Expand description
Visibility and attribution disclosure.
These are primitives, not a policy: the application decides which
audiences a viewer holds and who is privileged. Everything that leaves the
system for a viewer (API responses, exports) should pass through
view_record / view_history so that restricted records, events and
sources, and withheld identities, are never exposed by accident.
Structs§
- Viewer
- Who is looking.
Functions§
- view_
history - The events of a history that
viewermay see, with restricted content removed and withheld identities masked. Callers must first check that the record’s current state is visible (seeview_record). - view_
record - The record as
viewermay see it, orNoneif it is not visible.