Generic, deterministic capability authority store. 更多...
#include <Authority.h>
Public 成员函数 | |
| Store (eve::PersistentId instanceId={}) | |
| Creates an authority store with an optional persistent identity. | |
| std::string | grant (const std::string &actor, const std::string &scope, const std::string &capability, const std::string &source, int priority=0, double duration=0.0) |
| Adds a grant rule and returns its stable ID, or an empty string for invalid input. | |
| std::string | deny (const std::string &actor, const std::string &scope, const std::string &capability, const std::string &source, int priority=0, double duration=0.0) |
| Adds a deny rule and returns its stable ID, or an empty string for invalid input. | |
| bool | revoke (const std::string &id, const std::string &reason="revoked") |
| Revokes a rule by stable ID. | |
| int | revokeBySource (const std::string &source, const std::string &reason="source_revoked") |
| Revokes every rule from a source and returns the number removed. | |
| void | update (double dtSeconds) |
| Advances finite rule durations and expires rules reaching zero. | |
| bool | can (const std::string &actor, const std::string &scope, const std::string &capability) const |
| Returns whether the winning rule allows a capability. | |
| Decision | explain (const std::string &actor, const std::string &scope, const std::string &capability) const |
| Returns an explainable decision and its winning rule. | |
| const Rule * | find (const std::string &id) const |
| Returns a rule by stable ID, or nullptr. | |
| int | queryActor (const std::string &actor) |
| Queries rules for an actor in deterministic creation order. | |
| int | queryScope (const std::string &scope) |
| Queries rules for a scope in deterministic creation order. | |
| int | queryCapability (const std::string &capability) |
| Queries rules for a capability in deterministic creation order. | |
| int | query (const std::string &actor, const std::string &scope, const std::string &capability) |
| Queries rules matching actor, scope, and capability. Empty fields act as wildcards. | |
| const Rule * | queryAt (int index) const |
| Returns a rule from the latest query, or nullptr. | |
| int | eventCount () const |
| Returns retained authority event count. | |
| const Event * | eventAt (int index) const |
| Returns a retained event, or nullptr. | |
| void | clearEvents () |
| Clears retained events without resetting sequence allocation. | |
| std::string | snapshotJson () const |
| Exports persistent state as deterministic compact JSON. | |
| eve::Result< void > | restoreJson (const std::string &json) |
| Transactionally restores a snapshot produced by snapshotJson(). | |
| eve::Result< eve::SnapshotEnvelope > | snapshot (const eve::SnapshotHashProvider &hashProvider) const |
| Captures this store in the common versioned snapshot envelope. | |
| eve::Result< void > | restoreSnapshot (const eve::SnapshotEnvelope &snapshot, const eve::SnapshotHashProvider &hashProvider) |
| Restores a verified or migratable snapshot transactionally. | |
| eve::Result< std::string > | snapshotEnvelopeJson (const eve::SnapshotHashProvider &hashProvider) const |
| Serializes the common snapshot envelope as canonical JSON. | |
| eve::Result< void > | restoreSnapshotJson (std::string_view json, const eve::SnapshotHashProvider &hashProvider) |
| Parses and transactionally restores a common snapshot envelope. | |
详细描述
Generic, deterministic capability authority store.
在文件 Authority.h 第 65 行定义.
构造及析构函数说明
◆ Store()
|
explicit |
Creates an authority store with an optional persistent identity.
- 参数
-
instanceId Identity carried by new SnapshotEnvelope values; nil is a valid legacy identity.
在文件 Authority.cpp 第 130 行定义.
成员函数说明
◆ can()
| bool eve::authority::Store::can | ( | const std::string & | actor, |
| const std::string & | scope, | ||
| const std::string & | capability | ||
| ) | const |
Returns whether the winning rule allows a capability.
在文件 Authority.cpp 第 235 行定义.
引用了 eve::authority::Decision::allowed, explain() , 以及 scope.
◆ clearEvents()
| void eve::authority::Store::clearEvents | ( | ) |
Clears retained events without resetting sequence allocation.
在文件 Authority.cpp 第 261 行定义.
