Documentation
¶
Overview ¶
Package connchoicehttp serves the connections a script's connection-typed parameter may name (#1361), extracted from internal/httpserver/scripthttp for its size budget. The script route around it decides who may ask.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Choice ¶
type Choice struct {
Name string `json:"name" example:"warehouse"`
// Kind is the toolkit serving it.
Kind string `json:"kind,omitempty" example:"trino"`
Description string `json:"description,omitempty" example:"Production Trino cluster"`
}
Choice is one connection a parameter may name: the value bound into a run, and what a person needs to pick it by.
type Deps ¶
type Deps struct {
// List enumerates one caller's connections. Nil leaves the route
// unmounted (Enumerator).
List Enumerator
// Caller resolves the caller of a request for the script in its path,
// writing the refusal itself when there is none or the script is not
// theirs to bind.
Caller func(w http.ResponseWriter, r *http.Request) (Scope, bool)
}
Deps is what the route needs from the script surface around it.
type Enumerator ¶
Enumerator lists the connections one caller may reach, in the deployment's terms. It is the composition root's, because resolving it means walking the live toolkit registry through the persona boundary and this package holds neither.
Nil leaves the choices route unmounted: a deployment that cannot enumerate its connections should serve no set at all rather than an empty one, which a form would render as "this script may reach nothing".
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler serves the route.
type Scope ¶
type Scope struct {
// Persona is the caller's resolved persona, whose connections rules decide
// what they may reach. An unresolved persona reaches nothing, which is the
// same fail-closed default the authorizer applies to a tool call.
Persona string
// Unrestricted lifts the persona boundary for an administrator, whose reach
// over this surface is unrestricted by design.
Unrestricted bool
}
Scope is the caller a connection enumeration is narrowed to.