pub struct RefactorSession { /* private fields */ }Expand description
One server’s refactor surface: the confirmations it has issued and whether it may write.
The write gate lives here rather than at each call site so there is exactly one place that decides it, and it is fixed when the session is created — a gate re-read per call could be changed underneath a running server.
Implementations§
Source§impl RefactorSession
impl RefactorSession
Sourcepub fn new(write_allowed: bool) -> Self
pub fn new(write_allowed: bool) -> Self
Opens a session. write_allowed is the environment gate, already decided by the host.
Sourcepub fn read_only() -> Self
pub fn read_only() -> Self
A session that will never write, for callers that only plan.
Named rather than a bare new(false) so a caller that meant to pass a real gate cannot
silently get a closed one — which is exactly the bug this replaced.
Sourcepub fn call(
&self,
state: &RepositoryState,
name: &str,
arguments: &Value,
) -> Result<Value, String>
pub fn call( &self, state: &RepositoryState, name: &str, arguments: &Value, ) -> Result<Value, String>
Calls one refactor operation.
§Errors
Returns an error only when name is not a tool the contract declares. Every other
refusal is a value carrying a contract status, because an agent branches on statuses and
cannot branch on a transport error.