#[non_exhaustive]pub enum CommandOrigin {
DirectSafeUserAct {
evidence_digest: Digest,
},
ConfirmedInteraction {
interaction_id: InteractionId,
payload_hash: Digest,
interaction_kind: InteractionKind,
action_class: ActionClass,
channel: ResolutionChannel,
},
InternalPolicy {
policy_key: String,
},
ExternalCallback {
callback_id: String,
signature_verified: bool,
},
}Expand description
Who or what authorized a command (spec §14.2).
The enum grows as new authorization sources appear, so downstream matches need a wildcard arm.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
DirectSafeUserAct
A low-risk act grounded directly in validated user evidence.
ConfirmedInteraction
A stored option of a persisted interaction was chosen.
The three qualifying fields answer what was confirmed: the shape of the card, what its chosen option authorizes, and how the answer arrived. Without them a click on a “which trip did you mean?” card would be indistinguishable from a qualified signature (I12).
Fields
interaction_id: InteractionIdThe interaction.
interaction_kind: InteractionKindShape of the card that was answered.
action_class: ActionClassWhat the chosen option authorizes.
channel: ResolutionChannelHow the answer reached the server.
InternalPolicy
A server-side policy decided the command (e.g. automatic follow-up, or a qualified professional’s review recorded out of band).
ExternalCallback
An external system called back.
Implementations§
Source§impl CommandOrigin
impl CommandOrigin
Sourcepub fn is_trusted(&self) -> bool
pub fn is_trusted(&self) -> bool
Returns true when the origin may authorize commands above
RiskClass::ReversibleLowRisk (I12).
A confirmed interaction is trusted only when the chosen option actually authorizes commands and the answer did not come from an inference: a dismissed card and a model-interpreted “yes” are both untrusted.
Sourcepub fn satisfies_confirmation(&self, confirmation: ConfirmationPolicy) -> bool
pub fn satisfies_confirmation(&self, confirmation: ConfirmationPolicy) -> bool
Returns true when this origin is the specific authorization
ConfirmationPolicy demands (spec §14.3, §15.7).
The mapping is deliberately narrow, because a confirmation is a statement about one act by one authority:
| Policy | Accepted origin |
|---|---|
None | any |
ReviewCard, ExplicitClick | a ConfirmCommand or ReviewChanges card whose chosen option authorizes commands |
Reauthentication | a Reauthenticate card, or a verified external callback |
QualifiedSignature | an ExternalSignature card, or a verified external callback |
HumanProfessionalReview | an internal policy or a verified external callback — never the end user’s own click |
A ResolutionChannel::ModelInterpreted answer satisfies no policy but
ConfirmationPolicy::None.
Trait Implementations§
Source§impl Clone for CommandOrigin
impl Clone for CommandOrigin
Source§impl Debug for CommandOrigin
impl Debug for CommandOrigin
Source§impl<'de> Deserialize<'de> for CommandOrigin
impl<'de> Deserialize<'de> for CommandOrigin
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for CommandOrigin
Source§impl Hash for CommandOrigin
impl Hash for CommandOrigin
Source§impl PartialEq for CommandOrigin
impl PartialEq for CommandOrigin
Source§impl Serialize for CommandOrigin
impl Serialize for CommandOrigin
impl StructuralPartialEq for CommandOrigin
Auto Trait Implementations§
impl Freeze for CommandOrigin
impl RefUnwindSafe for CommandOrigin
impl Send for CommandOrigin
impl Sync for CommandOrigin
impl Unpin for CommandOrigin
impl UnsafeUnpin for CommandOrigin
impl UnwindSafe for CommandOrigin
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.