Skip to main content

LocalConfigApprovalIdentityResolver

Struct LocalConfigApprovalIdentityResolver 

pub struct LocalConfigApprovalIdentityResolver;
Expand description

Config-backed resolver over [sop.approval].groups.*.members. Stateless: it reads the config handed to it on each call, so there is no second copy of the membership map to go stale. A member entry may be source-qualified (<source>:<identity>, e.g. http:<subject>, agent:<alias>) to grant rights on ONE transport only - so a subject on the gateway and the same string on the agent tool do not collide - or a bare identity to grant it from any source. Channel principals are stricter: they match only channel:<channel-key>:<sender>, never channel:<sender> or a bare sender, so same-looking platform ids from different channel aliases cannot collide. A principal with no identity (e.g. the system tick) belongs to no group.

NOTE on the identity each surface actually PRODUCES today. The gateway HTTP and WS paths both produce the paired-token hash (a stable per-device subject); they share it, so for quorum they collapse to ONE canonical gateway voter (see super::principal::ApprovalPrincipal::voter_key). The agent tool produces the agent alias. The loopback CLI (zeroclaw sop approve) is currently ANONYMOUS - the admin path builds ApprovalPrincipal::cli(None) - so a cli:<user> group member is NOT satisfiable yet; it is reserved for a future CLI that forwards a trusted local identity, so do not gate a policy on cli:<user> expecting the current CLI to meet it. A future auth resolver (the documented junction seam) is where a per-PERSON canonical identity - linking a user’s several device/channel subjects to one account - belongs; until then membership is per-subject.

Trait Implementations§

Source§

impl ApprovalIdentityResolver for LocalConfigApprovalIdentityResolver

Source§

fn groups_for( &self, cfg: &SopApprovalConfig, principal: &ApprovalPrincipal, ) -> Vec<String>

The groups this principal belongs to under cfg (may be empty).
Source§

fn is_member( &self, cfg: &SopApprovalConfig, principal: &ApprovalPrincipal, group: &str, ) -> bool

Whether the principal is a member of group under cfg.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,