Search Apps Documentation Source Content File Folder Download Copy Actions Download State String Boolean Number Struct Map Slice Pointer Function Closure Reference Nil Package Type Interface Unknown

capwallet source realm

Package capwallet issues narrow, bounded, revocable capabilities to agents — instead of handing an agent a wallet key...

Overview

Package capwallet issues narrow, bounded, revocable capabilities to agents — instead of handing an agent a wallet key and hoping its prompt stays safe.

The demo makes three ideas that are usually conflated stand apart:

  • identity — "this is agent Percy"
  • authorization — "Percy may call this function on this realm"
  • approval — "Percy may do it at most N times, for ≤ M coins, before block H, and I can revoke it at any moment"

A capability is the third thing: a least-privilege grant with a ceiling, an expiry, a use counter and a kill switch. Other realms consult Authorized() before honoring an agent action; the granter revokes with one call the instant something looks wrong.

Functions 7

func Authorized

Action
1func Authorized(id uint64, principal address, coins int64) bool
source

Authorized reports whether principal may exercise capability id for the given coin amount right now — the check a target realm runs before acting. It never mutates state or consumes a use.

func Exercise

crossing Action
1func Exercise(cur realm, id uint64, coins int64)
source

Exercise consumes one use of a capability. Only the principal may call it, and every bound is checked: not revoked, not expired, uses remaining, and coins within the ceiling. On success the use is recorded and the counter decremented.

func Grant

crossing Action
1func Grant(
2	cur realm,
3	principal address,
4	targetRealm, function string,
5	maxCoins, validUntil int64,
6	uses uint32,
7	argsPolicy string,
8) uint64
source

Grant issues a capability. The caller becomes its granter and can revoke it later. validUntil is an absolute block height (0 = no expiry).

func Render

1func Render(path string) string
source

Render shows all capabilities, or one capability's detail + usage at :<id>.

func Revoke

crossing Action
1func Revoke(cur realm, id uint64)
source

Revoke disables a capability immediately. Only the granter may revoke.

func Get

Action
1func Get(id uint64) Capability
source

Get returns a copy of a capability.

Types 2

type Capability

struct
 1type Capability struct {
 2	ID            uint64
 3	Granter       address
 4	Principal     address // the only address that may exercise it
 5	TargetRealm   string  // realm the capability is scoped to
 6	Function      string  // function the capability authorizes
 7	MaxCoins      int64   // per-exercise ceiling in ugnot (0 = none allowed)
 8	ValidUntil    int64   // block height after which it expires (0 = never)
 9	RemainingUses uint32  // exercises left (0 = exhausted)
10	ArgsPolicy    string  // human-readable note on allowed arguments
11	Revoked       bool
12	GrantedAt     int64
13	Uses          []Use
14}
source

Capability is a least-privilege grant from a granter to a principal.

type Use

struct
1type Use struct {
2	By     address
3	Coins  int64
4	Height int64
5}
source

Use records one exercise of a capability.

Imports 4

Source Files 2