-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathMutationAuthorization.cs
More file actions
141 lines (134 loc) · 5.53 KB
/
Copy pathMutationAuthorization.cs
File metadata and controls
141 lines (134 loc) · 5.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
using System.Collections.Immutable;
using KeyLoad.Storage;
namespace KeyLoad.Core;
public sealed partial class DatabaseEngine
{
private const string MissingMutationSequenceMessage = "A mutation sequence is missing.";
private const string MissingMutationEntryMessage = "A mutation entry is missing.";
// An inbox retry checks current permissions without re-evaluating the old CAS or applying effects again.
private void ReauthorizeEffects(IKeyValueView view, PrincipalRecord principal, PartitionRef partition, ImmutableArray<Mutation> effects)
{
if (effects.IsDefault)
{
throw Errors.Fail(ErrorCode.Validation, MissingMutationSequenceMessage);
}
foreach (var effect in effects)
{
if (effect is null)
{
throw Errors.Fail(ErrorCode.Validation, MissingMutationEntryMessage);
}
ReauthorizeEffect(view, principal, partition, effect);
}
}
private void ReauthorizeEffect(IKeyValueView view, PrincipalRecord principal, PartitionRef partition, Mutation effect)
{
if (effect is ConfigureRecurringSchedule or EmitRecurringOccurrences or CancelRecurringSchedule or CompareExchangeSaga or ExpireSaga)
{
ReauthorizeRecurringSagaEffect(view, principal, partition, effect);
return;
}
if (effect is ApplyVectorProjection projection)
{
ReauthorizeVectorProjection(view, principal, partition, projection);
return;
}
if (effect is CreateQueueTransfer or AcceptQueueTransfer or CompleteQueueTransfer)
{
ReauthorizeQueueTransfer(view, principal, partition, effect);
return;
}
if (effect is ApplyCrossPartitionReverseEdge or CompleteCrossPartitionReverseEdge)
{
ReauthorizeGraphDelivery(view, principal, partition, effect);
return;
}
AuthorizeComposition(view, principal, partition, effect);
var resource = Resource(view, partition, effect.Resource);
var documentId = effect switch
{
PutDocument put => put.Id,
PatchDocument patch => patch.Id,
DeleteDocument delete => delete.Id,
PutVector vector => vector.Id,
_ => null
};
var document = documentId is null ? null : view.GetRecord<DocumentRecord>(DocumentKey(partition, effect.Resource, documentId));
if (document is not null)
{
Authorization.RequireWriteRow(principal, document.Access);
}
if (effect is PutDocument replacement)
{
Authorization.RequireWriteRow(principal, replacement.Access ?? document?.Access ?? new RowAccess());
if (document is { Deleted: false })
{
Authorization.RequireReplacement(principal, resource, replacement.ExplicitReplacement);
}
}
ReauthorizeEffectFields(principal, resource, effect);
ReauthorizeEffectHeaders(principal, resource, effect);
ReauthorizeEffectIndexes(principal, resource, effect);
ReauthorizeEffectVertices(view, principal, partition, effect);
}
private void ReauthorizeEffectFields(PrincipalRecord principal, ResourceDefinition resource, Mutation effect)
{
if (effect is PatchDocument patchFields)
{
foreach (var field in patchFields.Patches)
{
Authorization.RequireFieldWrite(principal, resource, field.Path);
}
return;
}
if (effect is PutVector vectorField)
{
Authorization.RequireFieldUse(principal, resource, vectorField.Field);
Authorization.RequireFieldWrite(principal, resource, vectorField.Field);
return;
}
if (effect is PutDocument or AppendEvents or PublishTopic or EnqueueMessage or UpsertEdge or AppendSamples)
{
foreach (var policy in resource.FieldPolicies)
{
Authorization.RequireFieldWrite(principal, resource, policy.Path);
}
}
}
private void ReauthorizeEffectHeaders(PrincipalRecord principal, ResourceDefinition resource, Mutation effect)
{
if (effect is AppendEvents or PublishTopic or EnqueueMessage)
{
foreach (var policy in resource.HeaderPolicies)
{
Authorization.RequireFieldWrite(principal, resource with { FieldPolicies = resource.HeaderPolicies }, policy.Path);
}
}
}
private void ReauthorizeEffectIndexes(PrincipalRecord principal, ResourceDefinition resource, Mutation effect)
{
if (effect is PutDocument or PatchDocument or DeleteDocument)
{
foreach (var index in resource.Indexes)
{
foreach (var field in index.Fields)
{
Authorization.RequireFieldUse(principal, resource, field);
}
}
}
}
private void ReauthorizeEffectVertices(IKeyValueView view, PrincipalRecord principal, PartitionRef partition, Mutation effect)
{
if (effect is UpsertEdge upsert)
{
VisibleVertex(view, principal, upsert.From);
VisibleVertex(view, principal, upsert.To);
}
if (effect is DeleteEdge remove && view.GetRecord<EdgeRecord>(EdgeKey(partition, remove.Graph, remove.EdgeId)) is { } edge)
{
VisibleVertex(view, principal, edge.From);
VisibleVertex(view, principal, edge.To);
}
}
}