Documentation
¶
Overview ¶
Package scope holds the authoritative, protocol-neutral principal/scope attribution snapshot for an accepted LLM Interactive Proxy request.
Values in this package are safe-by-construction: raw credentials, raw transport headers, bearer/API/OAuth/resume tokens, and unvetted claim values are never fields on PrincipalScopeView. Only non-secret identifiers, display labels, roles, operator-safe claims, and policy labels are carried.
The snapshot is immutable request lifecycle evidence. Consumers receive copies produced by PrincipalScopeView.Clone so roles, claims, and labels cannot be mutated through returned views.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func WithScope ¶
func WithScope(ctx context.Context, v PrincipalScopeView) context.Context
WithScope returns a child context carrying the authoritative principal/scope snapshot for downstream handlers and the execution pipeline. The value is cloned so callers cannot mutate the stored scope through the returned view (requirement 5.5). A nil parent is treated as context.TODO so the result is always non-nil.
Types ¶
type Origin ¶
type Origin string
Origin records whether the request originated from a client or an internal auxiliary derivation (requirement 4.4).
type PrincipalScopeView ¶
type PrincipalScopeView struct {
SubjectKind SubjectKind `json:"subject_kind"`
PrincipalID Value `json:"principal_id"`
DisplayName Value `json:"display_name"`
AuthMethod Value `json:"auth_method"`
CredentialID Value `json:"credential_id"`
Roles []string `json:"roles,omitempty"`
SafeClaims map[string]string `json:"safe_claims,omitempty"`
TenantID Value `json:"tenant_id"`
OrganizationID Value `json:"organization_id"`
WorkspaceID Value `json:"workspace_id"`
ProjectID Value `json:"project_id"`
DepartmentID Value `json:"department_id"`
CostCenterID Value `json:"cost_center_id"`
PolicyLabels map[string]string `json:"policy_labels,omitempty"`
Origin Origin `json:"origin"`
ParentTraceID Value `json:"parent_trace_id"`
}
PrincipalScopeView is the authoritative, protocol-neutral principal and scope attribution snapshot for one accepted request. It is safe-by-construction: raw credentials, raw transport headers, bearer/API/OAuth/resume tokens, and unvetted claim values are never fields here.
func ScopeFromContext ¶
func ScopeFromContext(ctx context.Context) (PrincipalScopeView, bool)
ScopeFromContext returns the authoritative scope attached with WithScope, if any. The returned view is a copy of the stored snapshot. A nil ctx is tolerated and returns (PrincipalScopeView{}, false).
func (PrincipalScopeView) Clone ¶
func (v PrincipalScopeView) Clone() PrincipalScopeView
Clone returns a deep copy of the view so roles, safe claims, and policy labels cannot be mutated through the returned view (requirements 5.5, 4.2). Nil slices and maps are preserved as nil.
func (PrincipalScopeView) Principal ¶
func (v PrincipalScopeView) Principal() execview.PrincipalView
Principal projects the authoritative scope onto the legacy execview.PrincipalView compatibility shape, preserving identity, display label, roles, and claims (requirements 1.5, 4.6, 7.3). Unknown scope values project to empty strings; roles and safe claims are copied so callers cannot mutate the authoritative scope through the projection.
type SubjectKind ¶
type SubjectKind string
SubjectKind classifies the request caller category (requirement 1.2).
const ( SubjectUnknown SubjectKind = "unknown" SubjectHuman SubjectKind = "human" SubjectService SubjectKind = "service" SubjectLocal SubjectKind = "local" )
type Value ¶
Value is a presence-aware string used for attribution fields where unknown must be distinguished from a known-but-empty value. The zero Value is unknown.
func Known ¶
Known returns a Value representing a known attribution field, including a known-empty string ("").
func Unknown ¶
func Unknown() Value
Unknown returns a Value representing an unknown attribution field.
func (Value) IsKnownEmpty ¶
IsKnownEmpty reports whether the value is known and intentionally empty.