From 45df4d0d9b577fecee798d672695fe24ff57fb1b Mon Sep 17 00:00:00 2001 From: mo khan Date: Tue, 15 Jul 2025 16:37:08 -0600 Subject: feat: migrate from Cedar to SpiceDB authorization system This is a major architectural change that replaces the Cedar policy-based authorization system with SpiceDB's relation-based authorization. Key changes: - Migrate from Rust to Go implementation - Replace Cedar policies with SpiceDB schema and relationships - Switch from envoy `ext_authz` with Cedar to SpiceDB permission checks - Update build system and dependencies for Go ecosystem - Maintain Envoy integration for external authorization This change enables more flexible permission modeling through SpiceDB's Google Zanzibar inspired relation-based system, supporting complex hierarchical permissions that were difficult to express in Cedar. Breaking change: Existing Cedar policies and Rust-based configuration will no longer work and need to be migrated to SpiceDB schema. --- vendor/windows-core/src/agile_reference.rs | 39 ------------------------------ 1 file changed, 39 deletions(-) delete mode 100644 vendor/windows-core/src/agile_reference.rs (limited to 'vendor/windows-core/src/agile_reference.rs') diff --git a/vendor/windows-core/src/agile_reference.rs b/vendor/windows-core/src/agile_reference.rs deleted file mode 100644 index 30554e97..00000000 --- a/vendor/windows-core/src/agile_reference.rs +++ /dev/null @@ -1,39 +0,0 @@ -use super::*; -use core::marker::PhantomData; - -/// A type representing an agile reference to a COM/WinRT object. -#[repr(transparent)] -#[derive(Clone, PartialEq, Eq)] -pub struct AgileReference(imp::IAgileReference, PhantomData); - -impl AgileReference { - /// Creates an agile reference to the object. - pub fn new(object: &T) -> Result { - // TODO: this assert is required until we can catch this at compile time using an "associated const equality" constraint. - // For example, > - // https://github.com/rust-lang/rust/issues/92827 - assert!(T::UNKNOWN); - unsafe { - imp::RoGetAgileReference( - imp::AGILEREFERENCE_DEFAULT, - &T::IID, - core::mem::transmute::<&T, &IUnknown>(object), - ) - .map(|reference| Self(reference, Default::default())) - } - } - - /// Retrieves a proxy to the target of the `AgileReference` object that may safely be used within any thread context in which get is called. - pub fn resolve(&self) -> Result { - unsafe { self.0.Resolve() } - } -} - -unsafe impl Send for AgileReference {} -unsafe impl Sync for AgileReference {} - -impl core::fmt::Debug for AgileReference { - fn fmt(&self, f: &mut core::fmt::Formatter<'_>) -> core::fmt::Result { - write!(f, "AgileReference({:?})", &self.0) - } -} -- cgit v1.2.3