Skip to contents

Context policy checks provenance and authorization metadata after retrieval. Applications must also enforce tenant and ACL scope inside the retrieval query so unauthorized rows are never selected in the first place.

Usage

context_policy(
  required_columns = c("document_id", "source"),
  tenant_id = NULL,
  tenant_col = "tenant",
  principals = NULL,
  acl_col = NULL,
  trusted_sources = NULL,
  source_col = "source",
  allowed_trust_tiers = NULL,
  trust_col = "trust_tier",
  max_age_seconds = NULL,
  timestamp_col = "updated_at",
  authorize = NULL,
  now = Sys.time,
  show_stats = FALSE
)

Arguments

required_columns

Character vector of metadata columns that must exist and contain a value in every row.

tenant_id

Optional scalar tenant identifier required for every row.

tenant_col

Scalar name of the tenant column.

principals

Optional character vector of subject or role identifiers.

acl_col

Optional ACL column. Values may be character vectors, list column entries, or comma-separated strings.

trusted_sources

Optional character vector of allowed source values.

source_col

Scalar name of the source column.

allowed_trust_tiers

Optional character vector of allowed trust tiers.

trust_col

Scalar name of the trust-tier column.

max_age_seconds

Optional non-negative maximum age in seconds.

timestamp_col

Scalar name of the freshness timestamp column.

authorize

Optional function that receives a one-row data frame and returns TRUE only when the row is authorized.

now

Zero-argument function returning the current time. Override it for deterministic tests and examples.

show_stats

Show construction time and available usage metrics.

Value

A shieldr_context_policy object.

Examples

admission <- context_policy(
  required_columns = c("document_id", "source", "tenant"),
  tenant_id = "tenant-a"
)