Documentation
¶
Overview ¶
Package authz defines intent and impact authorization contracts for governed Actions without prescribing a policy language or storage implementation.
Stability: alpha. Consumers should pin an exact pre-v1 Modary version.
Index ¶
Constants ¶
const ( MaxDecisionCodeRunes = 64 MaxDecisionReasonRunes = 512 MaxFingerprintRunes = 256 )
Decision field limits bound every policy-controlled value that can enter a public error, governed plan, or audit record.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Authorizer ¶
Authorizer evaluates current policy for ordinary or governed operations. Policy denial is expressed as a successful denied Decision. A returned error is an operational dependency failure and Runtime classifies it as CodeInternal. The same Authorizer may be called concurrently; implementations must be safe for concurrent use, honor context cancellation and deadlines, and treat each Request as immutable for the duration of the call.
type Constraints ¶
type Constraints struct {
MaxRows int `json:"max_rows,omitempty"`
}
Constraints contains limits that an allowed decision still enforces.
type Decision ¶
type Decision struct {
Allowed bool `json:"allowed"`
Code string `json:"code,omitempty"`
Reason string `json:"reason,omitempty"`
RequiredPermission string `json:"required_permission,omitempty"`
Constraints Constraints `json:"constraints,omitempty"`
Fingerprint string `json:"fingerprint"`
}
Decision records allow/deny state, public diagnostics, constraints, and a policy fingerprint used to detect changes between Preview and Execute. A denied custom Code is public only when the Action descriptor declares it with action.ErrorKindDenied; Reason is presented directly and must satisfy the documented bounded text contract.
type Impact ¶
type Impact struct {
Rows int `json:"rows,omitempty"`
Resources []string `json:"resources,omitempty"`
}
Impact is the bounded mutation footprint presented to policy.