Function: sanitizeContextToDeclared()
function sanitizeContextToDeclared(context: AccessContext, isDeclared: (path: string) => boolean): AccessContext;Defined in: shared/access/kernel.ts:431
Restrict a caller-supplied AccessContext to ONLY declared attributes.
Every subject / resource / environment key not declared in the
attribute registry (<namespace>.<attr>) is dropped, so a spoofed
{ subject: { tier: "admin" } } for an undeclared attribute can never
satisfy a condition or selector placeholder. This is the evaluation-time
half of the §3 trust boundary.
isDeclared(path) is the registry predicate. Callers without a registry
skip this sanitizer and remain responsible for every supplied attribute.
Parameters
| Parameter | Type |
|---|---|
context | AccessContext |
isDeclared | (path: string) => boolean |