pub fn effective_permission_expr(
conn: &Connection,
user_id: &str,
permission: &str,
) -> Result<Option<Expr>, String>Expand description
Resolves what a user may actually do, combining their class and individual rules.
- Class and individual are ANDed, so a class exclusion cannot be undone by an individual grant.
Nonemeans no grant at all — callers must deny. Absent expressions are deliberately not treated as “no restriction”: under AND that would give a user with no permissions whatsoever full access.- Write implies read, so the effective read rule is
read OR write. - Under strict write scoping the write rule is narrowed further — see
strict_write_forandcrate::permex::require_all.