pub struct Cedarling { /* private fields */ }Expand description
The instance of the Cedarling application.
Implementations§
Source§impl Cedarling
impl Cedarling
Sourcepub async fn new(config: &Object) -> Result<Cedarling, Error>
pub async fn new(config: &Object) -> Result<Cedarling, Error>
Creates a Cedarling application from bootstrap properties.
§Arguments
config- A plain object of Cedarling bootstrap-property names and values.
§Example
await initWasm();
const cedarling = await Cedarling.new({
CEDARLING_APPLICATION_NAME: "task-api",
CEDARLING_POLICY_STORE_URI: "https://example.com/policy-store.cjar",
CEDARLING_LOG_TYPE: "memory",
CEDARLING_LOG_TTL: 120,
});Sourcepub async fn new_from_map(config: Map) -> Result<Cedarling, Error>
pub async fn new_from_map(config: Map) -> Result<Cedarling, Error>
Creates a new Cedarling application from a JavaScript Map.
§Arguments
config- AMapof Cedarling bootstrap-property names and values.
§Example
await initWasm();
const cedarling = await Cedarling.newFromMap(new Map([
["CEDARLING_APPLICATION_NAME", "task-api"],
["CEDARLING_POLICY_STORE_URI", "https://example.com/policy-store.cjar"],
["CEDARLING_LOG_TYPE", "memory"],
["CEDARLING_LOG_TTL", 120],
]));Authorize an unsigned request carrying an optional single principal.
Makes an authorization decision based on the [RequestUnsigned].
When principal is omitted / null on the JS side the core uses Cedar
partial evaluation; residual-dependent requests fail closed with
Decision::Deny and surface residual policy ids in
response.diagnostics.reason.
§Arguments
request- JSON string representation of [RequestUnsigned].
§Example
const result = await cedarling.authorizeUnsigned(JSON.stringify(request));Authorize a batch of unsigned requests against one shared principal.
Setup work (principal build + pushed-data snapshot) runs once and each
item is evaluated in input order. Results are returned inside a
BatchAuthorizeUnsignedResponse carrying the shared batch_id.
Batch-level failures (validation, principal parse) reject the whole
call; per-item failures are returned as BatchItemError results and
exposed by WASM with is_ok=false and error, while genuine Cedar
denials remain AuthorizeResult values with decision=false.
§Arguments
request- JSON string representation of [BatchAuthorizeUnsignedRequest].
§Example
const result = await cedarling.authorizeUnsignedBatch(JSON.stringify(batchRequest));Authorize a batch of multi-issuer requests against one shared token set.
Tokens are validated and token/issuer entities are built once, then
each item is evaluated in input order. Batch-level failures (validation,
JWT verification, status-list refresh) reject the whole call; per-item
failures are returned as BatchItemError results and exposed by WASM
with is_ok=false and error, while genuine Cedar denials remain
AuthorizeResult values with decision=false.
§Arguments
request- JSON string representation of [BatchAuthorizeMultiIssuerRequest].
§Example
const result = await cedarling.authorizeMultiIssuerBatch(JSON.stringify(batchRequest));Sourcepub fn annotations_map(&self, policy_ids: Vec<String>) -> Result<JsValue, Error>
pub fn annotations_map(&self, policy_ids: Vec<String>) -> Result<JsValue, Error>
Merge the annotations (@key("value")) of the given policies into a single object.
Intended for resolving the determining policies of an authorization decision:
pass result.response.diagnostics.reason.
Lossy: if the same annotation key appears on several policies, one value wins
arbitrarily. Use annotationValues / annotationsByPolicy when duplicates
matter. Unknown policy IDs are silently skipped.
§Arguments
policy_ids- List of policy IDs whose annotations should be merged into a single object. Typicallyresult.response.diagnostics.reasonfrom an authorization result.
§Example
const annotations = cedarling.annotationsMap(result.response.diagnostics.reason);
// { redirect: "/upgrade", tier: "premium" }Sourcepub fn annotation_values(
&self,
policy_ids: Vec<String>,
key: &str,
) -> Vec<String>
pub fn annotation_values( &self, policy_ids: Vec<String>, key: &str, ) -> Vec<String>
Collect every value of the annotation key across the given policies,
preserving duplicates. Unknown policy IDs are silently skipped.
