Skip to main content

Cedarling

Struct Cedarling 

Source
pub struct Cedarling { /* private fields */ }
Expand description

The instance of the Cedarling application.

Implementations§

Source§

impl Cedarling

Source

pub async fn new(config: &Object) -> Result<Cedarling, Error>

Creates a Cedarling application from bootstrap properties.

§Arguments
  • config - A plain object of Cedarling bootstrap-property names and values.
§Example
await initWasm();
const cedarling = await Cedarling.new({
  CEDARLING_APPLICATION_NAME: "task-api",
  CEDARLING_POLICY_STORE_URI: "https://example.com/policy-store.cjar",
  CEDARLING_LOG_TYPE: "memory",
  CEDARLING_LOG_TTL: 120,
});
Source

pub async fn new_from_map(config: Map) -> Result<Cedarling, Error>

Creates a new Cedarling application from a JavaScript Map.

§Arguments
  • config - A Map of Cedarling bootstrap-property names and values.
§Example
await initWasm();
const cedarling = await Cedarling.newFromMap(new Map([
  ["CEDARLING_APPLICATION_NAME", "task-api"],
  ["CEDARLING_POLICY_STORE_URI", "https://example.com/policy-store.cjar"],
  ["CEDARLING_LOG_TYPE", "memory"],
  ["CEDARLING_LOG_TTL", 120],
]));
Source

pub async fn authorize_unsigned( &self, request: &str, ) -> Result<AuthorizeResult, Error>

Authorize an unsigned request carrying an optional single principal. Makes an authorization decision based on the [RequestUnsigned].

When principal is omitted / null on the JS side the core uses Cedar partial evaluation; residual-dependent requests fail closed with Decision::Deny and surface residual policy ids in response.diagnostics.reason.

§Arguments
  • request - JSON string representation of [RequestUnsigned].
§Example
const result = await cedarling.authorizeUnsigned(JSON.stringify(request));
Source

pub async fn authorize_multi_issuer( &self, request: &str, ) -> Result<MultiIssuerAuthorizeResult, Error>

Authorize multi-issuer request. Makes authorization decision based on multiple JWT tokens from different issuers.

§Arguments
  • request - JSON string representation of [AuthorizeMultiIssuerRequest].
§Example
const result = await cedarling.authorizeMultiIssuer(JSON.stringify(request));
Source

pub async fn authorize_unsigned_batch( &self, request: &str, ) -> Result<BatchAuthorizeUnsignedResponse, Error>

Authorize a batch of unsigned requests against one shared principal.

Setup work (principal build + pushed-data snapshot) runs once and each item is evaluated in input order. Results are returned inside a BatchAuthorizeUnsignedResponse carrying the shared batch_id. Batch-level failures (validation, principal parse) reject the whole call; per-item failures are returned as BatchItemError results and exposed by WASM with is_ok=false and error, while genuine Cedar denials remain AuthorizeResult values with decision=false.

§Arguments
  • request - JSON string representation of [BatchAuthorizeUnsignedRequest].
§Example
const result = await cedarling.authorizeUnsignedBatch(JSON.stringify(batchRequest));
Source

pub async fn authorize_multi_issuer_batch( &self, request: &str, ) -> Result<BatchAuthorizeMultiIssuerResponse, Error>

Authorize a batch of multi-issuer requests against one shared token set.

Tokens are validated and token/issuer entities are built once, then each item is evaluated in input order. Batch-level failures (validation, JWT verification, status-list refresh) reject the whole call; per-item failures are returned as BatchItemError results and exposed by WASM with is_ok=false and error, while genuine Cedar denials remain AuthorizeResult values with decision=false.

§Arguments
  • request - JSON string representation of [BatchAuthorizeMultiIssuerRequest].
§Example
const result = await cedarling.authorizeMultiIssuerBatch(JSON.stringify(batchRequest));
Source

pub fn annotations_map(&self, policy_ids: Vec<String>) -> Result<JsValue, Error>

Merge the annotations (@key("value")) of the given policies into a single object.

Intended for resolving the determining policies of an authorization decision: pass result.response.diagnostics.reason.

