access

package
v0.27.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package access is the host's gating vocabulary shared by content interactions and media: the authenticated Actor, the ContentResolver port and its Resolution. It has no dependencies beyond contentref.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Actor

type Actor struct {
	ID        string // stable subject id (uuid text); empty when Anonymous
	Kind      string // opaque: "user" | "service" | "delegated" | ...
	IP        string // anon fallback key for reactions / poll votes
	Anonymous bool
}

Actor is the already-authenticated caller. ContentKit never authenticates.

type ContentResolver

type ContentResolver interface {
	Resolve(ctx context.Context, ref contentref.ContentRef, actor Actor) (Resolution, error)
}

ContentResolver is the one mandatory content hook and the whole gating surface: it says whether a ContentRef exists, is visible and is accessible to the actor. Callers invoke it once per item per request; an error denies.

type Resolution

type Resolution struct {
	// Ref is the canonical reference every row is stored and read under (an
	// alias or slug resolves to it). A zero Ref keeps the requested one; a Ref
	// of another tenant is an error.
	Ref contentref.ContentRef
	// Visible = published and not soft-deleted. Teasers need only Visible.
	Visible bool
	// Accessible = the actor may consume it: an opaque host verdict
	// (entitlement, purchase, ACL, flag). ContentKit imposes no access model.
	Accessible bool
	// PreviewLimit caps a Visible item to its first N ordered units (pages,
	// files), whatever Accessible says. 0 = no cap. Content interactions
	// ignore it.
	PreviewLimit int
	// Editor = the actor may edit the item (its creator, staff): media signs
	// EditorOnly variants and returns edit metadata only for editors. It
	// grants nothing beyond what Visible, Accessible and PreviewLimit allow.
	Editor bool
}

Resolution is the host's verdict about a content reference for one actor.

func (Resolution) Full

func (r Resolution) Full() bool

Full reports unrestricted access: every unit is served.

func (Resolution) Units

func (r Resolution) Units(total int) int

Units returns how many leading units of an ordered list of total units the resolution grants.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL