specs/policy/evaluate/v0_2/payload library

Classes

Payload
Dry-run a policy decision against a synthetic PolicyInput. Returns the policy decision plus a trace of which policy modules matched and which rules fired. Used by the policy-editor UI to verify changes before save and by admins to diagnose unexpected deny/allow outcomes.
PolicyDecision
PolicyDecision
PolicyDecisionStepUp
When decision == "require_step_up", which method to demand.
PolicyInput
The structured input fed to a policy evaluator on every vault/proxy-login, vault/release, and policy/evaluate call.
PolicyInputConsumer
PolicyInputConsumer, generated from its schema.
PolicyInputRequest
PolicyInputRequest, generated from its schema.
Response
Policy Evaluate — response payload

Extension Types

PolicyDecisionDecision
PolicyDecisionDecision is a closed set of string values defined by this specification's schema.
PolicyDecisionMode
When decision == "allow", whether the maintainer should proxy-login or release-for-fill. Default: proxy.
PolicyDecisionStepUpMethod
PolicyDecisionStepUpMethod is a closed set of string values defined by this specification's schema.
PolicyInputConsumerNetworkClass
PolicyInputConsumerNetworkClass is a closed set of string values defined by this specification's schema.
PolicyInputRequestKind
PolicyInputRequestKind is a closed set of string values defined by this specification's schema.

Constants

payloadSchemaJson → const String
This specification's payload schema, as JSON text.
responsePayloadSchemaJson → const String
As payloadSchemaJson, for the success-response variant.
responseSpec → const SpecPolicy
The SPEC §7.2 policy for the success-response variant.
responseTypeUri → const String
The success-response form of typeUri (SPEC §4.4.1).
spec → const SpecPolicy
The SPEC §7.2 policy for the request variant, taken from this specification's front matter.
typeUri → const String
The Trust Task type URI this library's Payload is carried under.

Typedefs

ConsumerKind = Object?
Discriminator: is this consumer a user-driven Companion or a headless Service?
Ext = Map<String, dynamic>
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
SiteTarget = Object?
A single binding target for a vault entry. Tagged union over the discriminator kind. A VaultEntry's targets array MAY mix any number of these.