| | | 1 | | using Elsa.Common.Multitenancy; |
| | | 2 | | using Elsa.Common.Services; |
| | | 3 | | using Elsa.Identity.Contracts; |
| | | 4 | | using Elsa.Identity.Entities; |
| | | 5 | | using Elsa.Identity.Models; |
| | | 6 | | |
| | | 7 | | namespace Elsa.Identity.Services; |
| | | 8 | | |
| | | 9 | | /// <summary> |
| | | 10 | | /// Represents an in-memory role store. |
| | | 11 | | /// </summary> |
| | | 12 | | public class MemoryRoleStore : IRoleStore, IRoleStoreWithAtomicDelete |
| | | 13 | | { |
| | | 14 | | private readonly MemoryStore<Role> _store; |
| | | 15 | | private readonly ITenantAccessor _tenantAccessor; |
| | | 16 | | |
| | | 17 | | /// <summary> |
| | | 18 | | /// Initializes a new instance of the <see cref="MemoryRoleStore"/> class. |
| | | 19 | | /// </summary> |
| | 47 | 20 | | public MemoryRoleStore(MemoryStore<Role> store, ITenantAccessor tenantAccessor) |
| | | 21 | | { |
| | 47 | 22 | | _store = store; |
| | 47 | 23 | | _tenantAccessor = tenantAccessor; |
| | 47 | 24 | | } |
| | | 25 | | |
| | | 26 | | /// <inheritdoc /> |
| | | 27 | | public Task AddAsync(Role role, CancellationToken cancellationToken = default) |
| | | 28 | | { |
| | 38 | 29 | | lock (_store.Sync) |
| | | 30 | | { |
| | 77 | 31 | | MemoryIdentityUniqueness.EnsureAvailable(_store, role, x => x.Name, "name"); |
| | 74 | 32 | | _store.Add(role, x => x.Id); |
| | 5 | 33 | | } |
| | | 34 | | |
| | 5 | 35 | | return Task.CompletedTask; |
| | | 36 | | } |
| | | 37 | | |
| | | 38 | | /// <inheritdoc /> |
| | | 39 | | public Task DeleteAsync(RoleFilter filter, CancellationToken cancellationToken = default) |
| | | 40 | | { |
| | 2 | 41 | | lock (_store.Sync) |
| | | 42 | | { |
| | 4 | 43 | | var roles = _store.Query(query => Filter(query, filter)).ToList(); |
| | 4 | 44 | | _store.DeleteMany(roles, x => x.Id); |
| | 2 | 45 | | } |
| | | 46 | | |
| | 2 | 47 | | return Task.CompletedTask; |
| | | 48 | | } |
| | | 49 | | |
| | | 50 | | /// <inheritdoc /> |
| | | 51 | | /// <remarks> |
| | | 52 | | /// The matching role's key is removed through the underlying concurrent dictionary, whose removal is a single |
| | | 53 | | /// compare-and-remove step. Two callers racing on the same role ID therefore see one <see langword="true"/> and |
| | | 54 | | /// one <see langword="false"/>, rather than both concluding they deleted it. |
| | | 55 | | /// </remarks> |
| | | 56 | | public Task<bool> TryDeleteAsync(string roleId, CancellationToken cancellationToken = default) |
| | | 57 | | { |
| | 4 | 58 | | lock (_store.Sync) |
| | | 59 | | { |
| | 8 | 60 | | var role = _store.Query(query => Filter(query, new RoleFilter { Id = roleId })).FirstOrDefault(); |
| | 4 | 61 | | var deleted = role is not null && _store.Delete(role.Id); |
| | | 62 | | |
| | 4 | 63 | | return Task.FromResult(deleted); |
| | | 64 | | } |
| | 4 | 65 | | } |
| | | 66 | | |
| | | 67 | | /// <inheritdoc /> |
| | | 68 | | public Task SaveAsync(Role role, CancellationToken cancellationToken = default) |
| | | 69 | | { |
| | 47 | 70 | | Save(role); |
| | 40 | 71 | | return Task.CompletedTask; |
| | | 72 | | } |
| | | 73 | | |
| | | 74 | | private void Save(Role role) |
| | | 75 | | { |
| | 47 | 76 | | lock (_store.Sync) |
| | | 77 | | { |
| | 47 | 78 | | EnsureIdIsAvailable(role); |
