The population a Tier 1 run writes, which the caller supplies.
use Mediate.Conformance.AdapterCase, world: MyApp.World hands the
template a module. That module answers what a population holds, what the
rule over it says, and how to write one through the seam. The properties
and the laws ask it for everything they need. The core package names no
schema and no rule of its own. So an adapter outside this repository
proves itself against its own tables.
A population is a struct of the module that implements this behaviour.
So a law that gets one reaches the module through the struct and carries
no second argument. module/1 is that step.
Summary
Types
What a grant sits on, in the terms the world keeps it in.
A population: a struct of the module that implements this behaviour.
Callbacks
The rule: what the population says about one subject, operation, and object.
Delete every row of the population through the seam, one row at a time, so the seam records each.
Change the account fact the rule reads so the subject no longer satisfies it, and answer the population.
The exemption every write of a population declares through the seam.
Every attribute value the population holds that a rule reads: the clearances, the roles, the expiries, and whatever else a fact column carries. The list holds nothing a decision event carries of its own, such as a subject kind. A law asserts that no decision event carries one of these values. So a value here that is also a subject id, an object id, or a verdict fails that law for the wrong reason.
Bring the scope schema up to that many rows, none of them granted, after the population is in the tables. The population knows which rows it holds, and this callback must not read them. A read goes through the seam, and an adapter that binds the database itself answers a read with no decision with nothing.
The subject the fixed worlds grant to, which is a user, and what they grant it on.
A random population, for the properties.
One subject, one object, one grant: the world the fail-closed and latency cases run over.
Write the population through the seam.
Write one grant to the subject on the grantable through the seam and
nothing else, with the attributes given, and answer the population it
leaves. The laws set expires_at, and mediation, which is the
mediate: option the write carries and the world's exemption when
absent. One write, so the case that counts the queries a fact write costs
can count it.
The object a grant on this thing covers.
Every object the population holds.
The operations the rule knows.
Take the subject's grant away, through the seam, and answer the population it leaves.
Every protected schema the properties scope over.
The schema the shape cases fill with rows and scope over. It is one of schemas/0.
granted/0 with more objects in the scope schema than the grant covers, for the shape cases.
Every subject the population knows, one of kind :privileged among them.
The same population with the grant taken out, for the case that writes one fact and counts the queries.
Functions
The module behind a population.
Types
Callbacks
@callback allowed?(t(), Mediate.subject(), atom(), Mediate.object()) :: boolean()
The rule: what the population says about one subject, operation, and object.
@callback clear(module()) :: :ok
Delete every row of the population through the seam, one row at a time, so the seam records each.
@callback disqualify(module(), t(), Mediate.subject()) :: t()
Change the account fact the rule reads so the subject no longer satisfies it, and answer the population.
@callback exemption() :: term()
The exemption every write of a population declares through the seam.
Every attribute value the population holds that a rule reads: the clearances, the roles, the expiries, and whatever else a fact column carries. The list holds nothing a decision event carries of its own, such as a subject kind. A law asserts that no decision event carries one of these values. So a value here that is also a subject id, an object id, or a verdict fails that law for the wrong reason.
@callback fill(module(), t(), pos_integer()) :: :ok
Bring the scope schema up to that many rows, none of them granted, after the population is in the tables. The population knows which rows it holds, and this callback must not read them. A read goes through the seam, and an adapter that binds the database itself answers a read with no decision with nothing.
@callback focus(t()) :: {Mediate.subject(), grantable()}
The subject the fixed worlds grant to, which is a user, and what they grant it on.
@callback generator() :: StreamData.t(t())
A random population, for the properties.
@callback granted() :: t()
One subject, one object, one grant: the world the fail-closed and latency cases run over.
Write the population through the seam.
Write one grant to the subject on the grantable through the seam and
nothing else, with the attributes given, and answer the population it
leaves. The laws set expires_at, and mediation, which is the
mediate: option the write carries and the world's exemption when
absent. One write, so the case that counts the queries a fact write costs
can count it.
@callback object_of(grantable()) :: Mediate.object()
The object a grant on this thing covers.
@callback objects(t()) :: [Mediate.object()]
Every object the population holds.
@callback operations() :: [atom()]
The operations the rule knows.
@callback revoke(module(), t(), Mediate.subject(), grantable()) :: t()
Take the subject's grant away, through the seam, and answer the population it leaves.
@callback schemas() :: [module()]
Every protected schema the properties scope over.
@callback scope_schema() :: module()
The schema the shape cases fill with rows and scope over. It is one of schemas/0.
@callback scoped() :: t()
granted/0 with more objects in the scope schema than the grant covers, for the shape cases.
@callback subjects(t()) :: [Mediate.subject()]
Every subject the population knows, one of kind :privileged among them.
@callback ungranted() :: t()
The same population with the grant taken out, for the case that writes one fact and counts the queries.