connscope

package
v1.117.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 29, 2026 License: Apache-2.0 Imports: 1 Imported by: 0

Documentation

Overview

Package connscope answers, for discovery surfaces, the question the authorizer answers for tool calls: may this caller's persona reach this connection?

A persona's connections.allow list is deny-by-default and was enforced only when a caller acted, so a persona restricted to one connection still saw every dataset, connection, and API endpoint on the platform through search and list_connections (#1108). This package is the shared predicate both surfaces now consult. It delegates to persona.ToolFilter.IsConnectionAllowed rather than reimplementing the glob rules, so discovery and authorization cannot drift, and it resolves a caller's persona the same way the argument-completion gate does (by name, since every surface that reaches discovery carries a resolved persona).

It satisfies knowledge.ConnectionScope and pkg/connview's permit predicate; the platform composition root is the compile-time proof, so this package imports neither.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Deps

type Deps struct {
	// Registry resolves a persona name to its rules. Held live (not snapshotted)
	// so a persona edited through the admin API takes effect on the next lookup.
	// A nil registry denies every named connection, matching the fail-closed
	// action path.
	Registry *persona.Registry

	// URNConnections maps a catalog URN to the names of the connections that
	// could serve it. Nil (or an empty result) leaves a URN unattributable, which
	// keeps the entity visible rather than hiding it on a guess.
	URNConnections func(urn string) []string
}

Deps are the inputs a Scope needs.

type Scope

type Scope struct {
	// contains filtered or unexported fields
}

Scope is the persona connection boundary as discovery sees it.

func New

func New(deps Deps) *Scope

New builds a Scope from deps.

func (*Scope) AllowConnection

func (s *Scope) AllowConnection(personaName, connection string) bool

AllowConnection reports whether the named persona may reach the named connection, by the same rules the authorizer applies to a tool call: deny takes precedence, an explicit allow is required, and a persona that does not resolve is denied every named connection.

func (*Scope) ConnectionsForURN

func (s *Scope) ConnectionsForURN(urn string) []string

ConnectionsForURN returns the connections that could serve a catalog URN, or nil when the deployment carries no mapping for it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL