systemprompt_security/policy/
registry.rs1use serde_yaml::Value as YamlValue;
14
15use super::secrets::SecretPatternError;
16use super::types::GovernancePolicy;
17
18pub type PolicyFactory =
24 fn(&YamlValue) -> Result<Box<dyn GovernancePolicy>, PolicyConfigurationError>;
25
26#[derive(Debug, thiserror::Error)]
28pub enum PolicyConfigurationError {
29 #[error("unknown access scope `{scope}` in require_approval exempt_scopes")]
30 UnknownExemptScope { scope: String },
31
32 #[error(
33 "require_approval condition on `{tool}` at `{path}` has no operand its `{operator}` \
34 operator can use"
35 )]
36 UnusableCondition {
37 tool: String,
38 path: String,
39 operator: &'static str,
40 },
41
42 #[error(
43 "secret_scan is in enforce mode but compiles no secret patterns; declare `patterns` or \
44 set `mode: warn`"
45 )]
46 ToothlessSecretScan,
47
48 #[error("{context}: {source}")]
49 Yaml {
50 context: &'static str,
51 #[source]
52 source: serde_yaml::Error,
53 },
54
55 #[error(transparent)]
56 SecretPatterns(#[from] SecretPatternError),
57}
58
59#[derive(Debug, Clone, Copy)]
62pub struct PolicyRegistration {
63 pub id: &'static str,
64 pub factory: PolicyFactory,
65}
66
67inventory::collect!(PolicyRegistration);
68
69#[doc(hidden)]
70pub use inventory;
71
72#[macro_export]
73macro_rules! register_governance_policy {
74 ($id:expr, $factory:expr) => {
75 $crate::policy::registry::inventory::submit! {
76 $crate::policy::PolicyRegistration {
77 id: $id,
78 factory: $factory,
79 }
80 }
81 };
82}