#[non_exhaustive]pub struct PolicySnapshot {
pub default_policy: CommandPolicy,
pub forbidden_risk_classes: Vec<RiskClass>,
pub max_direct_risk: RiskClass,
pub allow_text_resolution_for_low_risk: bool,
}Expand description
Point-in-time policy configuration the reducer evaluates against.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.default_policy: CommandPolicyPolicy for commands the domain did not classify.
forbidden_risk_classes: Vec<RiskClass>Risk classes that may never execute (e.g. in a sandbox: everything above
ReversibleLowRisk).
max_direct_risk: RiskClassHighest risk a command may carry while originating from an untrusted
origin such as CommandOrigin::DirectSafeUserAct. Default
ReversibleLowRisk (I12).
The setting may only tighten: origin_satisfies refuses anything
above ReversibleLowRisk from an untrusted origin whatever the
snapshot says.
allow_text_resolution_for_low_risk: boolWhether low-risk interactions may be resolved from interpreted text when their stored policy permits it (spec §13.2 rule 8).
Implementations§
Source§impl PolicySnapshot
impl PolicySnapshot
Sourcepub fn conservative() -> Self
pub fn conservative() -> Self
The default snapshot: conservative default policy, nothing forbidden,
direct acts up to ReversibleLowRisk, text resolution allowed for
low-risk cards.
There is no “fail open” setting: when the policy source cannot be
consulted the runtime has no snapshot to consult either and must return
PolicyError::Unavailable
(I19).
Sourcepub fn sandbox() -> Self
pub fn sandbox() -> Self
A snapshot for sandboxed, reversible domains: everything above
ReversibleLowRisk is forbidden (spec §11.4).
Sourcepub fn is_risk_forbidden(&self, risk: RiskClass) -> bool
pub fn is_risk_forbidden(&self, risk: RiskClass) -> bool
Returns true when the risk class may never execute.
Sourcepub fn decide(
&self,
command_ref: CommandRef,
policy: &CommandPolicy,
origin: &CommandOrigin,
) -> PolicyDecision
pub fn decide( &self, command_ref: CommandRef, policy: &CommandPolicy, origin: &CommandOrigin, ) -> PolicyDecision
Evaluates one command.
The decision answers two questions: may this command execute with the
origin it carries, and if not, which card would authorize it. A policy
only somebody other than the end user can satisfy
(ConfirmationPolicy::HumanProfessionalReview)
names no card at all.
Trait Implementations§
Source§impl Clone for PolicySnapshot
impl Clone for PolicySnapshot
Source§impl Debug for PolicySnapshot
impl Debug for PolicySnapshot
Source§impl Default for PolicySnapshot
impl Default for PolicySnapshot
Source§impl<'de> Deserialize<'de> for PolicySnapshot
impl<'de> Deserialize<'de> for PolicySnapshot
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for PolicySnapshot
Source§impl PartialEq for PolicySnapshot
impl PartialEq for PolicySnapshot
Source§impl Serialize for PolicySnapshot
impl Serialize for PolicySnapshot
impl StructuralPartialEq for PolicySnapshot
Auto Trait Implementations§
impl Freeze for PolicySnapshot
impl RefUnwindSafe for PolicySnapshot
impl Send for PolicySnapshot
impl Sync for PolicySnapshot
impl Unpin for PolicySnapshot
impl UnsafeUnpin for PolicySnapshot
impl UnwindSafe for PolicySnapshot
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.