Lossy: if the same annotation key appears on several policies, one value wins arbitrarily. Use annotationValues / annotationsByPolicy when duplicates matter. Unknown policy IDs are silently skipped.

§Arguments
  • policy_ids - List of policy IDs whose annotations should be merged into a single object. Typically result.response.diagnostics.reason from an authorization result.
§Example
const annotations = cedarling.annotationsMap(result.response.diagnostics.reason);
// { redirect: "/upgrade", tier: "premium" }
Source

pub fn annotation_values( &self, policy_ids: Vec<String>, key: &str, ) -> Vec<String>

Collect every value of the annotation key across the given policies, preserving duplicates. Unknown policy IDs are silently skipped.

§Arguments
  • policy_ids - List of policy IDs to search. Typically result.response.diagnostics.reason from an authorization result.
  • key - The annotation key to collect values for (e.g. "redirect").
§Example
const redirects = cedarling.annotationValues(
  result.response.diagnostics.reason,
  "redirect",
);
// ["/upgrade"]
Source

pub fn annotations_by_policy( &self, policy_ids: Vec<String>, ) -> Result<JsValue, Error>

Return the annotations of each given policy, grouped by policy ID. It is the loss-free companion to annotationsMap. Unknown policy IDs are silently skipped.

§Arguments
  • policy_ids - List of policy IDs whose annotations should be returned grouped by policy ID. Typically result.response.diagnostics.reason from an authorization result.
§Example
const byPolicy = cedarling.annotationsByPolicy(result.response.diagnostics.reason);
// { "5": { redirect: "/upgrade", tier: "premium" } }
Source

pub fn pop_logs(&self) -> Result<Array, Error>

Returns all retained memory logs and removes them from storage. Other log configurations return an empty array.

§Arguments

None.

§Example
const logs = cedarling.popLogs();
Source

pub fn get_log_by_id(&self, id: &str) -> Result<JsValue, Error>

Returns one retained memory log by ID, or null when it is not retained.

§Arguments
  • id - The retained log identifier.
§Example
const log = cedarling.getLogById("request-id");
Source

pub fn get_log_ids(&self) -> Array

Returns identifiers for all retained memory logs.

§Arguments

None.

§Example
const ids = cedarling.getLogIds();
Source

pub fn get_logs_by_tag(&self, tag: &str) -> Result<Vec<JsValue>, Error>

Returns retained memory logs matching an indexed value.

§Arguments
  • tag - A log kind ("System", "Decision", or "Metric") or a system-log level such as "DEBUG".
§Example
const logs = cedarling.getLogsByTag("System");
Source

pub fn get_logs_by_request_id( &self, request_id: &str, ) -> Result<Vec<JsValue>, Error>

Returns retained memory logs for one request ID.

§Arguments
  • requestId - The request identifier to match.
§Example
const logs = cedarling.getLogsByRequestId("request-id");
Source

pub fn get_logs_by_request_id_and_tag( &self, request_id: &str, tag: &str, ) -> Result<Vec<JsValue>, Error>

Returns retained memory logs matching one request ID and indexed value.

§Arguments
  • requestId - The request identifier to match.
  • tag - A log kind ("System", "Decision", or "Metric") or a system-log level such as "DEBUG".
§Example
const logs = cedarling.getLogsByRequestIdAndTag("request-id", "System");
Source

pub async fn shut_down(&self)

Closes Lock Server connections and pushes all available logs.

§Arguments

None.

§Example
await cedarling.shutDown();
Source

pub fn push_data_ctx( &self, key: &str, value: JsValue, ttl_secs: Option<u64>, ) -> Result<(), Error>

Push a value into the data store with an optional TTL. If the key already exists, the value will be replaced. If TTL is not provided, the default TTL from configuration is used.

§Arguments
  • key - A string key for the data entry (must not be empty)
  • value - The value to store (any JSON-serializable JavaScript value: object, array, string, number, boolean)
  • ttl_secs - Optional TTL in seconds (undefined/null uses default from config)
§Example
cedarling.pushDataCtx("user:123", { name: "John", age: 30 }, 3600);
cedarling.pushDataCtx("config", { setting: "value" }); // Uses default TTL
Source

pub fn get_data_ctx(&self, key: &str) -> Result<JsValue, Error>

Get a value from the data store by key. Returns null if the key doesn’t exist or the entry has expired.

