policystore

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Overview

Package policystore publishes immutable filesystem-owned policy generations. Its APIs are for trusted owner administration; they are not HTTP permissions.

Index

Constants

This section is empty.

Variables

View Source
var ErrConflict = errors.New("policy generation revision conflict")

Functions

This section is empty.

Types

type Controller

type Controller struct {
	// contains filtered or unexported fields
}

Controller owns one admitted, immutable in-process policy snapshot. Publish and reload are trusted owner operations, not data-policy administration grants.

func NewController

func NewController(ctx context.Context, store *Store) (*Controller, error)

func (*Controller) AcquirePolicyLease

func (c *Controller) AcquirePolicyLease(ctx context.Context) (access.PolicyLease, error)

AcquirePolicyLease is called only after the adapter storage admission lock. Publication waits for this lease through the actual commit/abort boundary.

func (*Controller) Activate

func (c *Controller) Activate(ctx context.Context, expected string, documents []access.DTQLDocument) (Snapshot, error)

func (*Controller) Policies

func (c *Controller) Policies(ctx context.Context) ([]access.Policy, error)

func (*Controller) Reload

func (c *Controller) Reload(ctx context.Context) (Snapshot, error)

func (*Controller) Snapshot

func (c *Controller) Snapshot() (Snapshot, error)

type Document

type Document struct {
	ID       string `json:"id"`
	File     string `json:"file"`
	Revision string `json:"revision"`
}

type Owner

type Owner struct {
	Database string `json:"database"`
	Realm    string `json:"realm"`
	Enabled  bool   `json:"enabled"`
}

type Snapshot

type Snapshot struct {
	Revision  string
	Owner     Owner
	Documents []Document
	// contains filtered or unexported fields
}

func (Snapshot) Policies

func (s Snapshot) Policies() []access.Policy

type Store

type Store struct {
	// contains filtered or unexported fields
}

func Open

func Open(root string, owner Owner) (*Store, error)

Open opens an owner store without activating a generation. The caller must Load before serving an enabled owner. An absent pointer is never disabled ACL.

func (*Store) Activate

func (s *Store) Activate(ctx context.Context, expected string, documents []access.DTQLDocument) (Snapshot, error)

Activate publishes one complete set using whole-owner CAS. expected is empty only for first activation. Per-document administration can merge under this same owner lock in a future management API; public ETags are document hashes.

func (*Store) Load

func (s *Store) Load(ctx context.Context) (Snapshot, error)

Load verifies the selected manifest and every canonical document before compiling the complete policy set. Unreferenced generations are ignored.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL