Strand
Policy
Feature-gated, process-global append authorization hook.
StrandPolicy exposes only can_append(writer_public_key, data). It is not a read or replication policy. Enable the crate’s policy-hooks feature for the append call site to consult the optional global hook. set_strand_policy is one-time initialization backed by OnceCell; installing a policy without that feature does not enforce it. The hook receives a raw writer key, not a resolved DID.
This example is checked against source signatures; it was not compiled or run during this documentation pass.
use strand::{set_strand_policy, StrandPolicy};
/// Reject blocks larger than 4 KiB. Policies are evaluated before append commits.
struct MaxSizePolicy {
max_bytes: usize,
}
impl StrandPolicy for MaxSizePolicy {
fn can_append(&self, _writer_public_key: &[u8; 32], data: &[u8]) -> bool {
data.len() <= self.max_bytes
}
}
fn main() -> Result<(), Box<dyn std::error::Error>> {
// Install a process-global policy. The backing OnceCell guarantees the policy
// is observed by every Strand instance for the rest of the process; setting
// it twice returns Err with the rejected policy box.
let policy: Box<dyn StrandPolicy> = Box::new(MaxSizePolicy { max_bytes: 4 * 1024 });
set_strand_policy(policy).map_err(|_| "policy already set")?;
println!("strand policy installed: MaxSizePolicy(max_bytes=4096)");
Ok(())
}