refactor(authz): permet require_permission() as has_permission(), more explicit
This commit is contained in:
@@ -257,7 +257,7 @@ pub trait FileRetrievalUseCase: Send + Sync + 'static {
|
|||||||
|
|
||||||
/// Primary port for file management operations
|
/// Primary port for file management operations
|
||||||
pub trait FileManagementUseCase: Send + Sync + 'static {
|
pub trait FileManagementUseCase: Send + Sync + 'static {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
caller_id: Uuid,
|
caller_id: Uuid,
|
||||||
permission: Permission,
|
permission: Permission,
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ use crate::common::errors::DomainError;
|
|||||||
use crate::domain::services::authorization::Permission;
|
use crate::domain::services::authorization::Permission;
|
||||||
|
|
||||||
pub trait FolderUseCase: Send + Sync + 'static {
|
pub trait FolderUseCase: Send + Sync + 'static {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
caller_id: Uuid,
|
caller_id: Uuid,
|
||||||
permission: Permission,
|
permission: Permission,
|
||||||
|
|||||||
@@ -225,7 +225,7 @@ impl FileManagementService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
impl FileManagementUseCase for FileManagementService {
|
impl FileManagementUseCase for FileManagementService {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
caller_id: Uuid,
|
caller_id: Uuid,
|
||||||
permission: Permission,
|
permission: Permission,
|
||||||
|
|||||||
@@ -41,7 +41,7 @@ impl FolderService {
|
|||||||
struct FolderServiceStub;
|
struct FolderServiceStub;
|
||||||
|
|
||||||
impl FolderUseCase for FolderServiceStub {
|
impl FolderUseCase for FolderServiceStub {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
_caller_id: Uuid,
|
_caller_id: Uuid,
|
||||||
_permission: Permission,
|
_permission: Permission,
|
||||||
@@ -175,7 +175,7 @@ impl FolderUseCase for FolderService {
|
|||||||
/// large request bodies (file upload, chunked upload). The authoritative
|
/// large request bodies (file upload, chunked upload). The authoritative
|
||||||
/// check happens again inside the upload/management services before any
|
/// check happens again inside the upload/management services before any
|
||||||
/// DB write — this is a UX/resource optimization, not a security boundary.
|
/// DB write — this is a UX/resource optimization, not a security boundary.
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
caller_id: Uuid,
|
caller_id: Uuid,
|
||||||
permission: Permission,
|
permission: Permission,
|
||||||
|
|||||||
+2
-2
@@ -356,7 +356,7 @@ impl I18nService for StubI18nService {
|
|||||||
pub struct StubFolderUseCase;
|
pub struct StubFolderUseCase;
|
||||||
|
|
||||||
impl FolderUseCase for StubFolderUseCase {
|
impl FolderUseCase for StubFolderUseCase {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
_caller_id: Uuid,
|
_caller_id: Uuid,
|
||||||
_permission: Permission,
|
_permission: Permission,
|
||||||
@@ -637,7 +637,7 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
|
|||||||
pub struct StubFileManagementUseCase;
|
pub struct StubFileManagementUseCase;
|
||||||
|
|
||||||
impl FileManagementUseCase for StubFileManagementUseCase {
|
impl FileManagementUseCase for StubFileManagementUseCase {
|
||||||
async fn has_permission(
|
async fn require_permission(
|
||||||
&self,
|
&self,
|
||||||
_caller_id: Uuid,
|
_caller_id: Uuid,
|
||||||
_permission: Permission,
|
_permission: Permission,
|
||||||
|
|||||||
@@ -129,7 +129,7 @@ impl ChunkedUploadHandler {
|
|||||||
&& let Err(err) = state
|
&& let Err(err) = state
|
||||||
.applications
|
.applications
|
||||||
.folder_service_concrete
|
.folder_service_concrete
|
||||||
.has_permission(auth_user.id, Permission::Create, fid)
|
.require_permission(auth_user.id, Permission::Create, fid)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
|
|||||||
@@ -124,7 +124,7 @@ impl FileHandler {
|
|||||||
&& let Err(err) = state
|
&& let Err(err) = state
|
||||||
.applications
|
.applications
|
||||||
.folder_service_concrete
|
.folder_service_concrete
|
||||||
.has_permission(auth_user.id, Permission::Create, fid)
|
.require_permission(auth_user.id, Permission::Create, fid)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
@@ -333,7 +333,7 @@ impl FileHandler {
|
|||||||
if let Err(err) = state
|
if let Err(err) = state
|
||||||
.applications
|
.applications
|
||||||
.file_management_service
|
.file_management_service
|
||||||
.has_permission(auth_user.id, Permission::Read, &id)
|
.require_permission(auth_user.id, Permission::Read, &id)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
return AppError::from(err).into_response();
|
return AppError::from(err).into_response();
|
||||||
@@ -493,7 +493,7 @@ impl FileHandler {
|
|||||||
if let Err(err) = state
|
if let Err(err) = state
|
||||||
.applications
|
.applications
|
||||||
.file_management_service
|
.file_management_service
|
||||||
.has_permission(auth_user.id, Permission::Update, &id)
|
.require_permission(auth_user.id, Permission::Update, &id)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
return AppError::from(err).into_response();
|
return AppError::from(err).into_response();
|
||||||
@@ -855,7 +855,7 @@ impl FileHandler {
|
|||||||
if let Err(err) = state
|
if let Err(err) = state
|
||||||
.applications
|
.applications
|
||||||
.file_management_service
|
.file_management_service
|
||||||
.has_permission(auth_user.id, Permission::Read, &file_id)
|
.require_permission(auth_user.id, Permission::Read, &file_id)
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
return AppError::from(err).into_response();
|
return AppError::from(err).into_response();
|
||||||
|
|||||||
@@ -320,7 +320,7 @@ jsonpath "$" count == 0
|
|||||||
# · GET /{id}/metadata · GET /{id}/thumbnail/{size}
|
# · GET /{id}/metadata · GET /{id}/thumbnail/{size}
|
||||||
# · PUT /{id}/thumbnail/{size} (push, Update)
|
# · PUT /{id}/thumbnail/{size} (push, Update)
|
||||||
# · PUT /{id}/rename · PUT /{id}/move · DELETE /{id}
|
# · PUT /{id}/rename · PUT /{id}/move · DELETE /{id}
|
||||||
# · POST /upload (via folder has_permission)
|
# · POST /upload (via folder require_permission)
|
||||||
#
|
#
|
||||||
# Listing endpoints that are still owner-scoped (GET /api/folders root,
|
# Listing endpoints that are still owner-scoped (GET /api/folders root,
|
||||||
# GET /api/folders/paginated) are NOT covered here — they don't
|
# GET /api/folders/paginated) are NOT covered here — they don't
|
||||||
@@ -476,7 +476,7 @@ Authorization: Bearer {{adam_token}}
|
|||||||
HTTP 404
|
HTTP 404
|
||||||
|
|
||||||
# ── Chunked upload: cannot start session in alice's folder ──
|
# ── Chunked upload: cannot start session in alice's folder ──
|
||||||
# create_upload_impl pre-checks Permission::Create via has_permission.
|
# create_upload_impl pre-checks Permission::Create via require_permission.
|
||||||
POST {{base_url}}/api/uploads
|
POST {{base_url}}/api/uploads
|
||||||
Authorization: Bearer {{adam_token}}
|
Authorization: Bearer {{adam_token}}
|
||||||
Content-Type: application/json
|
Content-Type: application/json
|
||||||
|
|||||||
Reference in New Issue
Block a user