Skip to main content

Module access

Module access 

Source
Expand description

Visibility and attribution disclosure.

These are primitives, not a policy: the application decides which audiences a viewer holds and who is privileged. Everything that leaves the system for a viewer (API responses, exports) should pass through view_record / view_history so that restricted records, events and sources, and withheld identities, are never exposed by accident.

Structs§

Viewer
Who is looking.

Functions§

view_history
The events of a history that viewer may see, with restricted content removed and withheld identities masked. Callers must first check that the record’s current state is visible (see view_record).
view_record
The record as viewer may see it, or None if it is not visible.