Skip to main content

CallerBindingMode

Namespace: Meshmakers.Octo.Sdk.Common.EtlDataPipeline.Configuration

Per-trigger policy for turning the sender of a trigger into the execution's verified caller (AB#5126, "Strang B" of the pipeline-identity epic AB#4979). It makes "run anonymous" a deliberate choice instead of an accident of whether a channel happened to resolve a caller: a trigger says up front whether an unresolved sender is acceptable, tolerated, or a hard error.

public enum CallerBindingMode

Inheritance Object → ValueType → Enum → CallerBindingMode
Implements IComparable, ISpanFormattable, IFormattable, IConvertible

Remarks:

The three states are a small, totally ordered scale of increasing strictness — AnonymousAllowed < BindingOptional < BindingRequired — mirroring the None < Weak < Strong shape of the trust scale (AB#5122). The numeric keys carry that order.

🟢 Migration-safe by construction. A missing value deserialises to CallerBindingMode.AnonymousAllowed (value 0) — exactly the same pattern NodeExecutionIdentity uses. And CallerBindingMode.AnonymousAllowed reproduces today's behaviour byte for byte: no directory lookup is attempted, so a channel trigger runs as the service account (or system context) exactly as it did before this WI, and a caller that is already present on the execution (e.g. the bearer of FromHttpRequest@2, or the carried-through invoker of FromExecutePipelineCommand) is still honoured. Every pipeline authored before this property existed therefore keeps running unchanged.

Fields​

NameValueDescription
AnonymousAllowed0Anonymous is a first-class choice: the trigger does not attempt to resolve the sender against the verified-identifier directory. A caller already present on the execution is still used; otherwise the execution runs as the service account / system context. This is the default and equals the behaviour that existed before AB#5126.
BindingOptional1Bind when possible: the trigger resolves the sender against the directory and runs as the resolved caller when a binding exists; when the sender cannot be resolved it falls back to the service account (never rejected). The channel equivalent of an authenticated route that also accepts anonymous callers.
BindingRequired2Bind or reject: an unresolved sender is refused and the pipeline does not run — deliberately never silently downgraded to the service account. The strict mode for a channel that must act only on behalf of an identified user.