| | | 1 | | using Elsa.Common.Multitenancy; |
| | | 2 | | using Elsa.Secrets.Contracts; |
| | | 3 | | using Elsa.Secrets.Services; |
| | | 4 | | using Elsa.Tenants.Options; |
| | | 5 | | using Microsoft.Extensions.Options; |
| | | 6 | | |
| | | 7 | | namespace Elsa.Secrets.Repositories; |
| | | 8 | | |
| | | 9 | | /// <summary> |
| | | 10 | | /// An in-memory secret repository that mirrors the EF Core tenant contract. |
| | | 11 | | /// </summary> |
| | | 12 | | /// <remarks> |
| | | 13 | | /// Secrets are keyed by their stable ID so two tenants can own the same case-insensitive name. Name |
| | | 14 | | /// uniqueness and updates are resolved under the ambient tenant, while reads are filtered through |
| | | 15 | | /// <see cref="TenantVisibility"/>. This is deliberately the same shape as the persisted contract rather |
| | | 16 | | /// than a test-only global name dictionary. |
| | | 17 | | /// </remarks> |
| | | 18 | | public class InMemorySecretRepository : ISecretRepository |
| | | 19 | | { |
| | | 20 | | private readonly ITenantAccessor? tenantAccessor; |
| | | 21 | | private readonly bool tenancyEnabled; |
| | | 22 | | private readonly ISecretNameValidator nameValidator; |
| | | 23 | | |
| | | 24 | | public InMemorySecretRepository(ITenantAccessor? tenantAccessor = null) |
| | 67 | 25 | | : this(tenantAccessor, tenantAccessor is not null, new DefaultSecretNameValidator()) |
| | | 26 | | { |
| | 67 | 27 | | } |
| | | 28 | | |
| | | 29 | | // Keep the pre-tenancy parameterless constructor in the public binary surface. Optional parameters do |
| | | 30 | | // not emit a zero-argument constructor for existing binaries to bind to. |
| | 54 | 31 | | public InMemorySecretRepository() : this(null) |
| | | 32 | | { |
| | 54 | 33 | | } |
| | | 34 | | |
| | | 35 | | public InMemorySecretRepository( |
| | | 36 | | IOptions<TenantsOptions> tenantsOptions, |
| | | 37 | | ISecretNameValidator nameValidator, |
| | | 38 | | ITenantAccessor? tenantAccessor = null) |
| | 3 | 39 | | : this(tenantAccessor, tenantsOptions.Value.IsEnabled, nameValidator) |
| | | 40 | | { |
| | 3 | 41 | | } |
| | | 42 | | |
| | 70 | 43 | | private InMemorySecretRepository(ITenantAccessor? tenantAccessor, bool tenancyEnabled, ISecretNameValidator nameVali |
| | | 44 | | { |
| | 70 | 45 | | this.tenantAccessor = tenantAccessor; |
| | 70 | 46 | | this.tenancyEnabled = tenancyEnabled; |
| | 70 | 47 | | this.nameValidator = nameValidator; |
| | 70 | 48 | | } |
| | | 49 | | |
| | 70 | 50 | | private readonly Dictionary<string, Secret> _secrets = new(StringComparer.Ordinal); |
| | 70 | 51 | | private readonly object _sync = new(); |
| | | 52 | | |
| | | 53 | | public Task<Secret?> GetAsync(string normalizedName, CancellationToken cancellationToken = default) |
| | | 54 | | { |
| | 94 | 55 | | lock (_sync) |
| | | 56 | | { |
| | 94 | 57 | | var secret = FindVisible(normalizedName); |
| | 94 | 58 | | return Task.FromResult(secret is null ? null : Clone(secret)); |
| | | 59 | | } |
| | 94 | 60 | | } |
| | | 61 | | |
| | | 62 | | public Task<IReadOnlyCollection<Secret>> ListAsync(CancellationToken cancellationToken = default) |
| | | 63 | | { |
| | 11 | 64 | | lock (_sync) |
| | | 65 | | { |
| | 11 | 66 | | var secrets = _secrets.Values |
| | 27 | 67 | | .Where(x => SecretRepositoryTenant.IsVisible(x, tenantAccessor, tenancyEnabled)) |
| | 11 | 68 | | .Select(Clone) |
| | 11 | 69 | | .ToList(); |
| | 11 | 70 | | return Task.FromResult<IReadOnlyCollection<Secret>>(secrets); |
| | | 71 | | } |
| | 11 | 72 | | } |
| | | 73 | | |
| | | 74 | | public Task AddAsync(Secret secret, CancellationToken cancellationToken = default) |
| | | 75 | | { |
| | 41 | 76 | | SecretRepositoryTenant.Stamp(secret, tenantAccessor, tenancyEnabled); |
| | | 77 | | |
| | 41 | 78 | | lock (_sync) |
| | | 79 | | { |
| | 41 | 80 | | if (FindVisible(secret.Name) is not null) |
| | 6 | 81 | | throw new InvalidOperationException($"A secret named '{secret.Name}' already exists."); |
| | | 82 | | |
| | 48 | 83 | | if (_secrets.Values.Any(x => SecretRepositoryTenant.HasSameTenantName(x, secret, nameValidator, tenancyEnabl |
| | 2 | 84 | | throw new InvalidOperationException($"A secret named '{secret.Name}' already exists."); |
| | | 85 | | |
| | 33 | 86 | | EnsureIdAvailable(secret); |
| | 33 | 87 | | _secrets.Add(secret.Id, Clone(secret)); |
| | 33 | 88 | | } |
| | | 89 | | |
| | 33 | 90 | | return Task.CompletedTask; |
| | | 91 | | } |
| | | 92 | | |
| | | 93 | | public Task<bool> TryAddOrReplaceDeletedAsync(Secret secret, CancellationToken cancellationToken = default) |
| | | 94 | | { |
| | 46 | 95 | | SecretRepositoryTenant.Stamp(secret, tenantAccessor, tenancyEnabled); |
| | | 96 | | |
| | 46 | 97 | | lock (_sync) |
| | | 98 | | { |
| | 46 | 99 | | var existing = FindVisible(secret.Name); |
| | 46 | 100 | | if (existing is not null) |
| | | 101 | | { |
| | 11 | 102 | | if (existing.IsLifecycleManaged || existing.Status != SecretStatus.Deleted || !SecretRepositoryTenant.Ca |
| | | 103 | | { |
| | 5 | 104 | | return Task.FromResult(false); |
| | | 105 | | } |
| | | 106 | | |
| | 6 | 107 | | var replacement = Clone(secret); |
| | 6 | 108 | | if (tenancyEnabled) |
| | 2 | 109 | | replacement.TenantId = existing.TenantId; |
| | | 110 | | |
| | | 111 | | // Validate before removing the deleted row. Reusing its own ID is valid; another row's ID |
| | | 112 | | // is a collision and must leave the deleted row untouched when validation fails. |
| | 6 | 113 | | if (replacement.Id != existing.Id && _secrets.ContainsKey(replacement.Id)) |
| | 1 | 114 | | return Task.FromResult(false); |
| | | 115 | | |
| | 5 | 116 | | _secrets.Remove(existing.Id); |
| | 5 | 117 | | _secrets.Add(replacement.Id, replacement); |
| | 5 | 118 | | return Task.FromResult(true); |
| | | 119 | | } |
| | | 120 | | |
| | 50 | 121 | | if (_secrets.Values.Any(x => SecretRepositoryTenant.HasSameTenantName(x, secret, nameValidator, tenancyEnabl |
| | 2 | 122 | | return Task.FromResult(false); |
| | | 123 | | |
| | | 124 | | // Insert-side ID collisions must have the same non-mutating Try contract as the file repository. |
| | 33 | 125 | | if (_secrets.ContainsKey(secret.Id)) |
| | 1 | 126 | | return Task.FromResult(false); |
| | | 127 | | |
| | 32 | 128 | | _secrets.Add(secret.Id, Clone(secret)); |
| | 32 | 129 | | return Task.FromResult(true); |
| | | 130 | | } |
| | 46 | 131 | | } |
| | | 132 | | |
| | | 133 | | public Task SaveAsync(Secret secret, CancellationToken cancellationToken = default) |
| | | 134 | | { |
| | 23 | 135 | | SecretRepositoryTenant.Stamp(secret, tenantAccessor, tenancyEnabled); |
| | | 136 | | |
| | 23 | 137 | | lock (_sync) |
| | | 138 | | { |
| | 23 | 139 | | var existing = FindVisible(secret.Name); |
| | 23 | 140 | | if (existing is not null) |
| | | 141 | | { |
| | 18 | 142 | | if (!SecretRepositoryTenant.CanReplace(existing, secret, tenantAccessor, tenancyEnabled)) |
