ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Config.Rule

Description

Resolve a declared rules patch against a base policy.

A patch entry names a rule: it adds one, refines an existing one key by key, or disables one with enabled: false. Refusals accumulate across entries, so one load reports every malformed rule rather than the first. A patch that names no default and gives no type is refused, as is a parameter the named type does not read, because an ignored parameter reads on a deny gate as a setting the operator made and Écluse did not apply.

Synopsis

Policies

newtype RulePolicy Source #

A resolved rule set, keyed by the rule name an operator patches it under.

Constructors

RulePolicy 

Fields

Instances

Instances details
Show RulePolicy Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RulePolicy Source # 
Instance details

Defined in Ecluse.Config.Rule

emptyPolicy :: RulePolicy Source #

The policy a load starts from before the shipped defaults are applied.

resolvePolicy :: RulePolicy -> RulePatch -> Either [PolicyError] RulePolicy Source #

Apply a patch to a base policy. Every entry is resolved before any is applied, so one load reports every refusal rather than stopping at the first.

Declared patches

newtype RulePatch Source #

A declared rules object: one RuleEntry per rule name it names.

Constructors

RulePatch (Map Text RuleEntry) 

Instances

Instances details
FromJSON RulePatch Source # 
Instance details

Defined in Ecluse.Config.Aeson

Show RulePatch Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RulePatch Source # 
Instance details

Defined in Ecluse.Config.Rule

data RuleEntry Source #

One rule's declared keys, every one optional. Which of them the entry may set depends on the rule type, and refuseStrayParameters refuses the rest.

Instances

Instances details
FromJSON RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Aeson

Show RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Rule

knownRuleTypes :: [Text] Source #

The rule type names the diagnostics recognise. checkRestatedType reports one of these as a mismatched MalformedRule, and anything else as an UnknownRuleType.

Refusals

data PolicyError Source #

Why one declared rule was refused. A load reports every one it accumulated.

Instances

Instances details
Show PolicyError Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq PolicyError Source # 
Instance details

Defined in Ecluse.Config.Rule

renderPolicyError :: PolicyError -> Text Source #

One refusal as the boot reports it, naming the rule it was declared under.