permission

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package permission evaluates tool permission rules. Rule and YAML-object order are preserved because the last matching rule wins.

Index

Constants

View Source
const (
	ActionAllow = "allow"
	ActionDeny  = "deny"
	ActionAsk   = "ask"
)

Variables

This section is empty.

Functions

func WildcardMatch

func WildcardMatch(value string, pattern string) bool

WildcardMatch matches value against pattern: * spans any number of UTF-16 code units, ? spans one, and a trailing " *" is optional as a unit.

Types

type AskInput

type AskInput struct {
	Request
	Ruleset Ruleset `json:"ruleset"`
}

AskInput is the tool-context request shape evaluated by the live registry.

type Config

type Config struct {
	Entries []ConfigEntry
}

Config keeps permission entries in the order the config listed them.

func ConfigFromFrontmatter

func ConfigFromFrontmatter(markdown string) (Config, error)

ConfigFromFrontmatter parses the subset of YAML used by agent permission frontmatter: ordered scalar actions and one nested pattern/action mapping.

func ParseConfigJSON

func ParseConfigJSON(data []byte) (Config, error)

ParseConfigJSON decodes a permission config object without losing key order. Integer-like keys are ordered first, numerically.

func (*Config) UnmarshalJSON

func (c *Config) UnmarshalJSON(data []byte) error

type ConfigEntry

type ConfigEntry struct {
	Permission string
	Action     *string
	Patterns   []PatternAction
}

ConfigEntry is one permission entry in config source order.

type DeniedError

type DeniedError struct {
	Ruleset Ruleset
}

DeniedError is returned when Ask finds a deny rule.

func (DeniedError) Error

func (e DeniedError) Error() string

type PatternAction

type PatternAction struct {
	Pattern string
	Action  string
}

PatternAction is one nested config entry.

type Request

type Request struct {
	ID         string         `json:"id"`
	SessionID  string         `json:"sessionID"`
	Permission string         `json:"permission"`
	Patterns   []string       `json:"patterns"`
	Metadata   map[string]any `json:"metadata"`
	Always     []string       `json:"always"`
}

Request is the value-level pending request shape.

type Rule

type Rule struct {
	Permission string
	Pattern    string
	Action     string
	// contains filtered or unexported fields
}

Rule is one permission/pattern/action entry.

func Evaluate

func Evaluate(permission string, pattern string, rulesets ...Ruleset) Rule

Evaluate returns the last matching rule across the flattened rulesets.

func (Rule) MarshalJSON

func (r Rule) MarshalJSON() ([]byte, error)

func (*Rule) UnmarshalJSON

func (r *Rule) UnmarshalJSON(data []byte) error

type Ruleset

type Ruleset []Rule

Ruleset is evaluated in slice order; the last matching rule wins.

func FromConfig

func FromConfig(config Config) Ruleset

FromConfig flattens an ordered config object.

func Merge

func Merge(rulesets ...Ruleset) Ruleset

Merge concatenates rulesets without deduplication.

func RulesetFromFrontmatter

func RulesetFromFrontmatter(markdown string) (Ruleset, error)

RulesetFromFrontmatter parses the permission mapping of an agent Markdown document while preserving YAML source order.

type Service

type Service struct {
	Approved Ruleset
}

Service is the autonomous permission evaluator. Literal ask and allow both proceed; only deny returns an error.

func (*Service) Ask

func (s *Service) Ask(permission string, patterns []string, rules Ruleset) error

Ask evaluates every pattern against request rules followed by approvals.

func (*Service) Evaluate

func (s *Service) Evaluate(input AskInput) error

Evaluate preserves the full request metadata while applying autonomous Ask.

func (*Service) Pending

func (s *Service) Pending() []Request

Pending returns no requests: the autonomous evaluator never queues one.

type StringSet

type StringSet struct {
	// contains filtered or unexported fields
}

StringSet is an insertion-ordered string set.

func Disabled

func Disabled(tools []string, rules Ruleset) StringSet

Disabled returns tools disabled by a final whole-permission deny.

func (StringSet) Has

func (s StringSet) Has(value string) bool

Has reports set membership.

func (StringSet) Values

func (s StringSet) Values() []string

Values returns the members in insertion order.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL