Policies over workflows
impl Rule<Params> for Desk {
fn on_workflow(p: Params, ctx: Ctx<View>) -> (Verdict, Attest) {
let mut v = Verdict::require(p.allowed_programs.contains(ctx.method().program_id()), "desk/program");
for f in ctx.flows_out() {
v = v.and(Verdict::require(f.amount <= p.per_flow_cap, "desk/flow-cap"));
}
(v, Attest::none())
}
}Ctx<View> exposes records_in(), records_out(), notes_in(),
notes_out(), flows_in(), flows_out(), method(), actors(), and the
phase accessors. Typed record accessors (ctx.record_in::<Escrow>(0)) exist
only for templates the policy crate imports and only return a value when the
customer is a stakeholder, else None, so a policy cannot depend on a
record it cannot see.