authz

package
v0.3.0-alpha.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 27, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package authz defines intent and impact authorization contracts for governed Actions without prescribing a policy language or storage implementation.

Stability: alpha. Consumers should pin an exact pre-v1 Modary version.

Index

Constants

View Source
const (
	MaxDecisionCodeRunes   = 64
	MaxDecisionReasonRunes = 512
	MaxFingerprintRunes    = 256
)

Decision field limits bound every policy-controlled value that can enter a public error, governed plan, or audit record.

Variables

This section is empty.

Functions

This section is empty.

Types

type Authorizer

type Authorizer interface {
	Authorize(context.Context, Request) (Decision, error)
}

Authorizer evaluates current policy for ordinary or governed operations. Policy denial is expressed as a successful denied Decision. A returned error is an operational dependency failure and Runtime classifies it as CodeInternal. The same Authorizer may be called concurrently; implementations must be safe for concurrent use, honor context cancellation and deadlines, and treat each Request as immutable for the duration of the call.

type Constraints

type Constraints struct {
	MaxRows int `json:"max_rows,omitempty"`
}

Constraints contains limits that an allowed decision still enforces.

type Decision

type Decision struct {
	Allowed            bool        `json:"allowed"`
	Code               string      `json:"code,omitempty"`
	Reason             string      `json:"reason,omitempty"`
	RequiredPermission string      `json:"required_permission,omitempty"`
	Constraints        Constraints `json:"constraints,omitempty"`
	Fingerprint        string      `json:"fingerprint"`
}

Decision records allow/deny state, public diagnostics, constraints, and a policy fingerprint used to detect changes between Preview and Execute. A denied custom Code is public only when the Action descriptor declares it with action.ErrorKindDenied; Reason is presented directly and must satisfy the documented bounded text contract.

type Impact

type Impact struct {
	Rows      int      `json:"rows,omitempty"`
	Resources []string `json:"resources,omitempty"`
}

Impact is the bounded mutation footprint presented to policy.

type Phase

type Phase string

Phase identifies whether policy is evaluating requested intent or a concrete planned impact.

const (
	PhaseIntent Phase = "intent"
	PhaseImpact Phase = "impact"
)

Authorization phases describe an operation before and after its concrete mutation footprint is known. Ordinary business handlers usually evaluate only PhaseIntent.

type Request

type Request struct {
	Actor       identity.Actor
	OperationID string
	Permission  string
	Scope       scope.Execution
	Phase       Phase
	Impact      Impact
}

Request contains the complete policy input for one authorization decision.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL