Documentation
¶
Overview ¶
Package terminalpolicy provides the provider-neutral HTTP adapter for the process-owned terminal-decision policy.
Index ¶
Constants ¶
This section is empty.
Variables ¶
View Source
var ( // ErrUnauthenticated identifies an authentication failure before a // principal or operator scope is available. ErrUnauthenticated = errors.New("terminal policy: unauthenticated") // ErrSecureSessionRequired identifies a client principal without current // secure-session authority. ErrSecureSessionRequired = errors.New("terminal policy: secure session required") // ErrForbidden identifies an authenticated principal without target scope. ErrForbidden = errors.New("terminal policy: forbidden") // ErrSessionNotFound identifies an authorized operator target that does not // exist. It is intentionally distinct from authorization failure. ErrSessionNotFound = errors.New("terminal policy: session not found") )
Functions ¶
Types ¶
type Options ¶
type Options struct {
Store *sessionpolicy.Store
// FeatureStatus reports whether the generic feature is known and whether
// its provider is currently active. A known but inactive feature remains
// mountable and is reported with available=false.
FeatureStatus func(context.Context, string) (known, available bool, err error)
// ResolveClientScope resolves the current authoritative client scope. The
// feature ID is supplied separately from the request path for callers that
// bind authority to the admitted request.
ResolveClientScope func(context.Context, *http.Request, string) (sessionpolicy.Key, sessionpolicy.Authority, error)
// AuthorizeOperatorTarget validates an authenticated operator and target
// session. The callback receives only bounded path identities.
AuthorizeOperatorTarget func(context.Context, *http.Request, string, string) (sessionpolicy.Key, sessionpolicy.Authority, error)
// GenerationDefault supplies the immutable generation default used by the
// core store's effective-state calculation.
GenerationDefault func(string) bool
MaxBodyBytes int64
}
Options configures the narrow endpoint adapter. Authority callbacks are supplied by existing authentication and secure-session middleware; this package does not inspect credentials or create an authorization system.
Click to show internal directories.
Click to hide internal directories.