Something went wrong. Try again.
Identities for entities did.bot
agent llm did
Something went wrong. Try again.
1.7 kB · 41 lines
TypeScript
at commit 18ba4fe0
123456789101112131415161718192021222324252627282930313233343536373839404142// What a simulation looks like: the verdict, and one row per policy asked or// skipped. Kept apart from the view so a check can draw exactly what the page// draws.
import type { Simulation, SimulationRow } from "../checks.ts";import { h } from "../dom.ts";
/** What a policy that was not asked is called, in plain words. */const WHY: Record<string, string> = { notApplicable: "decides another kind of request", unbound: "no binding applies it to this account", notAsked: "not asked: a freeze ended the walk",};
/** The answer in one line: allowed, or refused by a policy, and why. */export function verdictLine(answer: Simulation): HTMLElement { const denied = answer.verdict !== "allow"; const refuser = (answer.consulted ?? []).find((row) => row.outcome !== "allow"); return h( "p", { class: `status ${denied ? "denied" : "allowed"}` }, denied ? `Refused by ${refuser?.name ?? "a policy"}: ${answer.reason ?? ""}` : "Allowed: no policy of yours refuses it.", );}
/** One policy's own answer, or the reason it was never asked. */export function policyRow(entry: SimulationRow): HTMLElement { const state = entry.outcome ?? "skipped"; return h( "li", { class: `policy-row ${state}` }, h("span", { class: "outcome" }, entry.outcome ?? "not asked"), h("span", { class: "name" }, entry.name), h("span", { class: "mono where" }, `${entry.rkey} · ${entry.path}${entry.statement ? ` · ${entry.statement}` : ""}`), h("span", { class: "action mono" }, entry.action), entry.reason ? h("p", { class: "reason" }, entry.reason) : null, entry.why ? h("p", { class: "hint" }, WHY[entry.why] ?? entry.why) : null, );}