strand-vault · permissions
Source declarations, signatures and documentation for permissions.
Reviewed implementation boundary: Vault construction does not automatically replay WAL entries. Snapshotting is a best-effort directory copy; replication mode/live settings are not implemented as runtime controls, and the capability preamble is not ACT authorization verification. See /libraries/strand-vault/overview.
Source: sigil/weave/libs/strand-vault/src/permissions.rs. SHA-256: 6cf6fc50cda2a0bb8a70ffbf49b141f70e6847f4e900e00d945372b864c391a6.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
permissions::AgentPermissions
Permissions for an agent within the vault
#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct AgentPermissions {
/// Can create new strands
pub can_create: bool,
/// Can delete strands
pub can_delete: bool,
/// Can authorize other agents
pub can_authorize: bool,
/// Maximum number of strands allowed (None = unlimited)
pub max_strands: Option<usize>,
/// Maximum storage size in bytes (None = unlimited)
pub max_storage_bytes: Option<u64>,
/// Allowed namespaces (None = all)
pub allowed_namespaces: Option<HashSet<String>>,
/// Custom permissions
pub custom: HashSet<String>
}Source line: 8.
permissions::AgentPermissions::full_access
Create permissions with all capabilities
pub fn full_access() -> Self;Source line: 47.
permissions::AgentPermissions::read_only
Create read-only permissions
pub fn read_only() -> Self;Source line: 60.
permissions::AgentPermissions::has_permission
Check if a specific permission is granted
pub fn has_permission(&self, permission: Permission) -> bool;Source line: 73.
permissions::Permission
Individual permission types
#[derive(Debug, Clone, PartialEq, Eq, Hash)]
pub enum Permission {
Create,
Delete,
Authorize,
Custom(String),
}Source line: 85.