Documentation
¶
Overview ¶
Package execview holds stable, transport-agnostic identity and attempt views for feature plugins (design §2), plus WithPrincipal / PrincipalFromContext for the canonical principal in context.Context (set at the transport edge, read by the core). WithFrontendID / FrontendIDFromContext carry the auth wire frontend label for the same request (session-start audit alignment with auth decision events). Values are snapshots; plugins must not treat them as authoritative for mutation—use documented extension stages instead.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func FrontendIDFromContext ¶
FrontendIDFromContext returns the frontend id attached with WithFrontendID, if any. The second result is false when unset or when the stored value is not a string. A nil ctx is tolerated and returns ("", false).
func WithFrontendID ¶
WithFrontendID returns a child context carrying the auth wire frontend id (same vocabulary as transport auth decision events, e.g. openai_compatible, anthropic, gemini). Transport wiring sets this at the edge; the executor reads it for session-start audit without importing HTTP packages. Whitespace-only ids are ignored (returns ctx unchanged) so a caller does not clobber a parent value. A nil parent is treated as context.TODO.
func WithPrincipal ¶
func WithPrincipal(ctx context.Context, p PrincipalView) context.Context
WithPrincipal returns a child context carrying the canonical principal for downstream handlers and the execution pipeline. A nil parent is treated as context.TODO so the result is always non-nil and safe for functions that do not allow nil context.Context.
Transport auth sets this at the edge; the policy core reads the same value without importing transport packages (introduce-hexagonal-architecture task 4.1).
Types ¶
type AttemptView ¶
type AttemptView struct {
TraceID string
BLegID string
AttemptSeq int
BackendID string
RouteRole string
}
AttemptView captures attempt-scoped lineage metadata for one backend open (design §2).
type PrincipalView ¶
PrincipalView is a generic identity snapshot visible to plugins (no HTTP or auth-provider types). For richer request attribution (subject kind, credential id, tenant/org/project/department/cost center, policy labels, origin — see [scope.PrincipalScopeView] in pkg/lipsdk/scope), this type is the legacy compatibility projection derived from the authoritative scope view.
func PrincipalFromContext ¶
func PrincipalFromContext(ctx context.Context) (PrincipalView, bool)
PrincipalFromContext returns the principal attached with WithPrincipal, if any. A nil ctx is tolerated and returns (PrincipalView{}, false).