§Arguments
  • key - A string key for the data entry to retrieve
§Example
const value = cedarling.getDataCtx("user:123");
if (value !== null) {
    console.log(value.name); // "John"
}
Source

pub fn get_data_entry_ctx(&self, key: &str) -> Result<Option<DataEntry>, Error>

Get a data entry with full metadata by key. Returns undefined if the key doesn’t exist or the entry has expired.

§Arguments
  • key - A string key for the data entry to retrieve
§Example
const entry = cedarling.getDataEntryCtx("user:123");
if (entry !== undefined) {
    console.log(entry.key); // "user:123"
    console.log(entry.value()); // { name: "John", age: 30 }
    console.log(entry.data_type); // "Record"
    console.log(entry.created_at); // "2024-01-01T12:00:00Z"
    console.log(entry.access_count); // 5
}
Source

pub fn remove_data_ctx(&self, key: &str) -> Result<bool, Error>

Remove a value from the data store by key. Returns true if the key existed and was removed, false otherwise.

§Arguments
  • key - A string key for the data entry to remove
§Example
const removed = cedarling.removeDataCtx("user:123");
if (removed) {
    console.log("Entry was successfully removed");
}
Source

pub fn clear_data_ctx(&self) -> Result<(), Error>

Clear all entries from the data store.

§Arguments

None.

§Example
cedarling.clearDataCtx();
console.log("All data entries cleared");
Source

pub fn list_data_ctx(&self) -> Result<Array, Error>

List all entries with their metadata. Returns an array of DataEntry objects.

§Arguments

None.

§Example
const entries = cedarling.listDataCtx();
entries.forEach(entry => {
    console.log(`${entry.key}: ${entry.data_type} (accessed ${entry.access_count} times)`);
});
Source

pub fn get_stats_ctx(&self) -> Result<DataStoreStats, Error>

Get statistics about the data store.

§Arguments

None.

§Example
const stats = cedarling.getStatsCtx();
console.log(`Entries: ${stats.entry_count}/${stats.max_entries || 'unlimited'}`);
console.log(`Capacity: ${stats.capacity_usage_percent.toFixed(2)}%`);
console.log(`Total size: ${stats.total_size_bytes} bytes`);
Source

pub fn is_trusted_issuer_loaded_by_name(&self, issuer_id: &str) -> bool

Check whether a trusted issuer was loaded by issuer identifier.

§Arguments
  • issuer_id - Trusted issuer identifier to check.
§Example
const ok = cedarling.isTrustedIssuerLoadedByName("issuer_id");
Source

pub fn is_trusted_issuer_loaded_by_iss(&self, iss_claim: &str) -> bool

Check whether a trusted issuer was loaded by iss claim.

§Arguments
  • iss_claim - Issuer iss claim value to check.
§Example
const ok = cedarling.isTrustedIssuerLoadedByIss("https://issuer.example.org");
Source

pub fn total_issuers(&self) -> usize

Get the total number of trusted issuer entries discovered.

§Arguments

None.

§Example
const total = cedarling.totalIssuers();
Source

pub fn loaded_trusted_issuers_count(&self) -> usize

Get the number of trusted issuers loaded successfully.

§Arguments

None.

§Example
const loadedCount = cedarling.loadedTrustedIssuersCount();
Source

pub fn loaded_trusted_issuer_ids(&self) -> Array

Get trusted issuer identifiers loaded successfully.

§Arguments

None.

§Example
const ids = cedarling.loadedTrustedIssuerIds();
Source

pub fn failed_trusted_issuer_ids(&self) -> Array

Get trusted issuer identifiers that failed to load.

§Arguments

None.

