Skip to main content

effective_permission_expr

Function effective_permission_expr 

Source
pub fn effective_permission_expr(
    conn: &Connection,
    user_id: &str,
    permission: &str,
) -> Result<Option<Expr>, String>
Expand description

Resolves what a user may actually do, combining their class and individual rules.

  • Class and individual are ANDed, so a class exclusion cannot be undone by an individual grant.
  • None means no grant at all — callers must deny. Absent expressions are deliberately not treated as “no restriction”: under AND that would give a user with no permissions whatsoever full access.
  • Write implies read, so the effective read rule is read OR write.
  • Under strict write scoping the write rule is narrowed further — see strict_write_for and crate::permex::require_all.