Documentation
¶
Overview ¶
Package permission evaluates tool permission rules. Rule and YAML-object order are preserved because the last matching rule wins.
Index ¶
Constants ¶
const ( ActionAllow = "allow" ActionDeny = "deny" ActionAsk = "ask" )
Variables ¶
This section is empty.
Functions ¶
func WildcardMatch ¶
WildcardMatch matches value against pattern: * spans any number of UTF-16 code units, ? spans one, and a trailing " *" is optional as a unit.
Types ¶
type Config ¶
type Config struct {
Entries []ConfigEntry
}
Config keeps permission entries in the order the config listed them.
func ConfigFromFrontmatter ¶
ConfigFromFrontmatter parses the subset of YAML used by agent permission frontmatter: ordered scalar actions and one nested pattern/action mapping.
func ParseConfigJSON ¶
ParseConfigJSON decodes a permission config object without losing key order. Integer-like keys are ordered first, numerically.
func (*Config) UnmarshalJSON ¶
type ConfigEntry ¶
type ConfigEntry struct {
Permission string
Action *string
Patterns []PatternAction
}
ConfigEntry is one permission entry in config source order.
type DeniedError ¶
type DeniedError struct {
Ruleset Ruleset
}
DeniedError is returned when Ask finds a deny rule.
func (DeniedError) Error ¶
func (e DeniedError) Error() string
type PatternAction ¶
PatternAction is one nested config entry.
type Request ¶
type Request struct {
ID string `json:"id"`
SessionID string `json:"sessionID"`
Permission string `json:"permission"`
Patterns []string `json:"patterns"`
Metadata map[string]any `json:"metadata"`
Always []string `json:"always"`
}
Request is the value-level pending request shape.
type Rule ¶
type Rule struct {
Permission string
Pattern string
Action string
// contains filtered or unexported fields
}
Rule is one permission/pattern/action entry.
func (Rule) MarshalJSON ¶
func (*Rule) UnmarshalJSON ¶
type Ruleset ¶
type Ruleset []Rule
Ruleset is evaluated in slice order; the last matching rule wins.
func FromConfig ¶
FromConfig flattens an ordered config object.
func RulesetFromFrontmatter ¶
RulesetFromFrontmatter parses the permission mapping of an agent Markdown document while preserving YAML source order.
type Service ¶
type Service struct {
Approved Ruleset
}
Service is the autonomous permission evaluator. Literal ask and allow both proceed; only deny returns an error.