pub fn any_of(a: Option<Expr>, b: Option<Expr>) -> Option<Expr>Expand description
Combines a class expression with an individual one.
Both present → AND: a class restriction cannot be undone by an individual
grant, which is what makes classes an actual boundary. Exactly one present →
that one. Neither → None, meaning no grant at all.
The AND is why “neither” must be None rather than a vacuous truth: treating
an absent expression as true would make a user with no permissions
whatsoever evaluate to true AND true and see everything.
ORs two optional expressions, used for “write implies read”.