Weave documentation
Rust referenceloom-mandate

loom-mandate · evaluate

Source declarations, signatures and documentation for evaluate.

Source: sigil/weave/tools/loom-mandate/src/evaluate.rs. SHA-256: 79abc4af42e4ae700d91f8b79bcbccaf31732878c009771971e187c086e9c571.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

evaluate::EvalRequest

Question being asked of the policy.

#[derive(Debug, Clone)]
pub struct EvalRequest<'a> {
/// Subject DID requesting the action.

pub subject_did: &'a str,
/// Repo id the action targets.

pub repo_id: &'a str,
/// Permission being requested.

pub permission: Permission,
/// Wall clock for expiry checks (UNIX millis).

pub now_ms: u64
}

Source line: 11.

evaluate::EvalDecision

Outcome of an evaluation.

#[derive(Debug, Clone, PartialEq, Eq)]
pub enum EvalDecision {
    /// One or more valid mandates grant the permission unconditionally.
    Allow,
    /// Permission is granted but contingent on additional approvals
    /// (used for `Approve` grants that come with an N-of-M
    /// `ApprovalPolicy`). The caller is expected to consult the
    /// approval store separately.
    AllowWithPolicy {
        /// Min approvals required by the gating policy.
        min_approvals: u32,
    },
    /// No mandate authorizes this action.
    Deny,
}

Source line: 24.

evaluate::evaluate

Evaluate a request against a slice of mandates and revocations. The evaluator filters out:

  • revoked mandates
  • expired mandates
  • mandates for a different repo
  • mandates whose subject is not the requester
  • mandates whose grant doesn't subsume the request
  • mandates with a malformed signature (caller is expected to have verified them already; defense-in-depth re-check is out of scope here to keep evaluator pure / cheap).
pub fn evaluate(
    req: &EvalRequest,
    mandates: &[Mandate],
    revocations: &[RevocationEntry],
) -> EvalDecision;

Source line: 49.

On this page