Expand description
Permission expressions — a small boolean language over vault entries.
Replaces the flat list of (scope_type, scope_value, permission) rows, which
could only ever mean “any of these matches”. Admins can now express what they
actually want:
project:Alpha AND NOT category:secret
(project:web OR project:api) AND env:production
tag:shared OR type:certificate§Grammar
expr := or_expr
or_expr := and_expr (OR and_expr)*
and_expr := not_expr (AND not_expr)*
not_expr := NOT not_expr | primary
primary := '(' expr ')' | predicate
predicate := field ':' globPrecedence is NOT > AND > OR; parentheses override. Operators are
case-insensitive and && / || / ! are accepted as aliases. Adjacency is
not implicit AND — an operator is always required, so an expression can
never quietly mean something other than it reads.
§Fields
| Field | Matches against |
|---|---|
vault | everything (the value is ignored) |
project | the entry’s project ids and their display names |
category | any of the entry’s categories |
tag | any of the entry’s tags |
env | the entry’s environment |
type | the entry’s secret type (default api_key) |
§Two rules worth knowing
field:* is unconditional. It means “no constraint on this field”,
not “has at least one value matching *”. Without that, project:* would
match unfiled entries (every entry carries the Universal catch-all) while
category:* would not (an entry can have no categories at all) — the same
wildcard behaving differently depending on the field.
A specific project grant is never satisfied by Universal. Every entry
belongs to it, so matching it would silently turn any project grant into a
vault-wide one.
Structs§
- Entry
View - The parts of a vault entry an expression can test.
Enums§
Functions§
- any_of
- Combines a class expression with an individual one.
- combine
- compile_
scopes - Builds the expression equivalent to a set of legacy
(scope_type, scope_value)rows, which always meant “any of these matches”. - eval
- Does
exprgrant access toentry? - eval_
str - Convenience: parse and evaluate, treating a malformed expression as deny.
- parse
- Parses a permission expression.
- require_
all - Rewrites a permission expression so every top-level alternative must match, instead of any one of them.