| | | 1 | | using System.Text.Json; |
| | | 2 | | using System.Text.Json.Serialization; |
| | | 3 | | |
| | | 4 | | namespace Elsa.Connections.Models; |
| | | 5 | | |
| | | 6 | | public enum ConnectionCredentialKind |
| | | 7 | | { |
| | | 8 | | OAuth = 0, |
| | | 9 | | ApiKey = 1 |
| | | 10 | | } |
| | | 11 | | |
| | | 12 | | /// <summary>Token material is serialized into the encrypted Secrets value and must remain short-lived in memory.</summa |
| | | 13 | | public sealed class CredentialMaterial(string accessToken, string refreshToken, DateTimeOffset accessTokenExpiresAt) |
| | | 14 | | { |
| | | 15 | | [JsonIgnore] |
| | | 16 | | public string AccessToken { get; } = accessToken; |
| | | 17 | | |
| | | 18 | | [JsonIgnore] |
| | | 19 | | public string RefreshToken { get; } = refreshToken; |
| | | 20 | | |
| | | 21 | | [JsonIgnore] |
| | | 22 | | public DateTimeOffset AccessTokenExpiresAt { get; } = accessTokenExpiresAt; |
| | | 23 | | |
| | | 24 | | public override string ToString() => "CredentialMaterial { Redacted = true }"; |
| | | 25 | | } |
| | | 26 | | |
| | | 27 | | /// <summary>Credential handed to an authorized consumer. Refresh material remains inside lifecycle management.</summary |
| | | 28 | | [JsonConverter(typeof(ConnectionAccessCredentialJsonConverter))] |
| | | 29 | | public sealed class ConnectionAccessCredential |
| | | 30 | | { |
| | | 31 | | private readonly DateTimeOffset? _expiresAt; |
| | | 32 | | |
| | | 33 | | [JsonIgnore] |
| | 30 | 34 | | public string AccessToken { get; } |
| | | 35 | | |
| | | 36 | | [JsonIgnore] |
| | 4 | 37 | | public string? ApiKey { get; } |
| | | 38 | | |
| | 27 | 39 | | public ConnectionCredentialKind Kind { get; } |
| | | 40 | | |
| | | 41 | | /// <summary>Gets the OAuth expiry. API-key credentials are explicitly non-expiring and have no expiry value.</summa |
| | 10 | 42 | | public DateTimeOffset ExpiresAt => _expiresAt ?? throw new InvalidOperationException("API-key credentials do not hav |
| | | 43 | | |
| | | 44 | | public ConnectionAccessCredential(string accessToken, DateTimeOffset expiresAt) |
| | 12 | 45 | | : this(ConnectionCredentialKind.OAuth, accessToken, expiresAt) |
| | | 46 | | { |
| | 12 | 47 | | } |
| | | 48 | | |
| | 34 | 49 | | public ConnectionAccessCredential(ConnectionCredentialKind kind, string value, DateTimeOffset? expiresAt) |
| | | 50 | | { |
| | 34 | 51 | | if (string.IsNullOrWhiteSpace(value)) |
| | | 52 | | { |
| | 0 | 53 | | throw new ArgumentException("Credential value is required.", nameof(value)); |
| | | 54 | | } |
| | | 55 | | |
| | 34 | 56 | | if (kind == ConnectionCredentialKind.OAuth && !expiresAt.HasValue) |
| | | 57 | | { |
| | 0 | 58 | | throw new ArgumentException("OAuth credentials require an expiry.", nameof(expiresAt)); |
| | | 59 | | } |
| | | 60 | | |
| | 34 | 61 | | if (kind == ConnectionCredentialKind.ApiKey && expiresAt.HasValue) |
| | | 62 | | { |
| | 0 | 63 | | throw new ArgumentException("API-key credentials do not have an expiry.", nameof(expiresAt)); |
| | | 64 | | } |
| | | 65 | | |
| | 34 | 66 | | Kind = kind; |
| | 34 | 67 | | AccessToken = value; |
| | 34 | 68 | | ApiKey = kind == ConnectionCredentialKind.ApiKey ? value : null; |
| | 34 | 69 | | _expiresAt = expiresAt; |
| | 34 | 70 | | } |
| | | 71 | | |
| | 4 | 72 | | public override string ToString() => "ConnectionAccessCredential { Redacted = true }"; |
| | | 73 | | } |
| | | 74 | | |
| | | 75 | | internal sealed class ConnectionAccessCredentialJsonConverter : JsonConverter<ConnectionAccessCredential> |
| | | 76 | | { |
| | | 77 | | public override ConnectionAccessCredential Read(ref Utf8JsonReader reader, Type typeToConvert, JsonSerializerOptions |
| | | 78 | | throw new JsonException("Connection access credentials are write-only."); |
| | | 79 | | |
| | | 80 | | public override void Write(Utf8JsonWriter writer, ConnectionAccessCredential value, JsonSerializerOptions options) |
| | | 81 | | { |
| | | 82 | | writer.WriteStartObject(); |
| | | 83 | | writer.WriteNumber(GetName(nameof(ConnectionAccessCredential.Kind)), (int)value.Kind); |
| | | 84 | | |
| | | 85 | | if (value.Kind == ConnectionCredentialKind.OAuth) |
| | | 86 | | { |
| | | 87 | | writer.WriteString(GetName(nameof(ConnectionAccessCredential.ExpiresAt)), value.ExpiresAt); |
| | | 88 | | } |
| | | 89 | | |
| | | 90 | | writer.WriteEndObject(); |
| | | 91 | | |
| | | 92 | | string GetName(string name) => options.PropertyNamingPolicy?.ConvertName(name) ?? name; |
| | | 93 | | } |
| | | 94 | | } |