specs/policy/evaluate/v0_2/payload
library
Classes
-
Payload
-
Dry-run a policy decision against a synthetic PolicyInput. Returns the policy
decision plus a trace of which policy modules matched and which rules fired. Used
by the policy-editor UI to verify changes before save and by admins to diagnose
unexpected deny/allow outcomes.
-
PolicyDecision
-
PolicyDecision
-
PolicyDecisionStepUp
-
When decision == "require_step_up", which method to demand.
-
PolicyInput
-
The structured input fed to a policy evaluator on every vault/proxy-login,
vault/release, and policy/evaluate call.
-
PolicyInputConsumer
-
PolicyInputConsumer, generated from its schema.
-
PolicyInputRequest
-
PolicyInputRequest, generated from its schema.
-
Response
-
Policy Evaluate — response payload
Extension Types
-
PolicyDecisionDecision
-
PolicyDecisionDecision is a closed set of string values defined by this
specification's schema.
-
PolicyDecisionMode
-
When decision == "allow", whether the maintainer should proxy-login or
release-for-fill. Default: proxy.
-
PolicyDecisionStepUpMethod
-
PolicyDecisionStepUpMethod is a closed set of string values defined by this
specification's schema.
-
PolicyInputConsumerNetworkClass
-
PolicyInputConsumerNetworkClass is a closed set of string values defined by this
specification's schema.
-
PolicyInputRequestKind
-
PolicyInputRequestKind is a closed set of string values defined by this
specification's schema.
Typedefs
-
ConsumerKind
= Object?
-
Discriminator: is this consumer a user-driven Companion or a headless Service?
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.
-
SiteTarget
= Object?
-
A single binding target for a vault entry. Tagged union over the discriminator
kind. A VaultEntry's targets array MAY mix any number of these.