Skip to main content

backbone_bucket/presentation/http/
file_share_handler.rs

1//! FileShare REST handlers
2//!
3//! Generated by metaphor-schema. Do not edit manually.
4//!
5//! Uses Axum and backbone-core's BackboneCrudHandler for all 12 CRUD endpoints.
6
7use std::collections::HashMap;
8use std::sync::Arc;
9
10use axum::Router;
11use serde::{Deserialize, Serialize};
12use uuid::Uuid;
13use chrono::{DateTime, Utc};
14
15// Backbone framework imports
16use backbone_core::http::{ApiResponse, BackboneCrudHandler};
17
18// Auth integration (optional)
19#[cfg(feature = "auth")]
20use backbone_auth::middleware::AuthContext;
21#[cfg(feature = "auth")]
22use backbone_auth::AuthMiddleware;
23
24// Domain imports
25use crate::domain::entity::*;
26use crate::application::service::{FileShareService, ServiceError};
27
28// DTO imports
29use crate::presentation::dto::{CreateFileShareDto, UpdateFileShareDto, PatchFileShareDto, FileShareResponseDto};
30
31use crate::domain::state_machine::{FileShareState, FileShareStateMachine, FileShareTransition};
32
33/// Application error type
34#[derive(Debug, thiserror::Error)]
35pub enum FileShareError {
36    #[error("Not found: {0}")]
37    NotFound(String),
38    #[error("Validation error: {0}")]
39    Validation(String),
40    #[error("Database error: {0}")]
41    Database(String),
42    #[error("Internal error: {0}")]
43    Internal(String),
44    // Domain-specific errors from hook rules
45    #[error("Share token must be 32-64 characters: {0}")]
46    InvalidTokenLength(String),
47    #[error("Share token must be alphanumeric: {0}")]
48    InvalidTokenChars(String),
49    #[error("Cannot share inactive or quarantined files: {0}")]
50    FileNotActive(String),
51    #[error("Only file owner can create shares: {0}")]
52    NotFileOwner(String),
53    #[error("Expiration date must be in the future: {0}")]
54    ExpiredDate(String),
55    #[error("Maximum downloads must be positive: {0}")]
56    InvalidMaxDownloads(String),
57    #[error("User shares must specify recipients: {0}")]
58    MissingRecipients(String),
59    #[error("Cannot modify inactive shares: {0}")]
60    ShareInactive(String),
61}
62
63impl From<ServiceError> for FileShareError {
64    fn from(err: ServiceError) -> Self {
65        match err {
66            ServiceError::NotFound => Self::NotFound(err.to_string()),
67            ServiceError::Validation(ref msg) => Self::Validation(msg.clone()),
68            ServiceError::AlreadyExists(ref msg) => Self::Validation(msg.clone()),
69            ServiceError::Repository(ref e) => Self::Database(e.to_string()),
70            ServiceError::Internal(ref msg) => Self::Internal(msg.clone()),
71            ServiceError::Violations(_) => Self::Validation(err.to_string()),
72        }
73    }
74}
75
76impl axum::response::IntoResponse for FileShareError {
77    fn into_response(self) -> axum::response::Response {
78        use axum::http::StatusCode;
79        use axum::Json;
80
81        let (status, code) = match &self {
82            Self::NotFound(_) => (StatusCode::NOT_FOUND, "FILESHARE_NOT_FOUND"),
83            Self::Validation(_) => (StatusCode::BAD_REQUEST, "FILESHARE_VALIDATION_ERROR"),
84            Self::Database(_) => (StatusCode::INTERNAL_SERVER_ERROR, "FILESHARE_DATABASE_ERROR"),
85            Self::Internal(_) => (StatusCode::INTERNAL_SERVER_ERROR, "FILESHARE_INTERNAL_ERROR"),
86            Self::InvalidTokenLength(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_INVALID_TOKEN_LENGTH"),
87            Self::InvalidTokenChars(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_INVALID_TOKEN_CHARS"),
88            Self::FileNotActive(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_FILE_NOT_ACTIVE"),
89            Self::NotFileOwner(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_NOT_FILE_OWNER"),
90            Self::ExpiredDate(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_EXPIRED_DATE"),
91            Self::InvalidMaxDownloads(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_INVALID_MAX_DOWNLOADS"),
92            Self::MissingRecipients(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_MISSING_RECIPIENTS"),
93            Self::ShareInactive(_) => (StatusCode::UNPROCESSABLE_ENTITY, "FILESHARE_SHARE_INACTIVE"),
94        };
95
96        let body = serde_json::json!({
97            "success": false,
98            "error": code,
99            "message": self.to_string(),
100        });
101
102        (status, Json(body)).into_response()
103    }
104}
105
106/// Domain-specific error codes for FileShare
107pub mod file_share_errors {
108    pub const INVALID_TOKEN_LENGTH: &str = "FILESHARE_INVALID_TOKEN_LENGTH";
109    pub const INVALID_TOKEN_CHARS: &str = "FILESHARE_INVALID_TOKEN_CHARS";
110    pub const FILE_NOT_ACTIVE: &str = "FILESHARE_FILE_NOT_ACTIVE";
111    pub const NOT_FILE_OWNER: &str = "FILESHARE_NOT_FILE_OWNER";
112    pub const EXPIRED_DATE: &str = "FILESHARE_EXPIRED_DATE";
113    pub const INVALID_MAX_DOWNLOADS: &str = "FILESHARE_INVALID_MAX_DOWNLOADS";
114    pub const MISSING_RECIPIENTS: &str = "FILESHARE_MISSING_RECIPIENTS";
115    pub const SHARE_INACTIVE: &str = "FILESHARE_SHARE_INACTIVE";
116}
117
118// =============================================================================
119// Route Configuration
120// =============================================================================
121
122/// Create Axum router with all 16 Backbone endpoints for FileShare.
