Skip to content

sgns::securecrdt::SecureCrdtRegistry

Thread-safe registry resolving a CRDT key to its policy entry.

#include <SecureCrdtRegistry.hpp>

Public Functions

Name
bool Register(const std::string & key_pattern, SecureCrdtRegistryEntry entry)
Registers the policy entry for key_pattern if absent. Compiles compiled_pattern as "/?" + key_pattern + "(/sig/[^/]+)?" so both the base key and a valid sig/<addr> child resolve to the same entry - mirrors CRDTDataFilter::RegisterElementFilter's regex shape (src/crdt/impl/crdt_data_filter.cpp).
bool RegisterIfAbsent(const std::string & key_pattern, SecureCrdtRegistryEntry entry)
Registers the policy entry for key_pattern ONLY when no entry for the pattern exists yet – an atomic-detecting insert that can never replace a live entry (G-WR-04: closes the check-then-act window between a caller's Resolve() pre-check and its Register(), which concurrent constructions could otherwise use to clobber a live policy entry and brick the registry still using it). Compiles compiled_pattern exactly like Register(): "/?" + key_pattern + "(/sig/[^/]+)?".
bool UnregisterIf(const std::string & key_pattern, const void * expected_token)
Removes the registration for key_pattern only if the caller's token matches the token supplied at Register() time (compare-and-remove, prevents a second unrelated registration from clobbering removal).
std::optional< SecureCrdtRegistryEntry > Resolve(const std::string & key) const
Resolves key against all registered patterns, returning the first matching entry (base_key or any sig/<addr> child).
std::vector< SecureCrdtRegistryEntry > AllEntries() const
Returns a snapshot copy of every currently-registered entry. Used by SecureCrdt::RegisterFilters to self-register a filter callback for each registered base_key pattern at startup.
bool RegisterCandidateDomain(const std::string & domain, CandidateDomainEntry entry)
void UnregisterCandidateDomainIf(const std::string & domain, const void * expected_token)
std::optional< CandidateDomainEntry > ResolveCandidateDomain(const std::string & domain) const
std::vector< CandidateDomainEntry > AllCandidateDomains() const

Public Functions Documentation

function Register

inline bool Register(
    const std::string & key_pattern,
    SecureCrdtRegistryEntry entry
)

Registers the policy entry for key_pattern if absent. Compiles compiled_pattern as "/?" + key_pattern + "(/sig/[^/]+)?" so both the base key and a valid sig/<addr> child resolve to the same entry - mirrors CRDTDataFilter::RegisterElementFilter's regex shape (src/crdt/impl/crdt_data_filter.cpp).

Parameters:

  • key_pattern Base key pattern (regex-escaped by the caller if it contains regex metacharacters).
  • entry Policy entry to register (compiled_pattern is overwritten by this call).

Return: true when inserted; false when this registry already owns the same pattern. Existing registrations are never replaced.

function RegisterIfAbsent

inline bool RegisterIfAbsent(
    const std::string & key_pattern,
    SecureCrdtRegistryEntry entry
)

Registers the policy entry for key_pattern ONLY when no entry for the pattern exists yet – an atomic-detecting insert that can never replace a live entry (G-WR-04: closes the check-then-act window between a caller's Resolve() pre-check and its Register(), which concurrent constructions could otherwise use to clobber a live policy entry and brick the registry still using it). Compiles compiled_pattern exactly like Register(): "/?" + key_pattern + "(/sig/[^/]+)?".

Parameters:

  • key_pattern Base key pattern (regex-escaped by the caller if it contains regex metacharacters).
  • entry Policy entry to register (compiled_pattern is overwritten by this call).

Return: true when the entry was inserted; false when an entry for the pattern already exists (the live entry is untouched and the caller's entry copy is destroyed only after the registry mutex has been released).

function UnregisterIf

inline bool UnregisterIf(
    const std::string & key_pattern,
    const void * expected_token
)

Removes the registration for key_pattern only if the caller's token matches the token supplied at Register() time (compare-and-remove, prevents a second unrelated registration from clobbering removal).

Parameters:

  • key_pattern Base key pattern to unregister.
  • expected_token Opaque token that must match the registering token for the removal to take effect.

Return: true when this call removed the entry; false when no entry existed or the live entry belongs to a different owner (lets the caller scope pattern-keyed cleanup – e.g. filter teardown – to the case where IT owned the entry).

function Resolve

inline std::optional< SecureCrdtRegistryEntry > Resolve(
    const std::string & key
) const

Resolves key against all registered patterns, returning the first matching entry (base_key or any sig/<addr> child).

Parameters:

  • key CRDT key to resolve.

Return: Snapshot of the matching entry, or std::nullopt if unregistered.

function AllEntries

inline std::vector< SecureCrdtRegistryEntry > AllEntries() const

Returns a snapshot copy of every currently-registered entry. Used by SecureCrdt::RegisterFilters to self-register a filter callback for each registered base_key pattern at startup.

Return: Vector of registered entries (order unspecified).

function RegisterCandidateDomain

inline bool RegisterCandidateDomain(
    const std::string & domain,
    CandidateDomainEntry entry
)

function UnregisterCandidateDomainIf

inline void UnregisterCandidateDomainIf(
    const std::string & domain,
    const void * expected_token
)

function ResolveCandidateDomain

inline std::optional< CandidateDomainEntry > ResolveCandidateDomain(
    const std::string & domain
) const

function AllCandidateDomains

inline std::vector< CandidateDomainEntry > AllCandidateDomains() const

Updated on 2026-10-06 at 13:34:20 +0000