§Arguments
policy_ids- List of policy IDs to search. Typicallyresult.response.diagnostics.reasonfrom an authorization result.key- The annotation key to collect values for (e.g."redirect").
§Example
const redirects = cedarling.annotationValues(
result.response.diagnostics.reason,
"redirect",
);
// ["/upgrade"]Sourcepub fn annotations_by_policy(
&self,
policy_ids: Vec<String>,
) -> Result<JsValue, Error>
pub fn annotations_by_policy( &self, policy_ids: Vec<String>, ) -> Result<JsValue, Error>
Return the annotations of each given policy, grouped by policy ID. It is
the loss-free companion to annotationsMap. Unknown policy IDs are
silently skipped.
§Arguments
policy_ids- List of policy IDs whose annotations should be returned grouped by policy ID. Typicallyresult.response.diagnostics.reasonfrom an authorization result.
§Example
const byPolicy = cedarling.annotationsByPolicy(result.response.diagnostics.reason);
// { "5": { redirect: "/upgrade", tier: "premium" } }Sourcepub fn get_log_by_id(&self, id: &str) -> Result<JsValue, Error>
pub fn get_log_by_id(&self, id: &str) -> Result<JsValue, Error>
Sourcepub fn get_log_ids(&self) -> Array
pub fn get_log_ids(&self) -> Array
Sourcepub fn get_logs_by_request_id_and_tag(
&self,
request_id: &str,
tag: &str,
) -> Result<Vec<JsValue>, Error>
pub fn get_logs_by_request_id_and_tag( &self, request_id: &str, tag: &str, ) -> Result<Vec<JsValue>, Error>
Returns retained memory logs matching one request ID and indexed value.
§Arguments
requestId- The request identifier to match.tag- A log kind ("System","Decision", or"Metric") or a system-log level such as"DEBUG".
§Example
const logs = cedarling.getLogsByRequestIdAndTag("request-id", "System");Sourcepub fn push_data_ctx(
&self,
key: &str,
value: JsValue,
ttl_secs: Option<u64>,
) -> Result<(), Error>
pub fn push_data_ctx( &self, key: &str, value: JsValue, ttl_secs: Option<u64>, ) -> Result<(), Error>
Push a value into the data store with an optional TTL. If the key already exists, the value will be replaced. If TTL is not provided, the default TTL from configuration is used.
§Arguments
key- A string key for the data entry (must not be empty)value- The value to store (any JSON-serializable JavaScript value: object, array, string, number, boolean)ttl_secs- Optional TTL in seconds (undefined/null uses default from config)
§Example
cedarling.pushDataCtx("user:123", { name: "John", age: 30 }, 3600);
cedarling.pushDataCtx("config", { setting: "value" }); // Uses default TTLSourcepub fn get_data_ctx(&self, key: &str) -> Result<JsValue, Error>
pub fn get_data_ctx(&self, key: &str) -> Result<JsValue, Error>
Sourcepub fn get_data_entry_ctx(&self, key: &str) -> Result<Option<DataEntry>, Error>
pub fn get_data_entry_ctx(&self, key: &str) -> Result<Option<DataEntry>, Error>
Get a data entry with full metadata by key. Returns undefined if the key doesn’t exist or the entry has expired.
§Arguments
key- A string key for the data entry to retrieve
§Example
const entry = cedarling.getDataEntryCtx("user:123");
if (entry !== undefined) {
console.log(entry.key); // "user:123"
console.log(entry.value()); // { name: "John", age: 30 }
console.log(entry.data_type); // "Record"
console.log(entry.created_at); // "2024-01-01T12:00:00Z"
console.log(entry.access_count); // 5
}Sourcepub fn remove_data_ctx(&self, key: &str) -> Result<bool, Error>
pub fn remove_data_ctx(&self, key: &str) -> Result<bool, Error>
Sourcepub fn clear_data_ctx(&self) -> Result<(), Error>
pub fn clear_data_ctx(&self) -> Result<(), Error>
Sourcepub fn list_data_ctx(&self) -> Result<Array, Error>
pub fn list_data_ctx(&self) -> Result<Array, Error>
Sourcepub fn get_stats_ctx(&self) -> Result<DataStoreStats, Error>
pub fn get_stats_ctx(&self) -> Result<DataStoreStats, Error>
Get statistics about the data store.
