session

package
v0.1.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package session holds session-scoped contracts and views for the feature SDK (design §2, §16).

Index

Constants

View Source
const MaxEvidenceCodeBytes = 64

MaxEvidenceCodeBytes is the maximum length of a classification evidence code.

Variables

This section is empty.

Functions

func WithSecureTurnPolicy

func WithSecureTurnPolicy(ctx context.Context, view SecureTurnPolicyView) context.Context

WithSecureTurnPolicy attaches the minimal policy view authorized by core for the current secure-session turn. It has no wire representation and no content, lineage, credential, or resume-token fields.

func WithSessionView

func WithSessionView(ctx context.Context, view SessionView) context.Context

WithSessionView attaches a defensive copy of the proxy-authoritative session snapshot to ctx. The snapshot is safe for feature plugins and never contains credentials or resume proofs.

func WithoutSecureTurnPolicy

func WithoutSecureTurnPolicy(ctx context.Context) context.Context

WithoutSecureTurnPolicy masks any inherited secure-turn policy in ctx. Core uses this when it projects a detached child without an authoritative session, preserving the primary-turn authority boundary for SDK consumers.

Types

type Classification

type Classification struct {
	Kind       Kind
	Source     ClassificationSource
	Confidence ConfidenceBand
	Evidence   EvidenceCode
	Revision   uint64
}

Classification is an immutable-by-convention scalar snapshot of advisory session classification. Its zero value represents unknown; it is not an authorization, identity, routing, or billing decision.

func (Classification) IsCodingAgent

func (c Classification) IsCodingAgent() bool

IsCodingAgent reports whether this is a well-formed positive classification. Malformed positive values are treated as unknown by consumers.

func (Classification) Validate

func (c Classification) Validate() error

Validate checks that the snapshot uses only the bounded V1 vocabulary and that unknown is represented by the all-zero value.

type ClassificationSource

type ClassificationSource string

ClassificationSource identifies the bounded source of a positive classification.

const (
	// SourceLocalIdentity records decisive local client-identity evidence.
	SourceLocalIdentity ClassificationSource = "local_identity"
	// SourceLocalTooling records decisive local tool-category evidence.
	SourceLocalTooling ClassificationSource = "local_tooling"
	// SourceRemote records a positive remote-classifier decision.
	SourceRemote ClassificationSource = "remote_classifier"
)

type ConfidenceBand

type ConfidenceBand string

ConfidenceBand is the bounded confidence vocabulary exposed to SDK consumers.

const (
	// ConfidenceUnknown is used only by the all-zero unknown classification.
	ConfidenceUnknown ConfidenceBand = ""
	// ConfidenceHigh is the V1 positive confidence band.
	ConfidenceHigh ConfidenceBand = "high"
)

type EvidenceCode

type EvidenceCode string

EvidenceCode is an opaque, bounded diagnostic code. It must contain only ASCII letters, digits, dots, underscores, or hyphens.

type Kind

type Kind string

Kind identifies the bounded classification attached to a session.

const (
	// KindUnknown is the zero-value session classification.
	KindUnknown Kind = ""
	// KindCodingAgent marks a session with accepted coding-agent evidence.
	KindCodingAgent Kind = "coding_agent"
)

type OpenInput

type OpenInput struct {
	TraceID   string
	Principal execview.PrincipalView
	Session   SessionView
}

OpenInput is the read-only context passed to Opener.Open before submit-time shaping (design §3).

type OpenResult

type OpenResult struct {
	SessionLabelUpserts map[string]string
}

OpenResult carries optional session metadata upserts from one opener invocation.

func (OpenResult) Merge

func (r OpenResult) Merge(other OpenResult) OpenResult

Merge combines label upserts from other into r (other wins on key collision).

type Opener

type Opener interface {
	ID() string
	Open(ctx context.Context, in OpenInput) (OpenResult, error)
}

Opener runs during the session_open stage after transport identity and before submit hooks (R5, R12).

type SecureTurnPolicyView

type SecureTurnPolicyView struct {
	TranscriptEnabled bool
}

SecureTurnPolicyView is the content-free secure-session policy needed by SDK consumers. Presence means the proxy has authorized the current turn; no secure-session domain object or turn/session identifier is exposed.

func SecureTurnPolicyFromContext

func SecureTurnPolicyFromContext(ctx context.Context) (SecureTurnPolicyView, bool)

SecureTurnPolicyFromContext returns the authorized policy view attached with WithSecureTurnPolicy.

type SessionView

type SessionView struct {
	// AuthoritativeSessionID is the proxy-owned secure session identifier when issued; empty before secure-session bind.
	AuthoritativeSessionID string
	// ClientSessionHint is the client-supplied conversation or session hint (never proof of ownership).
	ClientSessionHint string
	// ALegID is the resolved B2BUA A-leg identifier for this request.
	ALegID string
	// IsNew is true when the A-leg row appears newly created for this touch (CreatedAt equals LastSeenAt).
	IsNew bool
	// WorkspaceID is the resolved workspace identifier when the workspace resolver provides one.
	WorkspaceID string
	// ResumeEligible is true when secure-session policy allows resume for this session; set from [app.Manager.BeginTurn] when applicable.
	ResumeEligible bool
	// Labels carries active treatment / policy labels (including session_open upserts).
	Labels map[string]string
	// Classification is the bounded, read-only session classification snapshot.
	Classification Classification
	// TurnID is the proxy-owned secure-session turn identifier when secure sessions are active.
	TurnID string
}

SessionView is a read-only snapshot of session state exposed to plugins (design §2).

func SessionViewFromContext

func SessionViewFromContext(ctx context.Context) (SessionView, bool)

SessionViewFromContext returns a defensive copy of the proxy-authoritative session snapshot attached with WithSessionView.

func (SessionView) PartitionKey

func (v SessionView) PartitionKey() string

PartitionKey returns the key used for session-scoped plugin state: authoritative id when set, otherwise the client hint.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL