pub struct EffectAuthorizer { /* private fields */ }Expand description
Authorises the file paths in a plugin’s returned effects against its grant.
Built once per plugin at load — a grant never changes for a plugin’s life,
so nothing here costs anything per keystroke beyond the prefix compare a
WriteToFile actually needs.
Implementations§
Source§impl EffectAuthorizer
impl EffectAuthorizer
pub fn new(grant: &CapabilityGrant, plugin: impl Into<String>) -> Self
Sourcepub fn permits_write(&self, path: &Path) -> bool
pub fn permits_write(&self, path: &Path) -> bool
True when path lies within one of the plugin’s fs:write prefixes.
Both sides are canonicalized so a .. segment cannot escape a granted
prefix — the same rule host_services::grant_permits_walk applies, and
for the same reason.
A target that does not exist yet canonicalizes its nearest real
ANCESTOR. Capture’s first run creates its file, and a non-existent
path canonicalizes to nothing; without this, “create the capture file”
would be a permanent denial and the feature would be unreachable by
design. Walking up rather than stopping at the immediate parent is what
makes the same true when the directory is new too — see
[resolve_for_compare].
A path that still will not resolve falls back to its raw form, which requires a literal prefix match — so it can only ever deny more, never widen. Failing safe.
Authorise an effect, replacing any unpermitted WriteToFile with an
Echo naming the refusal.
Recurses into Many so a write buried in a compound effect is checked
too — an unchecked path there would be the whole gate, bypassed by
wrapping.
Trait Implementations§
Source§impl Clone for EffectAuthorizer
impl Clone for EffectAuthorizer
Source§fn clone(&self) -> EffectAuthorizer
fn clone(&self) -> EffectAuthorizer
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl Freeze for EffectAuthorizer
impl RefUnwindSafe for EffectAuthorizer
impl Send for EffectAuthorizer
impl Sync for EffectAuthorizer
impl Unpin for EffectAuthorizer
impl UnsafeUnpin for EffectAuthorizer
impl UnwindSafe for EffectAuthorizer
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more