns true if this capability involves access to the agent’s signing key (either for signing or key-derivation purposes).

This predicate is the single source of truth for the install-time attestation gate. The gate calls this function and NEVER matches the capability variant directly, so that a future key-touching capability forces a compile error here until classified.

The explicit match with NO wildcard arm (_ =>) ensures that every future variant addition requires a conscious classification decision — a compile error here is intentional, not accidental. Any future key-touching capability (such as a key-derivation variant) must be classified as true when added.

§Examples
use stellar_agent_toolsets::Capability;

assert!(Capability::SignPayment.is_key_touching());
assert!(!Capability::ReadBalance.is_key_touching());
assert!(!Capability::ProposeTransaction.is_key_touching());
assert!(!Capability::SuggestDestination.is_key_touching());
assert!(!Capability::ObserveEvent.is_key_touching());

Trait Implementations§

Source§

impl Clone for Capability

Source§

fn clone(&self) -> Capability

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Capability

Source§

impl Debug for Capability

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for Capability

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Capability

Source§

impl Hash for Capability

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Capability

Source§

fn cmp(&self, other: &Capability) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for Capability

Source§

fn eq(&self, other: &Capability) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for Capability

Source§

fn partial_cmp(&self, other: &Capability) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for Capability

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.