| | 1 | 143 | | throw new InvalidOperationException($"A secret named '{secret.Name}' belongs to another tenant."); |
| | | 144 | | |
| | | 145 | | // EF updates the row found by name, retaining its primary key and tenant ownership. |
| | 17 | 146 | | var replacement = Clone(secret); |
| | 17 | 147 | | replacement.Id = existing.Id; |
| | 17 | 148 | | replacement.ManagedOwnerId = existing.ManagedOwnerId; |
| | 17 | 149 | | replacement.ManagedGenerationId = existing.ManagedGenerationId; |
| | | 150 | | |
| | 17 | 151 | | if (tenancyEnabled) |
| | 2 | 152 | | replacement.TenantId = existing.TenantId; |
| | | 153 | | |
| | 17 | 154 | | _secrets[existing.Id] = replacement; |
| | 17 | 155 | | return Task.CompletedTask; |
| | | 156 | | } |
| | | 157 | | |
| | 8 | 158 | | if (_secrets.Values.Any(x => SecretRepositoryTenant.HasSameTenantName(x, secret, nameValidator, tenancyEnabl |
| | 2 | 159 | | throw new InvalidOperationException($"A secret named '{secret.Name}' already exists."); |
| | | 160 | | |
| | 3 | 161 | | EnsureIdAvailable(secret); |
| | 3 | 162 | | _secrets.Add(secret.Id, Clone(secret)); |
| | 3 | 163 | | } |
| | | 164 | | |
| | 3 | 165 | | return Task.CompletedTask; |
| | 17 | 166 | | } |
| | | 167 | | |
| | | 168 | | private Secret? FindVisible(string name) => |
| | 374 | 169 | | _secrets.Values.FirstOrDefault(x => SecretRepositoryTenant.IsVisible(x, tenantAccessor, tenancyEnabled) && Secre |
| | | 170 | | |
| | | 171 | | private void EnsureIdAvailable(Secret secret) |
| | | 172 | | { |
| | 36 | 173 | | if (_secrets.ContainsKey(secret.Id)) |
| | 0 | 174 | | throw new InvalidOperationException($"A secret with ID '{secret.Id}' already exists."); |
| | 36 | 175 | | } |
| | | 176 | | |
| | | 177 | | private static Secret Clone(Secret secret) |
| | | 178 | | { |
| | 195 | 179 | | return new Secret |
| | 195 | 180 | | { |
| | 195 | 181 | | Id = secret.Id, |
| | 195 | 182 | | TenantId = secret.TenantId, |
| | 195 | 183 | | Name = secret.Name, |
| | 195 | 184 | | DisplayName = secret.DisplayName, |
| | 195 | 185 | | Description = secret.Description, |
| | 195 | 186 | | TypeName = secret.TypeName, |
| | 195 | 187 | | StoreName = secret.StoreName, |
| | 195 | 188 | | Scope = secret.Scope, |
| | 195 | 189 | | ManagedOwnerId = secret.ManagedOwnerId, |
| | 195 | 190 | | ManagedGenerationId = secret.ManagedGenerationId, |
| | 195 | 191 | | Tags = secret.Tags.ToHashSet(StringComparer.OrdinalIgnoreCase), |
| | 195 | 192 | | Status = secret.Status, |
| | 195 | 193 | | CreatedAt = secret.CreatedAt, |
| | 195 | 194 | | UpdatedAt = secret.UpdatedAt, |
| | 195 | 195 | | Versions = secret.Versions.Select(Clone).ToList() |
| | 195 | 196 | | }; |
| | | 197 | | } |
| | | 198 | | |
| | | 199 | | private static SecretVersion Clone(SecretVersion version) |
| | | 200 | | { |
| | 127 | 201 | | return new SecretVersion |
| | 127 | 202 | | { |
| | 127 | 203 | | Version = version.Version, |
| | 127 | 204 | | Status = version.Status, |
| | 127 | 205 | | CreatedAt = version.CreatedAt, |
| | 127 | 206 | | ExpiresAt = version.ExpiresAt, |
| | 127 | 207 | | Payload = new SecretPayload |
| | 127 | 208 | | { |
| | 127 | 209 | | Value = version.Payload.Value, |
| | 127 | 210 | | Metadata = new Dictionary<string, string>(version.Payload.Metadata, StringComparer.OrdinalIgnoreCase) |
| | 127 | 211 | | } |
| | 127 | 212 | | }; |
| | | 213 | | } |
| | | 214 | | } |