# `Beamlet.Policy.Default`
[🔗](https://github.com/aaronrussell/beamlet/blob/v0.1.0/lib/beamlet/policy/default.ex#L1)

The policy Beamlet ships, which every token starts from.

`default` grants everyday Elixir, a few Erlang modules, the Phoenix
and Ecto modules agents build pages and data with, and the `Host.*`
stdlib. It leaves out what reaches past the beamlet directly: the
filesystem, processes, the environment and loading code. Agent code
does those through `Host.*` instead. To change any of it, declare a
policy (`Beamlet.Policy`).

## The policy

This is `default` as an agent reads it with
`Host.Code.print_policy/0`, and as
`beamlet policies.show default` prints it.

```text
Policy: default
Tools: define, eval, patch

Standard Elixir and Erlang are available; this is what the policy deliberately withholds. Anything else denied is simply not granted on your beamlet. Host.Code.print_modules() shows what is.

Rules for your code:
  defmacro/defmacrop are not permitted in define
  call targets must be literal modules

Not available:
  :file, :filelib, File, File.Stat, File.Stream
    — Host.File provides scoped file access
  :atomics, :counters, :dets, :ets, :persistent_term, Agent
    — state that outlives an eval is kept in Host.KV
  :gen_server, :gen_statem, :proc_lib, :timer, DynamicSupervisor, GenServer, PartitionSupervisor, Process, Registry, Supervisor, Task, Task.Supervisor
    — process primitives are withheld as a family; there is no sibling to reach for
  Application
    — environment and application config may hold credentials
  :code, :erl_eval, Code, Module
    — durable code is made with the define tool, and Host.Code.print_modules() shows what is on your beamlet
  Phoenix.Endpoint, Phoenix.LiveView.Router, Phoenix.Router, Plug.Router
    — the URL surface is managed through Host.Router
  Phoenix.PubSub
    — publish/subscribe goes through Host.PubSub
  Ecto.Migrator
    — migrations are run through Host.Migrator
  Req, Req.Finch, Req.Request
    — HTTP requests are made with Host.HTTP, which takes Req's arguments and returns a Req.Response
  Ecto.Adapters.SQL, Ecto.Repo
    — the agent database is reached through Host.Repo; raw SQL is Host.Repo.query!(sql)

Partially granted:
  :crypto — all except engine_add/1, engine_by_id/1, engine_ctrl_cmd_string/3, engine_ctrl_cmd_string/4, engine_get_all_methods/0, engine_get_id/1, engine_get_name/1, engine_list/0, engine_load/3, engine_load/4, engine_methods_convert_to_bitmask/2, engine_register/2, engine_remove/1, engine_unload/1, engine_unload/2, engine_unregister/2, ensure_engine_loaded/2, ensure_engine_loaded/3, ensure_engine_unloaded/1, ensure_engine_unloaded/2
  :erlang — only adler32/1, adler32/2, crc32/1, crc32/2, external_size/1, external_size/2, phash2/1, phash2/2
  Ecto.Migration — all except execute_file/1, execute_file/2
  Function — all except capture/3
  Host.Repo — all except disconnect_all/1, disconnect_all/2, put_dynamic_repo/1, start_link/0, start_link/1, stop/0, stop/1
  IO — only chardata_to_string/1, inspect/1, inspect/2, iodata_length/1, iodata_to_binary/1, puts/1, warn/1
  Kernel — all except apply/2, apply/3, exit/1, send/2, spawn/1, spawn/3, spawn_link/1, spawn_link/3, spawn_monitor/1, spawn_monitor/3
  List — all except to_atom/1, to_existing_atom/1
  Macro — only camelize/1, to_string/1, underscore/1
  Path — all except wildcard/1, wildcard/2
  Phoenix.Component — all except embed_templates/1, embed_templates/2
  Phoenix.Controller — all except send_download/2, send_download/3
  Plug.Conn — all except send_file/3, send_file/4, send_file/5
  String — all except to_atom/1, to_existing_atom/1
  System — only convert_time_unit/3, endianness/0, monotonic_time/0, monotonic_time/1, os_time/0, os_time/1, otp_release/0, schedulers/0, schedulers_online/0, system_time/0, system_time/1, time_offset/0, time_offset/1, unique_integer/0, unique_integer/1, version/0
```

# `framework_modules`

```elixir
@spec framework_modules() :: [module()]
```

The Phoenix and Ecto modules granted one by one, as listed under
web and data.

# `grants`

```elixir
@spec grants() :: Beamlet.Policy.grants()
```

The default's grant table, with each package expanded into its
modules.

A package's modules marked `@moduledoc false` are left out.

# `not_granted`

```elixir
@spec not_granted() :: [{String.t(), [module()]}]
```

The modules left out on purpose, grouped by reason.

Nothing at runtime reads it. A module is denied by being absent
from the grants.

# `packages`

```elixir
@spec packages() :: [atom()]
```

The packages granted whole, by OTP application name.

---

*Consult [api-reference.md](api-reference.md) for complete listing*
