| | | 1 | | using System.Security.Claims; |
| | | 2 | | using Elsa.Connections.Models; |
| | | 3 | | |
| | | 4 | | namespace Elsa.Connections.Contracts; |
| | | 5 | | |
| | | 6 | | /// <summary>Host-only durable grant storage. A grant never carries credential material.</summary> |
| | | 7 | | public interface IConnectionCredentialUseGrantStore |
| | | 8 | | { |
| | | 9 | | Task<ConnectionCredentialUseGrant?> FindAsync( |
| | | 10 | | string tenantId, string environmentId, string workflowInstanceId, string logicalBindingId, |
| | | 11 | | CancellationToken cancellationToken = default); |
| | | 12 | | |
| | | 13 | | Task<ConnectionCredentialUseGrant?> TryIssueAsync( |
| | | 14 | | string tenantId, string environmentId, string workflowInstanceId, string logicalBindingId, |
| | | 15 | | string connectionId, long bindingRevision, string actorId, DateTimeOffset issuedAt, |
| | | 16 | | CancellationToken cancellationToken = default); |
| | | 17 | | |
| | | 18 | | Task<bool> TryWithdrawAsync( |
| | | 19 | | string tenantId, string environmentId, string workflowInstanceId, string logicalBindingId, |
| | | 20 | | long expectedRevision, DateTimeOffset withdrawnAt, |
| | | 21 | | CancellationToken cancellationToken = default); |
| | | 22 | | } |
| | | 23 | | |
| | | 24 | | public enum ConnectionCredentialGrantAction |
| | | 25 | | { |
| | | 26 | | Issue, |
| | | 27 | | Withdraw |
| | | 28 | | } |
| | | 29 | | |
| | 28 | 30 | | public sealed record ConnectionCredentialGrantManagementRequest( |
| | 26 | 31 | | string TenantId, |
| | 26 | 32 | | string EnvironmentId, |
| | 0 | 33 | | string WorkflowInstanceId, |
| | 0 | 34 | | string LogicalBindingId, |
| | 0 | 35 | | string ConnectionId, |
| | 0 | 36 | | long BindingRevision, |
| | 31 | 37 | | ConnectionCredentialGrantAction Action); |
| | | 38 | | |
| | | 39 | | /// <summary>Host policy for issuing or withdrawing workflow-use grants; connection management does not imply this permi |
| | | 40 | | public interface IConnectionCredentialGrantManagementAuthorizer |
| | | 41 | | { |
| | | 42 | | Task<bool> AuthorizeAsync( |
| | | 43 | | ClaimsPrincipal principal, |
| | | 44 | | ConnectionCredentialGrantManagementRequest request, |
| | | 45 | | CancellationToken cancellationToken = default); |
| | | 46 | | } |