Packages
spawn
1.0.0-rc.35
2.0.0-RC9
2.0.0-RC8
2.0.0-RC7
2.0.0-RC6
2.0.0-RC5
2.0.0-RC4
2.0.0-RC3
2.0.0-RC2
2.0.0-RC14
2.0.0-RC13
2.0.0-RC12
2.0.0-RC11
2.0.0-RC10
2.0.0-RC1
1.4.3
1.4.2
1.4.1
1.4.0
1.3.3
1.3.2
1.3.1
1.3.0
1.2.1
1.2.0
1.1.1
1.1.0
1.0.1
1.0.0
1.0.0-rc3
1.0.0-rc16
1.0.0-rc1
1.0.0-rc.38
1.0.0-rc.37
1.0.0-rc.36
1.0.0-rc.35
1.0.0-rc.34
1.0.0-rc.33
1.0.0-rc.32
1.0.0-rc.31
1.0.0-rc.30
1.0.0-rc.29
1.0.0-rc.28
1.0.0-rc.27
1.0.0-rc.26
1.0.0-rc.25
1.0.0-rc.24
1.0.0-rc.23
1.0.0-rc.22
1.0.0-rc.21
1.0.0-rc.20
1.0.0-rc.19
1.0.0-rc.18
1.0.0-rc.17
1.0.0-rc.2
0.6.3
0.6.2
0.6.1
0.6.0
0.5.5
0.5.4
0.5.3
0.5.1
0.5.0
0.5.0-rc.13
0.5.0-rc.12
0.5.0-rc.11
0.5.0-rc.10
0.5.0-rc.9
0.5.0-rc.8
0.5.0-rc.7
0.5.0-rc.6
0.5.0-rc.5
0.5.0-rc.3
0.5.0-alpha.13
0.5.0-alpha.12
0.5.0-alpha.11
0.5.0-alpha.10
0.5.0-alpha.9
0.5.0-alpha.8
0.5.0-alpha.7
0.5.0-alpha.6
0.5.0-alpha.5
0.5.0-alpha.4
0.5.0-alpha.3
0.5.0-alpha.2
0.5.0-alpha.1
0.1.0
Spawn is the core lib for Spawn Actors System
Current section
Files
Jump to
Current section
Files
lib/actors/security/acl/rules/acl_evaluator.ex
defmodule Actors.Security.Acl.Rules.AclEvaluator do
@moduledoc """
`AclEvaluator`is responsible for evaluating whether a request can be accepted
or not based on the informed Access Control List policy.
"""
alias Actors.Security.Acl.Policy
alias Eigr.Functions.Protocol.Actors.{
Actor,
ActorId
}
alias Eigr.Functions.Protocol.InvocationRequest
@doc """
Applies a policy on a request by evaluating whether the request should pass or not.
## Example
iex> Actors.Security.Acl.Rules.AclEvaluator.eval(
...> %Actors.Security.Acl.Policy{
...> name: "the-police",
...> type: :allow,
...> actors: ["*"],
...> actions: ["get"],
...> actor_systems: ["*"]
...> },
...> %Eigr.Functions.Protocol.InvocationRequest{
...> actor: %Eigr.Functions.Protocol.Actors.Actor{id: %Eigr.Functions.Protocol.Actors.ActorId{name: "joe"}},
...> action_name: "get",
...> caller: %Eigr.Functions.Protocol.Actors.ActorId{name: "robert", system: "actor-system"}
...> }
...> )
true
"""
@spec eval(Policy.t(), InvocationRequest.t(), Keyword.t()) :: boolean()
def eval(policy, invocation, opts \\ [])
def eval(
%Policy{
name: name,
type: type,
actors: actors,
actions: actions,
actor_systems: actor_systems
},
invocation,
opts
) do
actors = normalize_list_input(actors)
actions = normalize_list_input(actions)
actor_systems = normalize_list_input(actor_systems)
eval_options = [name: name, invocation: invocation]
opts = Keyword.merge(opts, eval_options)
do_evaluation(type, actor_systems, actors, actions, opts)
end
defp do_evaluation(type, :all, :all, :all, _opts) when is_atom(type) and type == :allow,
do: true
defp do_evaluation(type, :all, :all, :all, _opts) when is_atom(type) and type == :deny,
do: false
defp do_evaluation(type, actor_systems, actors, actions, opts) do
%InvocationRequest{
actor: %Actor{} = _actor,
caller: %ActorId{name: from_actor_name, system: from_system},
action_name: action
} = _invocation = Keyword.get(opts, :invocation)
has_system? = match_op?(actor_systems, from_system)
has_actor_name? = match_op?(actors, from_actor_name)
has_action? = match_op?(actions, action)
case type do
:allow ->
has_system? && has_actor_name? && has_action?
:deny ->
!(has_system? && has_actor_name? && has_action?)
end
end
defp match_op?(:all, _elem), do: true
defp match_op?(list, elem), do: Enum.member?(list, elem)
defp normalize_list_input(list) do
if Enum.member?(list, "*") do
:all
else
list
end
end
end