QueryEntryPolicy
What a gateway requires of a query's QueryEntry before admitting it, and the budget each entry runs under.
Constructors
Properties
the budget of QueryEntry.HTTP queries.
the budget of QueryEntry.IN_PROCESS and QueryEntry.UNSPECIFIED queries; null, the default, checks nothing: in-process callers are trusted code.
rejects an QueryEntry.HTTP query on a built-in model whose authenticated scope does not pin the model's required scope. A declared scope (a tenant header, say) still filters the query but never satisfies this check. Off by default: the declared scope is trusted.
rejects QueryEntry.UNSPECIFIED queries, so every caller must say whether it is HTTP or in-process. Off by default: an unspecified entry is treated as in-process, which keeps existing QueryGateway callers working unchanged.
Functions
The entry the query runs under, after this policy accepted it.
Rejects the query when requireAuthenticatedScope applies and authenticated misses the required scope.