◆ deny()
| std::string eve::authority::Store::deny | ( | const std::string & | actor, |
| const std::string & | scope, | ||
| const std::string & | capability, | ||
| const std::string & | source, | ||
| int | priority = 0, |
||
| double | duration = 0.0 |
||
| ) |
Adds a deny rule and returns its stable ID, or an empty string for invalid input.
在文件 Authority.cpp 第 169 行定义.
引用了 eve::authority::Deny, duration, priority, scope , 以及 source.
◆ eventAt()
| const Event * eve::authority::Store::eventAt | ( | int | index | ) | const |
◆ eventCount()
| int eve::authority::Store::eventCount | ( | ) | const |
Returns retained authority event count.
在文件 Authority.cpp 第 257 行定义.
◆ explain()
| Decision eve::authority::Store::explain | ( | const std::string & | actor, |
| const std::string & | scope, | ||
| const std::string & | capability | ||
| ) | const |
Returns an explainable decision and its winning rule.
在文件 Authority.cpp 第 225 行定义.
引用了 eve::authority::Rule::actor, eve::authority::Rule::capability, eve::authority::Rule::effect, eve::authority::Grant, eve::authority::Rule::id, eve::authority::Rule::priority, eve::authority::Rule::scope, scope , 以及 eve::authority::Rule::source.
被这些函数引用 can().
◆ find()
| const Rule * eve::authority::Store::find | ( | const std::string & | id | ) | const |
Returns a rule by stable ID, or nullptr.
在文件 Authority.cpp 第 238 行定义.
◆ grant()
| std::string eve::authority::Store::grant | ( | const std::string & | actor, |
| const std::string & | scope, | ||
| const std::string & | capability, | ||
| const std::string & | source, | ||
| int | priority = 0, |
||
| double | duration = 0.0 |
||
| ) |
Adds a grant rule and returns its stable ID, or an empty string for invalid input.
在文件 Authority.cpp 第 165 行定义.
引用了 duration, eve::authority::Grant, priority, scope , 以及 source.
◆ query()
| int eve::authority::Store::query | ( | const std::string & | actor, |
| const std::string & | scope, | ||
| const std::string & | capability | ||
| ) |
Queries rules matching actor, scope, and capability. Empty fields act as wildcards.
在文件 Authority.cpp 第 243 行定义.
引用了 eve::authority::Rule::actor, eve::authority::Rule::capability, eve::authority::Rule::scope , 以及 scope.
被这些函数引用 queryActor(), queryCapability() , 以及 queryScope().
◆ queryActor()
| int eve::authority::Store::queryActor | ( | const std::string & | actor | ) |
Queries rules for an actor in deterministic creation order.
在文件 Authority.cpp 第 251 行定义.
引用了 query().
◆ queryAt()
| const Rule * eve::authority::Store::queryAt | ( | int | index | ) | const |
◆ queryCapability()
| int eve::authority::Store::queryCapability | ( | const std::string & | capability | ) |
Queries rules for a capability in deterministic creation order.
在文件 Authority.cpp 第 253 行定义.
引用了 query().
◆ queryScope()
| int eve::authority::Store::queryScope | ( | const std::string & | scope | ) |
Queries rules for a scope in deterministic creation order.
在文件 Authority.cpp 第 252 行定义.
◆ restoreJson()
| eve::Result< void > eve::authority::Store::restoreJson | ( | const std::string & | json | ) |
Transactionally restores a snapshot produced by snapshotJson().
- 参数
-
json Snapshot JSON to parse and validate.
- 返回
- Success, or a structured parse/invariant diagnostic; failure leaves every observable store field unchanged. @thread Call on the store's owning simulation thread. @reentrancy Does not invoke callbacks.
在文件 Authority.cpp 第 286 行定义.
引用了 eve::authority::Rule::actor, eve::authority::Rule::capability, eve::authority::Deny, eve::authority::Rule::duration, eve::authority::Rule::effect, effect, eve::Diagnostic::error(), eve::Result< T >::failure(), eve::authority::Grant, eve::authority::Rule::id, eve::InvariantViolation, eve::authority::Rule::order, order, eve::json::Document::parse(), eve::ParseError, eve::authority::Rule::priority, eve::authority::Rule::remaining, root, eve::authority::Rule::scope, eve::authority::Rule::source, eve::Result< T >::success() , 以及 values.
