| | | 1 | | using Elsa.Connections.Models; |
| | | 2 | | |
| | | 3 | | namespace Elsa.Connections.Contracts; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Host-only persistence primitive for durable, revisioned logical workflow bindings. Do not expose it through |
| | | 7 | | /// HTTP; application services must authorize the exact tenant, environment, logical reference and target connection |
| | | 8 | | /// before creating or rebinding a mapping. |
| | | 9 | | /// </summary> |
| | | 10 | | /// <remarks> |
| | | 11 | | /// A binding selects a connection but does not grant use. A connection can disconnect after the store's active-state |
| | | 12 | | /// check and leave a stale mapping; every resolution must still pass through the lifecycle service, which checks the |
| | | 13 | | /// current connection status before returning a credential. |
| | | 14 | | /// </remarks> |
| | | 15 | | public interface IConnectionCredentialBindingStore |
| | | 16 | | { |
| | | 17 | | Task<ConnectionCredentialBinding?> FindAsync( |
| | | 18 | | string tenantId, |
| | | 19 | | string environmentId, |
| | | 20 | | string logicalBindingId, |
| | | 21 | | CancellationToken cancellationToken = default); |
| | | 22 | | |
| | | 23 | | Task<ConnectionCredentialBinding?> TryCreateAsync( |
| | | 24 | | string tenantId, |
| | | 25 | | string environmentId, |
| | | 26 | | string logicalBindingId, |
| | | 27 | | string connectionId, |
| | | 28 | | CancellationToken cancellationToken = default); |
| | | 29 | | |
| | | 30 | | Task<ConnectionCredentialBinding?> TryRebindAsync( |
| | | 31 | | string tenantId, |
| | | 32 | | string environmentId, |
| | | 33 | | string logicalBindingId, |
| | | 34 | | long expectedRevision, |
| | | 35 | | string connectionId, |
| | | 36 | | CancellationToken cancellationToken = default); |
| | | 37 | | } |
| | | 38 | | |
| | 32 | 39 | | public sealed record ConnectionCredentialBindingUseRequest( |
| | 37 | 40 | | string TenantId, |
| | 36 | 41 | | string EnvironmentId, |
| | 23 | 42 | | string LogicalBindingId, |
| | 29 | 43 | | string ConnectionId, |
| | 15 | 44 | | long BindingRevision, |
| | 58 | 45 | | string WorkflowInstanceId); |
| | | 46 | | |
| | | 47 | | /// <summary>Host authorization for a workflow's use of the binding snapshot resolved by the adapter.</summary> |
| | | 48 | | public interface IConnectionCredentialBindingUseAuthorizer |
| | | 49 | | { |
| | | 50 | | Task<bool> AuthorizeAsync(ConnectionCredentialBindingUseRequest request, CancellationToken cancellationToken = defau |
| | | 51 | | } |
| | | 52 | | |
| | | 53 | | public sealed record ConnectionCredentialBindingManagementRequest( |
| | | 54 | | string TenantId, |
| | | 55 | | string EnvironmentId, |
| | | 56 | | string LogicalBindingId, |
| | | 57 | | string ConnectionId, |
| | | 58 | | long? ExpectedRevision); |
| | | 59 | | |
| | | 60 | | /// <summary>Host authorization for a human creating or explicitly rebinding a logical connection mapping.</summary> |
| | | 61 | | public interface IConnectionCredentialBindingManagementAuthorizer |
| | | 62 | | { |
| | | 63 | | Task<bool> AuthorizeAsync( |
| | | 64 | | System.Security.Claims.ClaimsPrincipal principal, |
| | | 65 | | ConnectionCredentialBindingManagementRequest request, |
| | | 66 | | CancellationToken cancellationToken = default); |
| | | 67 | | } |