scope

package
v0.1.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package scope holds the authoritative, protocol-neutral principal/scope attribution snapshot for an accepted LLM Interactive Proxy request.

Values in this package are safe-by-construction: raw credentials, raw transport headers, bearer/API/OAuth/resume tokens, and unvetted claim values are never fields on PrincipalScopeView. Only non-secret identifiers, display labels, roles, operator-safe claims, and policy labels are carried.

The snapshot is immutable request lifecycle evidence. Consumers receive copies produced by PrincipalScopeView.Clone so roles, claims, and labels cannot be mutated through returned views.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func WithScope

WithScope returns a child context carrying the authoritative principal/scope snapshot for downstream handlers and the execution pipeline. The value is cloned so callers cannot mutate the stored scope through the returned view (requirement 5.5). A nil parent is treated as context.TODO so the result is always non-nil.

Types

type Origin

type Origin string

Origin records whether the request originated from a client or an internal auxiliary derivation (requirement 4.4).

const (
	OriginClient   Origin = "client"
	OriginInternal Origin = "internal"
)

type PrincipalScopeView

type PrincipalScopeView struct {
	SubjectKind    SubjectKind       `json:"subject_kind"`
	PrincipalID    Value             `json:"principal_id"`
	DisplayName    Value             `json:"display_name"`
	AuthMethod     Value             `json:"auth_method"`
	CredentialID   Value             `json:"credential_id"`
	Roles          []string          `json:"roles,omitempty"`
	SafeClaims     map[string]string `json:"safe_claims,omitempty"`
	TenantID       Value             `json:"tenant_id"`
	OrganizationID Value             `json:"organization_id"`
	WorkspaceID    Value             `json:"workspace_id"`
	ProjectID      Value             `json:"project_id"`
	DepartmentID   Value             `json:"department_id"`
	CostCenterID   Value             `json:"cost_center_id"`
	PolicyLabels   map[string]string `json:"policy_labels,omitempty"`
	Origin         Origin            `json:"origin"`
	ParentTraceID  Value             `json:"parent_trace_id"`
}

PrincipalScopeView is the authoritative, protocol-neutral principal and scope attribution snapshot for one accepted request. It is safe-by-construction: raw credentials, raw transport headers, bearer/API/OAuth/resume tokens, and unvetted claim values are never fields here.

func ScopeFromContext

func ScopeFromContext(ctx context.Context) (PrincipalScopeView, bool)

ScopeFromContext returns the authoritative scope attached with WithScope, if any. The returned view is a copy of the stored snapshot. A nil ctx is tolerated and returns (PrincipalScopeView{}, false).

func (PrincipalScopeView) Clone

Clone returns a deep copy of the view so roles, safe claims, and policy labels cannot be mutated through the returned view (requirements 5.5, 4.2). Nil slices and maps are preserved as nil.

func (PrincipalScopeView) Principal

Principal projects the authoritative scope onto the legacy execview.PrincipalView compatibility shape, preserving identity, display label, roles, and claims (requirements 1.5, 4.6, 7.3). Unknown scope values project to empty strings; roles and safe claims are copied so callers cannot mutate the authoritative scope through the projection.

type SubjectKind

type SubjectKind string

SubjectKind classifies the request caller category (requirement 1.2).

const (
	SubjectUnknown SubjectKind = "unknown"
	SubjectHuman   SubjectKind = "human"
	SubjectService SubjectKind = "service"
	SubjectLocal   SubjectKind = "local"
)

type Value

type Value struct {
	Known bool   `json:"known"`
	Value string `json:"value"`
}

Value is a presence-aware string used for attribution fields where unknown must be distinguished from a known-but-empty value. The zero Value is unknown.

func Known

func Known(s string) Value

Known returns a Value representing a known attribution field, including a known-empty string ("").

func Unknown

func Unknown() Value

Unknown returns a Value representing an unknown attribution field.

func (Value) Equal

func (v Value) Equal(o Value) bool

Equal reports whether two Values share presence and string content.

func (Value) IsKnown

func (v Value) IsKnown() bool

IsKnown reports whether the value is known, including known-empty.

func (Value) IsKnownEmpty

func (v Value) IsKnownEmpty() bool

IsKnownEmpty reports whether the value is known and intentionally empty.

func (Value) IsUnknown

func (v Value) IsUnknown() bool

IsUnknown reports whether the value is unknown (not supplied).

func (Value) String

func (v Value) String() string

String returns the underlying string for known values and "" for unknown.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL