QueryEntryPolicy

data class QueryEntryPolicy(val requireExplicitEntry: Boolean = false, val requireAuthenticatedScope: Boolean = false, val http: QueryBudget = QueryBudget.HTTP_DEFAULT, val inProcess: QueryBudget? = null)

What a gateway requires of a query's QueryEntry before admitting it, and the budget each entry runs under.

Constructors

Link copied to clipboard
constructor(requireExplicitEntry: Boolean = false, requireAuthenticatedScope: Boolean = false, http: QueryBudget = QueryBudget.HTTP_DEFAULT, inProcess: QueryBudget? = null)

Types

Link copied to clipboard
object Companion

Properties

Link copied to clipboard

the budget of QueryEntry.HTTP queries.

Link copied to clipboard

the budget of QueryEntry.IN_PROCESS and QueryEntry.UNSPECIFIED queries; null, the default, checks nothing: in-process callers are trusted code.

Link copied to clipboard

rejects an QueryEntry.HTTP query on a built-in model whose authenticated scope does not pin the model's required scope. A declared scope (a tenant header, say) still filters the query but never satisfies this check. Off by default: the declared scope is trusted.

Link copied to clipboard

rejects QueryEntry.UNSPECIFIED queries, so every caller must say whether it is HTTP or in-process. Off by default: an unspecified entry is treated as in-process, which keeps existing QueryGateway callers working unchanged.

Functions

Link copied to clipboard

The entry the query runs under, after this policy accepted it.

Link copied to clipboard
Link copied to clipboard
fun requireScope(entry: QueryEntry, authenticated: FilterExpression, profile: QueryModelProfile?)

Rejects the query when requireAuthenticatedScope applies and authenticated misses the required scope.