use backbone_core::GenericCrudService;
use crate::presentation::dto::{CreateFileShareDto, UpdateFileShareDto};
use crate::domain::entity::FileShare;
use crate::infrastructure::persistence::FileShareRepository;
pub type FileShareService = GenericCrudService<
FileShare,
CreateFileShareDto,
UpdateFileShareDto,
FileShareRepository,
>;
pub struct FileShareRowRules;
#[async_trait::async_trait]
impl backbone_core::write_guard::WriteGuard<FileShare> for FileShareRowRules {
async fn check(
&self,
ctx: &backbone_core::write_guard::WriteCtx<'_, FileShare>,
) -> backbone_core::write_guard::GuardOutcome {
use backbone_core::row_rule as r;
use backbone_core::violation::Violation;
use backbone_core::write_guard::{GuardOutcome, WriteKind};
let (create, update) = (ctx.kind == WriteKind::Create, ctx.kind == WriteKind::Update);
let Some(after) = ctx.after.filter(|_| create || update) else {
return GuardOutcome::allow();
};
let Ok(row) = serde_json::to_value(after) else {
return GuardOutcome::allow();
};
let row = &row;
let old = ctx.before.and_then(|b| serde_json::to_value(b).ok());
let mut shadow = Vec::new();
if update && ctx.transition.is_none() && r::changed(old.as_ref(), row, &["status"]) {
shadow.push(Violation::new("status", "state_field_verbs_only", "the state field moves only through its verbs"));
}
if (create) && !r::holds(&r::and(r::ge(r::length(r::field(row, "token")), r::Val::Num(32.0_f64)), r::le(r::length(r::field(row, "token")), r::Val::Num(64.0_f64)))) {
shadow.push(Violation::new("token", "invalid_token_length", "Share token must be 32-64 characters"));
}
if (create) && !r::holds(&r::matches(r::field(row, "token"), "^[a-zA-Z0-9]+$")) {
shadow.push(Violation::new("token", "invalid_token_chars", "Share token must be alphanumeric"));
}
if (create || (update && r::changed(old.as_ref(), row, &["expires_at"]))) && !r::holds(&r::or(r::is_null(r::field(row, "expires_at")), r::gt(r::field(row, "expires_at"), r::at(ctx.at)))) {
shadow.push(Violation::new("expires_at", "expired_date", "Expiration date must be in the future"));
}
if (create || update) && !r::holds(&r::or(r::is_null(r::field(row, "max_downloads")), r::gt(r::field(row, "max_downloads"), r::Val::Num(0.0_f64)))) {
shadow.push(Violation::new("max_downloads", "invalid_max_downloads", "Maximum downloads must be positive"));
}
if (create) && !r::holds(&r::or(r::ne(r::field(row, "share_type"), r::text("user")), r::and(r::is_not_null(r::field(row, "shared_with")), r::gt(r::length(r::field(row, "shared_with")), r::Val::Num(0.0_f64))))) {
shadow.push(Violation::new("share_type", "missing_recipients", "User shares must specify recipients"));
}
if (update) && !r::holds(&r::or(r::or(r::eq(r::field(row, "status"), r::text("active")), r::eq(r::actor(ctx.actor.as_deref()), r::field(row, "owner_id"))), r::has_role(ctx.actor.as_deref(), "admin").await)) {
shadow.push(Violation::new("status", "share_inactive", "Cannot modify inactive shares"));
}
GuardOutcome { refuse: Vec::new(), shadow }
}
}