被这些函数引用 restoreSnapshot().
◆ restoreSnapshot()
| eve::Result< void > eve::authority::Store::restoreSnapshot | ( | const eve::SnapshotEnvelope & | snapshot, |
| const eve::SnapshotHashProvider & | hashProvider | ||
| ) |
Restores a verified or migratable snapshot transactionally.
- 参数
-
snapshot Source envelope. Its schema must be authority:store.hashProvider Explicit provider used to verify and reseal the payload.
- 返回
- Success, or a failure leaving all store state unchanged.
在文件 Authority.cpp 第 353 行定义.
引用了 eve::Conflict, eve::Diagnostic::error(), eve::Result< T >::failure(), eve::InvalidArgument, eve::detail::Id128< Tag >::isNil(), payload, restoreJson(), source, eve::Result< T >::success() , 以及 eve::validateSnapshotPayloadMetadata().
被这些函数引用 restoreSnapshotJson().
◆ restoreSnapshotJson()
| eve::Result< void > eve::authority::Store::restoreSnapshotJson | ( | std::string_view | json, |
| const eve::SnapshotHashProvider & | hashProvider | ||
| ) |
Parses and transactionally restores a common snapshot envelope.
- 参数
-
json Canonical snapshot envelope JSON. hashProvider Explicit provider used to verify contentHash.
- 返回
- Success, or a failure leaving all store state unchanged.
在文件 Authority.cpp 第 389 行定义.
引用了 eve::Result< T >::failure(), eve::parseSnapshotEnvelope(), restoreSnapshot() , 以及 source.
◆ revoke()
| bool eve::authority::Store::revoke | ( | const std::string & | id, |
| const std::string & | reason = "revoked" |
||
| ) |
◆ revokeBySource()
| int eve::authority::Store::revokeBySource | ( | const std::string & | source, |
| const std::string & | reason = "source_revoked" |
||
| ) |
Revokes every rule from a source and returns the number removed.
在文件 Authority.cpp 第 188 行定义.
引用了 removed, eve::authority::Revoked , 以及 source.
◆ snapshot()
| eve::Result< eve::SnapshotEnvelope > eve::authority::Store::snapshot | ( | const eve::SnapshotHashProvider & | hashProvider | ) | const |
Captures this store in the common versioned snapshot envelope.
- 参数
-
hashProvider Explicit content-digest provider; it is never defaulted silently.
- 返回
- A sealed snapshot, or a structured serialization/hash failure.
在文件 Authority.cpp 第 346 行定义.
引用了 eve::Result< T >::failure(), eve::Value::fromJson(), eve::makeSnapshotEnvelope(), payload , 以及 snapshotJson().
被这些函数引用 snapshotEnvelopeJson().
◆ snapshotEnvelopeJson()
| eve::Result< std::string > eve::authority::Store::snapshotEnvelopeJson | ( | const eve::SnapshotHashProvider & | hashProvider | ) | const |
Serializes the common snapshot envelope as canonical JSON.
- 参数
-
hashProvider Explicit content-digest provider.
- 返回
- Canonical envelope JSON or a structured failure.
在文件 Authority.cpp 第 382 行定义.
引用了 eve::Result< T >::failure(), eve::serializeSnapshotEnvelope(), snapshot() , 以及 value.
◆ snapshotJson()
| std::string eve::authority::Store::snapshotJson | ( | ) | const |
Exports persistent state as deterministic compact JSON.
在文件 Authority.cpp 第 268 行定义.
引用了 eve::authority::Rule::actor, eve::authority::Rule::capability, eve::authority::Rule::duration, eve::authority::Rule::effect, eve::authority::effectName(), first, eve::authority::Rule::id, eve::authority::Rule::order, eve::authority::Rule::priority, quote, eve::authority::Rule::remaining, eve::authority::Rule::scope , 以及 eve::authority::Rule::source.
被这些函数引用 snapshot().
◆ update()
| void eve::authority::Store::update | ( | double | dtSeconds | ) |
Advances finite rule durations and expires rules reaching zero.
在文件 Authority.cpp 第 204 行定义.
该类的文档由以下文件生成:
- src/modules/authority/Authority.h
- src/modules/authority/Authority.cpp