Skip to main content

DenialReason

Enum DenialReason 

Source
pub enum DenialReason {
    RedirectNotInAllowlist,
    InsecureScheme,
    HostInBlockList,
    SizeCapExceeded,
    SchemaDrift,
    CapabilityNotGranted,
    RateLimitWindow,
    SsrfPrivateAddress,
    ContentTypeMismatch,
}
Expand description

Closed-set reasons a denial-class error envelope can carry on its optional denial_context.reason field.

Wire form (JSON / MCP) is snake_case — e.g. "redirect_not_in_allowlist". The set is closed per ADR-0023 §2: adding a new variant is a minor semver bump; renaming or repurposing one is a breaking change. Mirrors the stability rule that already governs ErrorCode.

See DenialContext for the surrounding struct, docs/ERRORS.md §3.1 for the wire surface, and docs/PUBLIC_API.md §8 for the semver-locked surface contract.

Variants§

§

RedirectNotInAllowlist

Redirect target host did not match the source’s allowlist (HttpError::RedirectDenied).

§

InsecureScheme

Redirect target had a non-HTTPS scheme (HttpError::InsecureRedirect).

§

HostInBlockList

Source produced a URL whose host is on a future blocklist.

Reserved — no producer wired yet. Will be emitted by the future per-source URL host-blocklist guard once that component lands (post-Phase-1 supply-chain hardening; see docs/REDIRECT_ALLOWLIST.md §4 for the staging plan).

§

SizeCapExceeded

Body exceeded PDF_MAX_BYTES (HttpError::OversizedBody).

§

SchemaDrift

Store entry’s schema_version is ahead of this binary.

Reserved — no producer wired yet. Will be emitted by the FsStore schema-rejection path once the read-side bump check lands (it currently only writes the current SCHEMA_VERSION).

§

CapabilityNotGranted

Source not in the runtime CapabilityProfile (FetchError::NotEligible).

§

RateLimitWindow

Rate limiter rejected the call inside the current window.

Reserved — no producer wired yet. Will be emitted by RateLimiter once the limiter surfaces structured denials (Phase 2+; today the limiter only sleeps to enforce the window).

§

SsrfPrivateAddress

SSRF guard rejected a private / link-local / cloud-metadata address.

Reserved — no producer wired yet. Will be emitted by the future SSRF pre-flight check (post-Phase-1 supply-chain hardening; the workspace currently relies on rustls + the HTTPS-only redirect policy to keep the attack surface small).

§

ContentTypeMismatch

Response Content-Type / magic-byte mismatch (HttpError::NotAPdf).

Trait Implementations§

Source§

impl Clone for DenialReason

Source§

fn clone(&self) -> DenialReason

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for DenialReason

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for DenialReason

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Hash for DenialReason

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl PartialEq for DenialReason

Source§

fn eq(&self, other: &DenialReason) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Serialize for DenialReason

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl Copy for DenialReason

Source§

impl Eq for DenialReason

Source§

impl StructuralPartialEq for DenialReason

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,