pub struct FilteredToolExecutor { /* private fields */ }Expand description
Wraps an ErasedToolExecutor and enforces a ToolPolicy plus an optional
additional denylist (disallowed).
All calls are checked against the policy and the denylist before being forwarded
to the inner executor. The denylist is evaluated first — a tool in disallowed
is blocked even if policy would allow it (deny wins). Rejected calls return a
descriptive ToolError.
Implementations§
Source§impl FilteredToolExecutor
impl FilteredToolExecutor
Sourcepub fn new(inner: Arc<dyn ErasedToolExecutor>, policy: ToolPolicy) -> Self
pub fn new(inner: Arc<dyn ErasedToolExecutor>, policy: ToolPolicy) -> Self
Create a new filtered executor with the given policy and no additional denylist.
Use with_disallowed when the agent definition also
specifies tools.except entries.
Sourcepub fn with_disallowed(
inner: Arc<dyn ErasedToolExecutor>,
policy: ToolPolicy,
disallowed: Vec<String>,
) -> Self
pub fn with_disallowed( inner: Arc<dyn ErasedToolExecutor>, policy: ToolPolicy, disallowed: Vec<String>, ) -> Self
Create a new filtered executor with an additional denylist.
Tools in disallowed are blocked regardless of the base policy
(deny wins over allow).
Trait Implementations§
Source§impl ErasedToolExecutor for FilteredToolExecutor
impl ErasedToolExecutor for FilteredToolExecutor
Source§fn execute_tool_call_confirmed_erased<'a>(
&'a self,
call: &'a ToolCall,
) -> Pin<Box<dyn Future<Output = Result<Option<ToolOutput>, ToolError>> + Send + 'a>>
fn execute_tool_call_confirmed_erased<'a>( &'a self, call: &'a ToolCall, ) -> Pin<Box<dyn Future<Output = Result<Option<ToolOutput>, ToolError>> + Send + 'a>>
Same policy as execute_tool_call_erased: the confirmed path must go through the
same allow/deny check, not bypass it. Mirrors the removed trait default’s behavior
(delegate to execute_tool_call_erased) while preserving the policy enforcement
already present there.
fn execute_erased<'a>( &'a self, response: &'a str, ) -> Pin<Box<dyn Future<Output = Result<Option<ToolOutput>, ToolError>> + Send + 'a>>
fn execute_confirmed_erased<'a>( &'a self, response: &'a str, ) -> Pin<Box<dyn Future<Output = Result<Option<ToolOutput>, ToolError>> + Send + 'a>>
fn tool_definitions_erased(&self) -> Vec<ToolDef>
fn execute_tool_call_erased<'a>( &'a self, call: &'a ToolCall, ) -> Pin<Box<dyn Future<Output = Result<Option<ToolOutput>, ToolError>> + Send + 'a>>
Source§fn set_skill_env(&self, env: Option<HashMap<String, String>>)
fn set_skill_env(&self, env: Option<HashMap<String, String>>)
Source§fn set_effective_trust(&self, level: SkillTrustLevel)
fn set_effective_trust(&self, level: SkillTrustLevel)
Source§fn is_tool_retryable_erased(&self, tool_id: &str) -> bool
fn is_tool_retryable_erased(&self, tool_id: &str) -> bool
Source§fn requires_confirmation_erased(&self, call: &ToolCall) -> bool
fn requires_confirmation_erased(&self, call: &ToolCall) -> bool
Source§fn checkpoint_undo_erased(&self, n: usize) -> CheckpointActionResult
fn checkpoint_undo_erased(&self, n: usize) -> CheckpointActionResult
n checkpointed write commands. Read moreSource§fn checkpoint_redo_erased(&self) -> CheckpointActionResult
fn checkpoint_redo_erased(&self) -> CheckpointActionResult
Source§fn checkpoint_list_erased(&self) -> CheckpointListResult
fn checkpoint_list_erased(&self) -> CheckpointListResult
Auto Trait Implementations§
impl !RefUnwindSafe for FilteredToolExecutor
impl !UnwindSafe for FilteredToolExecutor
impl Freeze for FilteredToolExecutor
impl Send for FilteredToolExecutor
impl Sync for FilteredToolExecutor
impl Unpin for FilteredToolExecutor
impl UnsafeUnpin for FilteredToolExecutor
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request