| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Config.Rule
Contents
Description
Resolve a declared rules patch against a base policy.
A patch entry names a rule: it adds one, refines an existing one key by key, or disables one with
enabled: false. Refusals accumulate across entries, so one load reports every malformed rule
rather than the first. A patch that names no default and gives no type is refused, as is a
parameter the named type does not read, because an ignored parameter reads on a deny gate as a
setting the operator made and Écluse did not apply.
Synopsis
- newtype RulePolicy = RulePolicy {
- policyRules :: Map Text PrecededRule
- emptyPolicy :: RulePolicy
- resolvePolicy :: RulePolicy -> RulePatch -> Either [PolicyError] RulePolicy
- newtype RulePatch = RulePatch (Map Text RuleEntry)
- data RuleEntry = RuleEntry {}
- knownRuleTypes :: [Text]
- data PolicyError
- renderPolicyError :: PolicyError -> Text
Policies
newtype RulePolicy Source #
A resolved rule set, keyed by the rule name an operator patches it under.
Constructors
| RulePolicy | |
Fields
| |
Instances
| Show RulePolicy Source # | |
Defined in Ecluse.Config.Rule Methods showsPrec :: Int -> RulePolicy -> ShowS # show :: RulePolicy -> String # showList :: [RulePolicy] -> ShowS # | |
| Eq RulePolicy Source # | |
Defined in Ecluse.Config.Rule | |
emptyPolicy :: RulePolicy Source #
The policy a load starts from before the shipped defaults are applied.
resolvePolicy :: RulePolicy -> RulePatch -> Either [PolicyError] RulePolicy Source #
Apply a patch to a base policy. Every entry is resolved before any is applied, so one load reports every refusal rather than stopping at the first.
Declared patches
A declared rules object: one RuleEntry per rule name it names.
One rule's declared keys, every one optional. Which of them the entry may set depends on the
rule type, and refuseStrayParameters refuses the rest.
Constructors
| RuleEntry | |
Fields
| |
knownRuleTypes :: [Text] Source #
The rule type names the diagnostics recognise. checkRestatedType reports one of these as a
mismatched MalformedRule, and anything else as an UnknownRuleType.
Refusals
data PolicyError Source #
Why one declared rule was refused. A load reports every one it accumulated.
Constructors
| MissingRuleType Text | |
| UnknownRuleType Text Text | |
| MalformedRule Text Text | |
| SuppressUnknownRule Text |
Instances
| Show PolicyError Source # | |
Defined in Ecluse.Config.Rule Methods showsPrec :: Int -> PolicyError -> ShowS # show :: PolicyError -> String # showList :: [PolicyError] -> ShowS # | |
| Eq PolicyError Source # | |
Defined in Ecluse.Config.Rule | |
renderPolicyError :: PolicyError -> Text Source #
One refusal as the boot reports it, naming the rule it was declared under.