Skip to main content

Module permex

Module permex 

Source
Expand description

Permission expressions — a small boolean language over vault entries.

Replaces the flat list of (scope_type, scope_value, permission) rows, which could only ever mean “any of these matches”. Admins can now express what they actually want:

project:Alpha AND NOT category:secret
(project:web OR project:api) AND env:production
tag:shared OR type:certificate

§Grammar

expr      := or_expr
or_expr   := and_expr (OR and_expr)*
and_expr  := not_expr (AND not_expr)*
not_expr  := NOT not_expr | primary
primary   := '(' expr ')' | predicate
predicate := field ':' glob

Precedence is NOT > AND > OR; parentheses override. Operators are case-insensitive and && / || / ! are accepted as aliases. Adjacency is not implicit AND — an operator is always required, so an expression can never quietly mean something other than it reads.

§Fields

FieldMatches against
vaulteverything (the value is ignored)
projectthe entry’s project ids and their display names
categoryany of the entry’s categories
tagany of the entry’s tags
envthe entry’s environment
typethe entry’s secret type (default api_key)

§Two rules worth knowing

field:* is unconditional. It means “no constraint on this field”, not “has at least one value matching *”. Without that, project:* would match unfiled entries (every entry carries the Universal catch-all) while category:* would not (an entry can have no categories at all) — the same wildcard behaving differently depending on the field.

A specific project grant is never satisfied by Universal. Every entry belongs to it, so matching it would silently turn any project grant into a vault-wide one.

Structs§

EntryView
The parts of a vault entry an expression can test.

Enums§

Expr
A parsed permission expression.
Field
Which part of an entry a predicate tests.

Functions§

any_of
Combines a class expression with an individual one.
combine
compile_scopes
Builds the expression equivalent to a set of legacy (scope_type, scope_value) rows, which always meant “any of these matches”.
eval
Does expr grant access to entry?
eval_str
Convenience: parse and evaluate, treating a malformed expression as deny.
parse
Parses a permission expression.
require_all
Rewrites a permission expression so every top-level alternative must match, instead of any one of them.