| | 91 | 79 | | MemoryIdentityUniqueness.EnsureAvailable(_store, role, x => x.Name, "name"); |
| | 80 | 80 | | _store.Save(role, x => x.Id); |
| | 40 | 81 | | } |
| | 40 | 82 | | } |
| | | 83 | | |
| | | 84 | | private void EnsureIdIsAvailable(Role role) |
| | | 85 | | { |
| | 66 | 86 | | var existing = _store.Find(x => x.Id == role.Id); |
| | 47 | 87 | | if (existing is not null && !CanReplace(existing, role)) |
| | | 88 | | { |
| | 4 | 89 | | throw new InvalidOperationException( |
| | 4 | 90 | | $"A role already exists with ID '{role.Id}' in tenant '{existing.TenantId}'."); |
| | | 91 | | } |
| | 43 | 92 | | } |
| | | 93 | | |
| | | 94 | | /// <summary> |
| | | 95 | | /// A role may be replaced only when its existing row is visible to the ambient tenant and the incoming role |
| | | 96 | | /// retains that row's tenant marker. This matches the durable store's query-filtered ID lookup while preventing |
| | | 97 | | /// a caller from re-homing a globally keyed row by changing its <c>TenantId</c>. |
| | | 98 | | /// </summary> |
| | | 99 | | private bool CanReplace(Role existing, Role replacement) => |
| | 11 | 100 | | string.Equals(existing.TenantId, replacement.TenantId, StringComparison.Ordinal) && |
| | 11 | 101 | | TenantVisibility.IsVisible(existing.TenantId, _tenantAccessor.TenantId); |
| | | 102 | | |
| | | 103 | | /// <inheritdoc /> |
| | | 104 | | public Task<Role?> FindAsync(RoleFilter filter, CancellationToken cancellationToken = default) |
| | | 105 | | { |
| | 156 | 106 | | var result = _store.Query(query => Filter(query, filter)).Select(Clone).FirstOrDefault(); |
| | 78 | 107 | | return Task.FromResult(result); |
| | | 108 | | } |
| | | 109 | | |
| | | 110 | | /// <inheritdoc /> |
| | | 111 | | public Task<IEnumerable<Role>> FindManyAsync(RoleFilter filter, CancellationToken cancellationToken = default) |
| | | 112 | | { |
| | 22 | 113 | | var result = _store.Query(query => Filter(query, filter)).Select(Clone).ToList().AsEnumerable(); |
| | 11 | 114 | | return Task.FromResult(result); |
| | | 115 | | } |
| | | 116 | | |
| | | 117 | | /// <remarks> |
| | | 118 | | /// The ambient tenant is applied here rather than left to callers. Isolation previously existed only |
| | | 119 | | /// on the Entity Framework path, and only when multitenancy was enabled, so a deployment running the |
| | | 120 | | /// default in-memory stores had none at all. Null tenant IDs are retained only for the default tenant |
| | | 121 | | /// for backwards compatibility with records created before tenant assignment was added. |
| | | 122 | | /// </remarks> |
| | | 123 | | private IQueryable<Role> Filter(IQueryable<Role> queryable, RoleFilter filter) |
| | | 124 | | { |
| | 95 | 125 | | var tenantId = _tenantAccessor.TenantId; |
| | 95 | 126 | | queryable = queryable.Where(x => x.TenantId == tenantId || x.TenantId == Tenant.AgnosticTenantId || (x.TenantId |
| | | 127 | | |
| | 95 | 128 | | return filter.Apply(queryable); |
| | | 129 | | } |
| | | 130 | | |
| | | 131 | | private static Role Clone(Role role) => |
| | 75 | 132 | | new() |
| | 75 | 133 | | { |
| | 75 | 134 | | Id = role.Id, |
| | 75 | 135 | | Name = role.Name, |
| | 75 | 136 | | TenantId = role.TenantId, |
| | 75 | 137 | | Permissions = role.Permissions.ToList() |
| | 75 | 138 | | }; |
| | | 139 | | } |