Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | n/a |
0 / 0 |
n/a |
0 / 0 |
CRAP | n/a |
0 / 0 |
|||
| 1 | <?php |
| 2 | |
| 3 | declare(strict_types=1); |
| 4 | |
| 5 | namespace LambdaTwelve\OneRecord\Server\Spi; |
| 6 | |
| 7 | use LambdaTwelve\OneRecord\Rdf\Iri; |
| 8 | |
| 9 | /** |
| 10 | * Who may do what. The spec puts access control at logistics-object level |
| 11 | * with deny by default; how a host decides (its own ownership rules, groups, |
| 12 | * accepted access delegations) is up to it. |
| 13 | * |
| 14 | * The server never asks for actions the spec grants to any authenticated |
| 15 | * party (server information, posting notifications, requesting subscriptions, |
| 16 | * delegations and verifications, reading one's own action requests). |
| 17 | */ |
| 18 | interface AccessPolicy |
| 19 | { |
| 20 | /** |
| 21 | * @param ?Iri $resource the logistics object (or action request) concerned, null for server-wide actions |
| 22 | */ |
| 23 | public function decide(Agent $agent, Action $action, ?Iri $resource): Decision; |
| 24 | } |