123///
124/// # Routes
125///
126/// | Method | Path | Description |
127/// |--------|------|-------------|
128/// | GET | /file_shares | List with pagination |
129/// | POST | /file_shares | Create new |
130/// | GET | /file_shares/:id | Get by ID |
131/// | PUT | /file_shares/:id | Full update |
132/// | PATCH | /file_shares/:id | Partial update |
133/// | DELETE | /file_shares/:id | Soft delete |
134/// | POST | /file_shares/bulk | Bulk create |
135/// | POST | /file_shares/upsert | Upsert |
136/// | GET | /file_shares/trash | List deleted |
137/// | POST | /file_shares/:id/restore | Restore |
138/// | DELETE | /file_shares/empty | Empty trash |
139/// | GET | /file_shares/:id/deleted | Get deleted by ID |
140/// | DELETE | /file_shares/trash/:id | Permanent delete from trash |
141/// | GET | /file_shares/count | Count active entities |
142/// | GET | /file_shares/trash/count | Count deleted entities |
143///
144/// # Example
145///
146/// ```text
147/// let service = Arc::new(FileShareService::with_repository(repository));
148/// let router = create_file_share_routes(service);
149/// ```
150pub fn create_file_share_routes(service: Arc<FileShareService>) -> Router {
151    BackboneCrudHandler::<FileShareService, FileShare, CreateFileShareDto, UpdateFileShareDto, FileShareResponseDto>::routes(
152        service,
153        "/file_shares",
154    )
155}
156
157/// Create Axum router with only the read (GET) endpoints for FileShare.
158///
159/// Safe for public, unauthenticated exposure (e.g., reference data).
160/// Mutations must be served separately via `create_file_share_write_routes`,
161/// typically wrapped in an auth middleware layer.
162pub fn create_file_share_read_routes(service: Arc<FileShareService>) -> Router {
163    BackboneCrudHandler::<FileShareService, FileShare, CreateFileShareDto, UpdateFileShareDto, FileShareResponseDto>::read_routes(
164        service,
165        "/file_shares",
166    )
167}
168
169/// Create Axum router with only the write (mutation) endpoints for FileShare.
170///
171/// These routes must NOT be publicly exposed. Wrap them with an auth
172/// middleware before nesting into the application router.
173///
174/// # This is unguarded generic CRUD, not a validated write path
175///
176/// These are plain create/update/patch/delete mutations over the entity row —
177/// they bypass all business invariants. If the module exposes a validated write
178/// service (e.g. a command router over its domain engine), serve THAT instead
179/// for any mutation that must respect domain rules.
180pub fn create_file_share_write_routes(service: Arc<FileShareService>) -> Router {
181    BackboneCrudHandler::<FileShareService, FileShare, CreateFileShareDto, UpdateFileShareDto, FileShareResponseDto>::write_routes(
182        service,
183        "/file_shares",
184    )
185}
186
187/// Create authenticated routes with auth middleware.
188///
189/// Requires the `auth` feature flag. The `AuthMiddleware` implementation
190/// is responsible for extracting and validating tokens, then providing
191/// an `AuthContext` via request extensions.