§Arguments
None.
§Example
const stats = cedarling.getStatsCtx();
console.log(`Entries: ${stats.entry_count}/${stats.max_entries || 'unlimited'}`);
console.log(`Capacity: ${stats.capacity_usage_percent.toFixed(2)}%`);
console.log(`Total size: ${stats.total_size_bytes} bytes`);Sourcepub fn is_trusted_issuer_loaded_by_name(&self, issuer_id: &str) -> bool
pub fn is_trusted_issuer_loaded_by_name(&self, issuer_id: &str) -> bool
Sourcepub fn is_trusted_issuer_loaded_by_iss(&self, iss_claim: &str) -> bool
pub fn is_trusted_issuer_loaded_by_iss(&self, iss_claim: &str) -> bool
Sourcepub fn total_issuers(&self) -> usize
pub fn total_issuers(&self) -> usize
Sourcepub fn loaded_trusted_issuers_count(&self) -> usize
pub fn loaded_trusted_issuers_count(&self) -> usize
Sourcepub fn loaded_trusted_issuer_ids(&self) -> Array
pub fn loaded_trusted_issuer_ids(&self) -> Array
Sourcepub fn failed_trusted_issuer_ids(&self) -> Array
pub fn failed_trusted_issuer_ids(&self) -> Array
Trait Implementations§
Source§impl FromWasmAbi for Cedarling
impl FromWasmAbi for Cedarling
Source§impl IntoWasmAbi for Cedarling
impl IntoWasmAbi for Cedarling
Source§impl LongRefFromWasmAbi for Cedarling
impl LongRefFromWasmAbi for Cedarling
Source§impl OptionFromWasmAbi for Cedarling
impl OptionFromWasmAbi for Cedarling
Source§impl OptionIntoWasmAbi for Cedarling
impl OptionIntoWasmAbi for Cedarling
Source§impl RefFromWasmAbi for Cedarling
impl RefFromWasmAbi for Cedarling
Source§type Abi = WasmPtr<WasmRefCell<Cedarling>>
type Abi = WasmPtr<WasmRefCell<Cedarling>>
Self are recovered from.Source§impl RefMutFromWasmAbi for Cedarling
impl RefMutFromWasmAbi for Cedarling
impl SupportsConstructor for Cedarling
impl SupportsInstanceProperty for Cedarling
impl SupportsStaticProperty for Cedarling
Source§impl TryFromJsValue for Cedarling
impl TryFromJsValue for Cedarling
Source§impl VectorFromWasmAbi for Cedarling
impl VectorFromWasmAbi for Cedarling
Source§impl VectorIntoWasmAbi for Cedarling
impl VectorIntoWasmAbi for Cedarling
Auto Trait Implementations§
impl !RefUnwindSafe for Cedarling
impl !UnwindSafe for Cedarling
impl Freeze for Cedarling
impl Send for Cedarling
impl Sync for Cedarling
impl Unpin for Cedarling
impl UnsafeUnpin for Cedarling
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request§impl<L> LayerExt<L> for L
impl<L> LayerExt<L> for L
§fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
Layered].§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> ReturnWasmAbi for Twhere
T: IntoWasmAbi,
impl<T> ReturnWasmAbi for Twhere
T: IntoWasmAbi,
Source§type Abi = <T as IntoWasmAbi>::Abi
type Abi = <T as IntoWasmAbi>::Abi
IntoWasmAbi::AbiSource§fn return_abi(self) -> <T as ReturnWasmAbi>::Abi
fn return_abi(self) -> <T as ReturnWasmAbi>::Abi
IntoWasmAbi::into_abi, except that it may throw and never
return in the case of Err.