Skip to main content

Module policy

Module policy 

Source
Expand description

Whether a command may run now, and if not, what would let it (spec §14.3).

PolicySnapshot::decide in core answers the narrow question: does this origin satisfy this policy? PolicyEngine answers the question a turn actually asks, which has three more inputs — the constraints the user put on the turn (“do not submit anything yet”), the orchestration mode, and the configuration — and which has to produce not just a verdict but the card that would change it.

§Gates, in order

  1. Mode (§11.4). A sandboxed run is not eligible for destructive, irreversible or externally regulated commands at all. No card helps.

  2. Constraints (§10.4). Evaluated in a fixed order so the same set of constraints always names the same blocker:

  3. Policy (§14.3, I12). The core snapshot decides, against the policy as the constraints left it.

§An absent policy is a conservative policy

PolicyRequest::policy is an Option because a domain that has not classified a command is a real situation. It is treated as CommandPolicy::conservative: irreversible, explicit click, per case, server receipts only. Silence is never permission.

Modules§

reason
Reason keys the engine adds to the ones in turnframe_core::policy::reason.

Structs§

ConfirmationCopy
Server-authored copy for the cards the engine builds.
NoReviewDiff
A diff builder that shows nothing, so review cards degrade to confirmations.
PolicyEngine
Applies constraints, mode and policy to one command, and builds the card that would unblock it.
PolicyRequest
One command as the policy engine sees it.

Enums§

BlockReason
Why a command may not run, when no card the end user can click would help.
PolicyOutcome
What the engine decided about one command.

Constants§

CONFIRM_OPTION_ID
Option identifier of the confirming CTA on a card the engine builds.
DECLINE_OPTION_ID
Option identifier of the declining CTA on a card the engine builds.

Traits§

ReviewDiffBuilder
Builds the before/after lines of a InteractionKind::ReviewChanges card.