192#[cfg(feature = "auth")]
193pub fn create_protected_file_share_routes<A: AuthMiddleware + Send + Sync + 'static>(
194    service: Arc<FileShareService>,
195    auth: Arc<A>,
196) -> Router {
197    use axum::middleware;
198    use axum::response::IntoResponse;
199
200    let auth_layer = auth.clone();
201    create_file_share_routes(service)
202        .layer(middleware::from_fn(move |mut req: axum::extract::Request, next: axum::middleware::Next| {
203            let auth = auth_layer.clone();
204            async move {
205                let token = req.headers()
206                    .get(axum::http::header::AUTHORIZATION)
207                    .and_then(|h| h.to_str().ok())
208                    .and_then(|raw| raw.strip_prefix("Bearer ").or_else(|| raw.strip_prefix("bearer ")))
209                    .unwrap_or("");
210                match auth.authenticate(token).await {
211                    Ok(ctx) => {
212                        req.extensions_mut().insert(ctx);
213                        next.run(req).await
214                    }
215                    Err(_) => {
216                        (axum::http::StatusCode::UNAUTHORIZED,
217                         axum::Json(serde_json::json!({
218                             "success": false,
219                             "error": "unauthorized",
220                             "message": "Authentication required"
221                         }))
222                        ).into_response()
223                    }
224                }
225            }
226        }))
227}
228
229// =============================================================================
230// State Transition Handlers
231// =============================================================================
232
233/// Execute expire transition on a FileShare.
234///
235/// POST /file_shares/:id/transitions/expire
236pub async fn expire_transition(
237    axum::extract::State(service): axum::extract::State<Arc<FileShareService>>,
238    axum::extract::Path(id): axum::extract::Path<String>,
239    #[cfg(feature = "auth")] axum::Extension(auth): axum::Extension<AuthContext>,
240) -> impl axum::response::IntoResponse {
241    use axum::{http::StatusCode, Json};
242
243    // Get current entity
244    let entity = match service.get_by_id(&id).await {
245        Ok(Some(e)) => e,
246        Ok(None) => return (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
247        Err(e) => return (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
248    };
249
250    // Check permission (if auth enabled)
251    #[cfg(feature = "auth")]
252    {
253        let allowed_roles = FileShareTransition::Expire.allowed_roles();
254        let has_specific_perm = auth.permissions.iter().any(|p| p == "file_share:transition:expire");
255        let has_update_perm = auth.permissions.iter().any(|p| p == "file_share:update");
256        let has_role = auth.roles.iter().any(|r| allowed_roles.contains(&r.as_str()));
257        if !has_specific_perm && !has_update_perm && !has_role {
258            return (StatusCode::FORBIDDEN, Json(ApiResponse::<FileShareResponseDto>::error("Insufficient permissions for expire transition")));
259        }
260    }
261
262    // Create state machine from entity's actual status and validate transition
263    let current_state: FileShareState = entity.status.to_string().parse()
264        .unwrap_or(FileShareState::default());
265    let sm = FileShareStateMachine::from_state(current_state);
266    if !sm.can_transition(FileShareTransition::Expire) {
267        return (StatusCode::BAD_REQUEST, Json(ApiResponse::<FileShareResponseDto>::error("Transition not allowed from current state")));
268    }
269
270    // Apply transition via partial update
271    let mut fields: HashMap<String, serde_json::Value> = HashMap::new();
272    fields.insert("status".to_string(), serde_json::Value::String("Expired".to_string()));
273
274    match service.partial_update(&id, fields).await {
275        Ok(Some(updated)) => {
276            let response: FileShareResponseDto = updated.into();
277            (StatusCode::OK, Json(ApiResponse::ok(response)))
278        }
279        Ok(None) => (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
280        Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
281    }
282}
283
284/// Execute exhaust transition on a FileShare.
