Weave documentation
Rust referencestrand-vault

strand-vault · policy

Source declarations, signatures and documentation for policy.

Reviewed implementation boundary: Vault construction does not automatically replay WAL entries. Snapshotting is a best-effort directory copy; replication mode/live settings are not implemented as runtime controls, and the capability preamble is not ACT authorization verification. See /libraries/strand-vault/overview.

Source: sigil/weave/libs/strand-vault/src/policy.rs. SHA-256: dd306870e920c18bef3bd550245625e9f3f6b3f0de443d5e4446391e196700a8.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

policy::AccessPolicy

Access policy to control read/write/delete/authorization

pub trait AccessPolicy: Send + Sync {
    fn can_read(&self, requesting_agent: Option<&str>, id: &StrandId) -> bool;
    fn can_write(&self, requesting_agent: Option<&str>, id: &StrandId) -> bool;
    fn can_delete(&self, requesting_agent: &str, id: &StrandId, perms: &AgentPermissions) -> bool;
    fn can_authorize(&self, current_authorizers: usize, new_permissions: &AgentPermissions)
        -> bool;
}

Source line: 8.

policy::DefaultPolicy

Default permissive policy with optional public-read flag

#[derive(Default)]
pub struct DefaultPolicy {
pub allow_public_read: bool
}

Source line: 18.

policy::AccessPolicyRef

pub type AccessPolicyRef = Arc<dyn AccessPolicy>;

Source line: 64.

policy::WriterOnlyPolicy

Writer-only policy: only agent namespace owner can write/delete; reads per allow flag

pub struct WriterOnlyPolicy {
pub allow_public_read: bool
}

Source line: 67.

policy::OrgScopedPolicy

Org-scoped policy: only namespaces with allowed prefixes can write

pub struct OrgScopedPolicy {
pub allow_public_read: bool,
pub allowed_prefixes: Vec<String>
}

Source line: 109.

policy::ReadOnlyMirrorPolicy

Read-only mirror policy: no writes/deletes/authorizations

pub struct ReadOnlyMirrorPolicy;

Source line: 159.

On this page