Documentation
¶
Overview ¶
Package access is the host's gating vocabulary shared by content interactions and media: the authenticated Actor, the ContentResolver port and its Resolution. It has no dependencies beyond contentref.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Actor ¶
type Actor struct {
ID string // stable subject id (uuid text); empty when Anonymous
Kind string // opaque: "user" | "service" | "delegated" | ...
IP string // anon fallback key for reactions / poll votes
Anonymous bool
}
Actor is the already-authenticated caller. ContentKit never authenticates.
type ContentResolver ¶
type ContentResolver interface {
Resolve(ctx context.Context, refs []contentref.ContentRef, actor Actor) (map[contentref.ContentKey]Resolution, error)
}
ContentResolver is the one mandatory content hook and the whole gating surface: it says whether each ContentRef exists, is visible and is accessible to the actor. It is batch-first: callers pass every ref a request needs in one call (a single item is a batch of one). The map is keyed by each requested ref's Key; a ref missing from it denies. An error fails the whole batch and denies every ref.
type Resolution ¶
type Resolution struct {
// Ref is the canonical reference every row is stored and read under (an
// alias or slug resolves to it). A zero Ref keeps the requested one; a Ref
// of another tenant is an error.
Ref contentref.ContentRef
// Visible = published and not soft-deleted. Teasers need only Visible.
Visible bool
// Accessible = the actor may consume it: an opaque host verdict
// (entitlement, purchase, ACL, flag). ContentKit imposes no access model.
Accessible bool
// PreviewLimit caps a Visible item to its first N ordered units (pages,
// files), whatever Accessible says. 0 = no cap. Content interactions
// ignore it.
PreviewLimit int
// Editor = the actor may edit the item (its creator, staff): media signs
// editor views (the item's temp/, one editor token) and returns edit
// metadata only for editors. Its read API URLs stay within what Visible,
// Accessible and PreviewLimit allow.
Editor bool
}
Resolution is the host's verdict about a content reference for one actor.
func ResolveOne ¶ added in v0.34.0
func ResolveOne(ctx context.Context, r ContentResolver, ref contentref.ContentRef, actor Actor) (Resolution, error)
ResolveOne resolves a single ref as a batch of one; an omitted ref yields the zero (denying) Resolution.
func (Resolution) Full ¶
func (r Resolution) Full() bool
Full reports unrestricted access: every unit is served.
func (Resolution) Units ¶
func (r Resolution) Units(total int) int
Units returns how many leading units of an ordered list of total units the resolution grants.