285///
286/// POST /file_shares/:id/transitions/exhaust
287pub async fn exhaust_transition(
288    axum::extract::State(service): axum::extract::State<Arc<FileShareService>>,
289    axum::extract::Path(id): axum::extract::Path<String>,
290    #[cfg(feature = "auth")] axum::Extension(auth): axum::Extension<AuthContext>,
291) -> impl axum::response::IntoResponse {
292    use axum::{http::StatusCode, Json};
293
294    // Get current entity
295    let entity = match service.get_by_id(&id).await {
296        Ok(Some(e)) => e,
297        Ok(None) => return (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
298        Err(e) => return (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
299    };
300
301    // Check permission (if auth enabled)
302    #[cfg(feature = "auth")]
303    {
304        let allowed_roles = FileShareTransition::Exhaust.allowed_roles();
305        let has_specific_perm = auth.permissions.iter().any(|p| p == "file_share:transition:exhaust");
306        let has_update_perm = auth.permissions.iter().any(|p| p == "file_share:update");
307        let has_role = auth.roles.iter().any(|r| allowed_roles.contains(&r.as_str()));
308        if !has_specific_perm && !has_update_perm && !has_role {
309            return (StatusCode::FORBIDDEN, Json(ApiResponse::<FileShareResponseDto>::error("Insufficient permissions for exhaust transition")));
310        }
311    }
312
313    // Create state machine from entity's actual status and validate transition
314    let current_state: FileShareState = entity.status.to_string().parse()
315        .unwrap_or(FileShareState::default());
316    let sm = FileShareStateMachine::from_state(current_state);
317    if !sm.can_transition(FileShareTransition::Exhaust) {
318        return (StatusCode::BAD_REQUEST, Json(ApiResponse::<FileShareResponseDto>::error("Transition not allowed from current state")));
319    }
320
321    // Apply transition via partial update
322    let mut fields: HashMap<String, serde_json::Value> = HashMap::new();
323    fields.insert("status".to_string(), serde_json::Value::String("Exhausted".to_string()));
324
325    match service.partial_update(&id, fields).await {
326        Ok(Some(updated)) => {
327            let response: FileShareResponseDto = updated.into();
328            (StatusCode::OK, Json(ApiResponse::ok(response)))
329        }
330        Ok(None) => (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
331        Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
332    }
333}
334
335/// Execute revoke transition on a FileShare.
336///
337/// POST /file_shares/:id/transitions/revoke
338pub async fn revoke_transition(
339    axum::extract::State(service): axum::extract::State<Arc<FileShareService>>,
340    axum::extract::Path(id): axum::extract::Path<String>,
341    #[cfg(feature = "auth")] axum::Extension(auth): axum::Extension<AuthContext>,
342) -> impl axum::response::IntoResponse {
343    use axum::{http::StatusCode, Json};
344
345    // Get current entity
346    let entity = match service.get_by_id(&id).await {
347        Ok(Some(e)) => e,
348        Ok(None) => return (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
349        Err(e) => return (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
350    };
351
352    // Check permission (if auth enabled)
353    #[cfg(feature = "auth")]
354    {
355        let allowed_roles = FileShareTransition::Revoke.allowed_roles();
356        let has_specific_perm = auth.permissions.iter().any(|p| p == "file_share:transition:revoke");
357        let has_update_perm = auth.permissions.iter().any(|p| p == "file_share:update");
358        let has_role = auth.roles.iter().any(|r| allowed_roles.contains(&r.as_str()));
359        if !has_specific_perm && !has_update_perm && !has_role {
360            return (StatusCode::FORBIDDEN, Json(ApiResponse::<FileShareResponseDto>::error("Insufficient permissions for revoke transition")));
361        }
362    }
363
364    // Create state machine from entity's actual status and validate transition
365    let current_state: FileShareState = entity.status.to_string().parse()
366        .unwrap_or(FileShareState::default());
367    let sm = FileShareStateMachine::from_state(current_state);
368    if !sm.can_transition(FileShareTransition::Revoke) {
369        return (StatusCode::BAD_REQUEST, Json(ApiResponse::<FileShareResponseDto>::error("Transition not allowed from current state")));
370    }
371
372    // Apply transition via partial update
373    let mut fields: HashMap<String, serde_json::Value> = HashMap::new();
374    fields.insert("status".to_string(), serde_json::Value::String("Revoked".to_string()));
375
376    match service.partial_update(&id, fields).await {
377        Ok(Some(updated)) => {
378            let response: FileShareResponseDto = updated.into();
379            (StatusCode::OK, Json(ApiResponse::ok(response)))
380        }
381        Ok(None) => (StatusCode::NOT_FOUND, Json(ApiResponse::<FileShareResponseDto>::not_found("FileShare", &id))),
382        Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, Json(ApiResponse::<FileShareResponseDto>::error(e.to_string()))),
383    }
384}
385
386/// Create routes for state transitions.
387pub fn create_file_share_transition_routes(service: Arc<FileShareService>) -> Router {
388    use axum::routing::post;
389
390    Router::new()
391        .route("/file_shares/:id/transitions/expire", post(expire_transition))
392        .route("/file_shares/:id/transitions/exhaust", post(exhaust_transition))
393        .route("/file_shares/:id/transitions/revoke", post(revoke_transition))
394        .with_state(service)
395}