Skip to main content

systemprompt_api/services/gateway/service/
error.rs

1//! The typed failures a gateway dispatch can end in, downcast by the HTTP
2//! layer to choose a status and envelope.
3//!
4//! [`DispatchError`] separates a failure that happened before the audit row
5//! was opened from one already recorded against it, so the route handler
6//! knows whether it still owes an audit write.
7//!
8//! Copyright (c) systemprompt.io — Business Source License 1.1.
9//! See <https://systemprompt.io> for licensing details.
10
11#[derive(Debug, thiserror::Error)]
12pub enum DispatchError {
13    #[error(transparent)]
14    PreAudit(anyhow::Error),
15    #[error(transparent)]
16    Recorded(anyhow::Error),
17}
18
19#[derive(Debug, thiserror::Error)]
20#[error("{0}")]
21pub struct PolicyDenied(pub String);
22
23#[derive(Debug, thiserror::Error)]
24#[error("{message}")]
25pub struct QuotaExceeded {
26    pub message: String,
27    pub retry_after_seconds: i32,
28}
29
30#[derive(Debug, thiserror::Error)]
31#[error("{message}")]
32pub struct GuardForbidden {
33    pub message: String,
34}
35
36/// A denial from the typed four-stage governance chain — the same engine and
37/// the same operator-configured policies that govern MCP tool calls.
38#[derive(Debug, thiserror::Error)]
39#[error("{message}")]
40pub struct GovernanceDenied {
41    pub policy: String,
42    pub message: String,
43}
44
45/// A secret-scan denial the gateway could not repair; `locations` names the
46/// provider-payload fields the client must fix before retrying.
47#[derive(Debug, thiserror::Error)]
48#[error("{message}")]
49pub struct PromptRepairRequired {
50    pub message: String,
51    pub locations: Vec<String>,
52}
53
54#[derive(Debug, thiserror::Error)]
55#[error("{message}")]
56pub struct SafetyBlocked {
57    pub category: String,
58    pub message: String,
59}