MCPcopy Create free account
hub / github.com/hashintel/hash / create_policy

Method create_policy

libs/@local/graph/postgres-store/src/store/postgres/mod.rs:1422–1475  ·  view source on GitHub ↗
(
        &mut self,
        authenticated_actor: AuthenticatedActor,
        policy: PolicyCreationParams,
    )

Source from the content-addressed store, hash-verified

1420 C: AsClient,
1421{
1422 async fn create_policy(
1423 &mut self,
1424 authenticated_actor: AuthenticatedActor,
1425 policy: PolicyCreationParams,
1426 ) -> Result<PolicyId, Report<CreatePolicyError>> {
1427 let transaction = self
1428 .transaction()
1429 .await
1430 .change_context(CreatePolicyError::StoreError)?;
1431
1432 let policy_ids = transaction.insert_policies_into_database([&policy]).await?;
1433 let &[policy_id] = policy_ids.as_slice() else {
1434 unreachable!("Expected exactly one policy ID");
1435 };
1436
1437 let policy_components = PolicyComponents::builder(&transaction)
1438 .with_actor(authenticated_actor)
1439 .with_action(ActionName::CreatePolicy, MergePolicies::No)
1440 .with_policy_meta_resource(&PolicyMetaResource {
1441 id: policy_id,
1442 actions: &policy.actions,
1443 resource: policy.resource.as_ref(),
1444 })
1445 .await
1446 .change_context(CreatePolicyError::BuildPolicyComponents)?;
1447
1448 match policy_components
1449 .build_policy_set([ActionName::CreatePolicy])
1450 .change_context(CreatePolicyError::PolicySetCreation)?
1451 .evaluate(
1452 &Request {
1453 actor: policy_components.actor_id(),
1454 action: ActionName::CreatePolicy,
1455 resource: &ResourceId::Policy(policy_id),
1456 context: RequestContext::default(),
1457 },
1458 policy_components.context(),
1459 )
1460 .change_context(CreatePolicyError::StoreError)?
1461 {
1462 Authorized::Always => {}
1463 Authorized::Never => {
1464 return Err(Report::new(CreatePolicyError::NotAuthorized))
1465 .attach(StatusCode::PermissionDenied);
1466 }
1467 }
1468
1469 transaction
1470 .commit()
1471 .await
1472 .change_context(CreatePolicyError::StoreError)?;
1473
1474 Ok(policy_id)
1475 }
1476
1477 async fn get_policy_by_id(
1478 &self,

Callers 3

deep_team_hierarchyFunction · 0.45

Calls 15

ErrInterface · 0.85
OkInterface · 0.85
with_actionMethod · 0.80
with_actorMethod · 0.80
build_policy_setMethod · 0.80
actor_idMethod · 0.80
PolicyClass · 0.50
defaultFunction · 0.50
change_contextMethod · 0.45
transactionMethod · 0.45

Tested by 3

deep_team_hierarchyFunction · 0.36