strand-vault · policy
Source declarations, signatures and documentation for policy.
Reviewed implementation boundary: Vault construction does not automatically replay WAL entries. Snapshotting is a best-effort directory copy; replication mode/live settings are not implemented as runtime controls, and the capability preamble is not ACT authorization verification. See /libraries/strand-vault/overview.
Source: sigil/weave/libs/strand-vault/src/policy.rs. SHA-256: dd306870e920c18bef3bd550245625e9f3f6b3f0de443d5e4446391e196700a8.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
policy::AccessPolicy
Access policy to control read/write/delete/authorization
pub trait AccessPolicy: Send + Sync {
fn can_read(&self, requesting_agent: Option<&str>, id: &StrandId) -> bool;
fn can_write(&self, requesting_agent: Option<&str>, id: &StrandId) -> bool;
fn can_delete(&self, requesting_agent: &str, id: &StrandId, perms: &AgentPermissions) -> bool;
fn can_authorize(&self, current_authorizers: usize, new_permissions: &AgentPermissions)
-> bool;
}Source line: 8.
policy::DefaultPolicy
Default permissive policy with optional public-read flag
#[derive(Default)]
pub struct DefaultPolicy {
pub allow_public_read: bool
}Source line: 18.
policy::AccessPolicyRef
pub type AccessPolicyRef = Arc<dyn AccessPolicy>;Source line: 64.
policy::WriterOnlyPolicy
Writer-only policy: only agent namespace owner can write/delete; reads per allow flag
pub struct WriterOnlyPolicy {
pub allow_public_read: bool
}Source line: 67.
policy::OrgScopedPolicy
Org-scoped policy: only namespaces with allowed prefixes can write
pub struct OrgScopedPolicy {
pub allow_public_read: bool,
pub allowed_prefixes: Vec<String>
}Source line: 109.
policy::ReadOnlyMirrorPolicy
Read-only mirror policy: no writes/deletes/authorizations
pub struct ReadOnlyMirrorPolicy;Source line: 159.