execview

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 2 Imported by: 0

Documentation

Overview

Package execview holds stable, transport-agnostic identity and attempt views for feature plugins (design §2), plus WithPrincipal / PrincipalFromContext for the canonical principal in context.Context (set at the transport edge, read by the core). WithFrontendID / FrontendIDFromContext carry the auth wire frontend label for the same request (session-start audit alignment with auth decision events). Values are snapshots; plugins must not treat them as authoritative for mutation—use documented extension stages instead.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func FrontendIDFromContext

func FrontendIDFromContext(ctx context.Context) (string, bool)

FrontendIDFromContext returns the frontend id attached with WithFrontendID, if any. The second result is false when unset or when the stored value is not a string. A nil ctx is tolerated and returns ("", false).

func WithFrontendID

func WithFrontendID(ctx context.Context, frontendID string) context.Context

WithFrontendID returns a child context carrying the auth wire frontend id (same vocabulary as transport auth decision events, e.g. openai_compatible, anthropic, gemini). Transport wiring sets this at the edge; the executor reads it for session-start audit without importing HTTP packages. Whitespace-only ids are ignored (returns ctx unchanged) so a caller does not clobber a parent value. A nil parent is treated as context.TODO.

func WithPrincipal

func WithPrincipal(ctx context.Context, p PrincipalView) context.Context

WithPrincipal returns a child context carrying the canonical principal for downstream handlers and the execution pipeline. A nil parent is treated as context.TODO so the result is always non-nil and safe for functions that do not allow nil context.Context.

Transport auth sets this at the edge; the policy core reads the same value without importing transport packages (introduce-hexagonal-architecture task 4.1).

Types

type AttemptView

type AttemptView struct {
	TraceID    string
	BLegID     string
	AttemptSeq int
	BackendID  string
	RouteRole  string
}

AttemptView captures attempt-scoped lineage metadata for one backend open (design §2).

type PrincipalView

type PrincipalView struct {
	ID          string
	DisplayName string
	Roles       []string
	Claims      map[string]string
}

PrincipalView is a generic identity snapshot visible to plugins (no HTTP or auth-provider types). For richer request attribution (subject kind, credential id, tenant/org/project/department/cost center, policy labels, origin — see [scope.PrincipalScopeView] in pkg/lipsdk/scope), this type is the legacy compatibility projection derived from the authoritative scope view.

func PrincipalFromContext

func PrincipalFromContext(ctx context.Context) (PrincipalView, bool)

PrincipalFromContext returns the principal attached with WithPrincipal, if any. A nil ctx is tolerated and returns (PrincipalView{}, false).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL