access

package
v0.58.7 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 26, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package access is the host's gating vocabulary shared by content interactions and media: the authenticated Actor, the ContentResolver port and its Resolution. It has no dependencies beyond contentref.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Actor

type Actor struct {
	ID        string // stable subject id (uuid text); empty when Anonymous
	Kind      string // opaque: "user" | "service" | "delegated" | ...
	IP        string // anon fallback key for reactions / poll votes
	Anonymous bool
}

Actor is the already-authenticated caller. ContentKit never authenticates.

type ContentResolver

type ContentResolver interface {
	Resolve(ctx context.Context, refs []contentref.ContentRef, actor Actor) (map[contentref.ContentKey]Resolution, error)
}

ContentResolver is the one mandatory content hook and the whole gating surface: it says whether each ContentRef exists, is visible and is accessible to the actor. It is batch-first: callers pass every ref a request needs in one call (a single item is a batch of one). The map is keyed by each requested ref's Key; a ref missing from it denies. An error fails the whole batch and denies every ref.

type Resolution

type Resolution struct {
	// Ref is the canonical reference every row is stored and read under (an
	// alias or slug resolves to it). A zero Ref keeps the requested one; a Ref
	// of another tenant is an error.
	Ref contentref.ContentRef
	// Visible = published and not soft-deleted. Teasers need only Visible.
	Visible bool
	// Accessible = the actor may consume it: an opaque host verdict
	// (entitlement, purchase, ACL, flag). ContentKit imposes no access model.
	Accessible bool
	// PreviewLimit caps a Visible item to its first N ordered units (pages,
	// files), whatever Accessible says. 0 = no cap. Content interactions
	// ignore it.
	PreviewLimit int
	// Editor = the actor may edit the item (its creator, staff): media signs
	// editor views (the item's temp/, one editor token) and returns edit
	// metadata only for editors. Its read API URLs stay within what Visible,
	// Accessible and PreviewLimit allow.
	Editor bool
}

Resolution is the host's verdict about a content reference for one actor.

func ResolveOne added in v0.34.0

func ResolveOne(ctx context.Context, r ContentResolver, ref contentref.ContentRef, actor Actor) (Resolution, error)

ResolveOne resolves a single ref as a batch of one; an omitted ref yields the zero (denying) Resolution.

func (Resolution) Full

func (r Resolution) Full() bool

Full reports unrestricted access: every unit is served.

func (Resolution) Units

func (r Resolution) Units(total int) int

Units returns how many leading units of an ordered list of total units the resolution grants.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL