pub struct ToolAuthorization<Tool> {
acting_user_id: Uuid,
_authorization: AuthorizationToken,
_tool: PhantomData<fn() -> Tool>,
}Expand description
Proof that the caller was authorized for Tool before the tool ran.
Wraps the application-wide AuthorizationToken and adds the two things a chatbot tool boundary needs that a controller’s does not: which tool the check was for, as the type parameter, so a proof minted for one tool cannot be handed to another; and who was checked, so an audit row cannot name a user the check never saw. Every field is private, so authorize_tool_call is the only way to obtain one.
Fields§
§acting_user_id: UuidKept only as evidence that the ordinary authorize path produced a token for this caller.
_tool: PhantomData<fn() -> Tool>Implementations§
Source§impl<Tool> ToolAuthorization<Tool>
impl<Tool> ToolAuthorization<Tool>
Sourcepub fn acting_user_id(&self) -> Uuid
pub fn acting_user_id(&self) -> Uuid
The user whose permission was verified, and therefore the one an action tool must record as the actor.
Auto Trait Implementations§
impl<Tool> Freeze for ToolAuthorization<Tool>
impl<Tool> RefUnwindSafe for ToolAuthorization<Tool>
impl<Tool> Send for ToolAuthorization<Tool>
impl<Tool> Sync for ToolAuthorization<Tool>
impl<Tool> Unpin for ToolAuthorization<Tool>
impl<Tool> UnsafeUnpin for ToolAuthorization<Tool>
impl<Tool> UnwindSafe for ToolAuthorization<Tool>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::Request§impl<L> LayerExt<L> for L
impl<L> LayerExt<L> for L
§fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
Applies the layer to a service and wraps it in [
Layered].§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§impl<T> ServiceExt for T
impl<T> ServiceExt for T
§fn map_response_body<F>(self, f: F) -> MapResponseBody<Self, F>where
Self: Sized,
fn map_response_body<F>(self, f: F) -> MapResponseBody<Self, F>where
Self: Sized,
Apply a transformation to the response body. Read more
§fn decompression(self) -> Decompression<Self>where
Self: Sized,
fn decompression(self) -> Decompression<Self>where
Self: Sized,
Decompress response bodies. Read more
§fn trace_for_http(self) -> Trace<Self, SharedClassifier<ServerErrorsAsFailures>>where
Self: Sized,
fn trace_for_http(self) -> Trace<Self, SharedClassifier<ServerErrorsAsFailures>>where
Self: Sized,
High level tracing that classifies responses using HTTP status codes. Read more
§fn trace_for_grpc(self) -> Trace<Self, SharedClassifier<GrpcErrorsAsFailures>>where
Self: Sized,
fn trace_for_grpc(self) -> Trace<Self, SharedClassifier<GrpcErrorsAsFailures>>where
Self: Sized,
High level tracing that classifies responses using gRPC headers. Read more