§Example
const ids = cedarling.failedTrustedIssuerIds();

Trait Implementations§

Source§

impl Clone for Cedarling

Source§

fn clone(&self) -> Cedarling

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl From<Cedarling> for JsValue

Source§

fn from(value: Cedarling) -> Self

Converts to this type from the input type.
Source§

impl FromWasmAbi for Cedarling

Source§

type Abi = WasmPtr<WasmRefCell<Cedarling>>

The Wasm ABI type that this converts from when coming back out from the ABI boundary.
Source§

unsafe fn from_abi(js: Self::Abi) -> Self

Recover a Self from Self::Abi. Read more
Source§

impl IntoWasmAbi for Cedarling

Source§

type Abi = WasmPtr<WasmRefCell<Cedarling>>

The Wasm ABI type that this converts into when crossing the ABI boundary.
Source§

fn into_abi(self) -> Self::Abi

Convert self into Self::Abi so that it can be sent across the wasm ABI boundary.
Source§

impl LongRefFromWasmAbi for Cedarling

Source§

type Abi = WasmPtr<WasmRefCell<Cedarling>>

Same as RefFromWasmAbi::Abi
Source§

type Anchor = RcRef<Cedarling>

Same as RefFromWasmAbi::Anchor
Source§

unsafe fn long_ref_from_abi(js: Self::Abi) -> Self::Anchor

Same as RefFromWasmAbi::ref_from_abi
Source§

impl OptionFromWasmAbi for Cedarling

Source§

fn is_none(abi: &Self::Abi) -> bool

Tests whether the argument is a “none” instance. If so it will be deserialized as None, and otherwise it will be passed to FromWasmAbi.
Source§

impl OptionIntoWasmAbi for Cedarling

Source§

fn none() -> Self::Abi

Returns an ABI instance indicating “none”, which JS will interpret as the None branch of this option. Read more
Source§

impl RefFromWasmAbi for Cedarling

Source§

type Abi = WasmPtr<WasmRefCell<Cedarling>>

The Wasm ABI type references to Self are recovered from.
Source§

type Anchor = RcRef<Cedarling>

The type that holds the reference to Self for the duration of the invocation of the function that has an &Self parameter. This is required to ensure that the lifetimes don’t persist beyond one function call, and so that they remain anonymous.
Source§

unsafe fn ref_from_abi(js: Self::Abi) -> Self::Anchor

Recover a Self::Anchor from Self::Abi. Read more
Source§

impl RefMutFromWasmAbi for Cedarling

Source§

type Abi = WasmPtr<WasmRefCell<Cedarling>>

Same as RefFromWasmAbi::Abi
Source§

type Anchor = RcRefMut<Cedarling>

Same as RefFromWasmAbi::Anchor
Source§

unsafe fn ref_mut_from_abi(js: Self::Abi) -> Self::Anchor

Same as RefFromWasmAbi::ref_from_abi
Source§

impl SupportsConstructor for Cedarling

Source§

impl SupportsInstanceProperty for Cedarling

Source§

impl SupportsStaticProperty for Cedarling

Source§

impl TryFromJsValue for Cedarling

Source§

fn try_from_js_value(value: JsValue) -> Result<Self, JsValue>

Performs the conversion.
Source§

fn try_from_js_value_ref(value: &JsValue) -> Option<Self>

Performs the conversion.
Source§

impl VectorFromWasmAbi for Cedarling

Source§

type Abi = <Box<[JsValue]> as FromWasmAbi>::Abi

Source§

unsafe fn vector_from_abi(js: Self::Abi) -> Box<[Cedarling]>

Source§

impl VectorIntoWasmAbi for Cedarling

Source§

impl WasmDescribe for Cedarling

Source§

impl WasmDescribeVector for Cedarling

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> FromRef<T> for T
where T: Clone,

§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> IntoRequest<T> for T

§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
§

impl<L> LayerExt<L> for L

§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in [Layered].
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> ReturnWasmAbi for T
where T: IntoWasmAbi,

Source§

type Abi = <T as IntoWasmAbi>::Abi

Same as IntoWasmAbi::Abi
Source§

fn return_abi(self) -> <T as ReturnWasmAbi>::Abi

Same as IntoWasmAbi::into_abi, except that it may throw and never return in the case of Err.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<S, T> Upcast<T> for S
where T: UpcastFrom<S> + ?Sized, S: ?Sized,

Source§

fn upcast(&self) -> &T
where Self: ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider ref type within the Wasm bindgen generics type system. Read more
Source§

fn upcast_into(self) -> T
where Self: Sized + ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider type within the Wasm bindgen generics type system. Read more
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more