use backbone_core::GenericCrudService;
use crate::presentation::dto::{CreateStoredFileDto, UpdateStoredFileDto};
use crate::domain::entity::StoredFile;
use crate::infrastructure::persistence::StoredFileRepository;
pub type StoredFileService = GenericCrudService<
StoredFile,
CreateStoredFileDto,
UpdateStoredFileDto,
StoredFileRepository,
>;
pub struct StoredFileRowRules;
#[async_trait::async_trait]
impl backbone_core::write_guard::WriteGuard<StoredFile> for StoredFileRowRules {
async fn check(
&self,
ctx: &backbone_core::write_guard::WriteCtx<'_, StoredFile>,
) -> backbone_core::write_guard::GuardOutcome {
use backbone_core::row_rule as r;
use backbone_core::violation::Violation;
use backbone_core::write_guard::{GuardOutcome, WriteKind};
let (create, update) = (ctx.kind == WriteKind::Create, ctx.kind == WriteKind::Update);
let Some(after) = ctx.after.filter(|_| create || update) else {
return GuardOutcome::allow();
};
let Ok(row) = serde_json::to_value(after) else {
return GuardOutcome::allow();
};
let row = &row;
let old = ctx.before.and_then(|b| serde_json::to_value(b).ok());
let mut shadow = Vec::new();
if update && ctx.transition.is_none() && r::changed(old.as_ref(), row, &["status"]) {
shadow.push(Violation::new("status", "state_field_verbs_only", "the state field moves only through its verbs"));
}
if (create || update) && !r::holds(&r::le(r::length(r::field(row, "path")), r::Val::Num(1024.0_f64))) {
shadow.push(Violation::new("path", "path_too_long", "File path too long (max 1024 characters)"));
}
if (create || update) && !r::holds(&r::not(r::contains(r::field(row, "path"), r::text("..")))) {
shadow.push(Violation::new("path", "path_traversal", "Path traversal not allowed"));
}
if (create) && !r::holds(&r::le(r::length(r::field(row, "original_name")), r::Val::Num(255.0_f64))) {
shadow.push(Violation::new("original_name", "filename_too_long", "File name too long (max 255 characters)"));
}
if (create) && !r::holds(&r::matches(r::field(row, "mime_type"), "^[a-z]+/[a-z0-9.+-]+$")) {
shadow.push(Violation::new("mime_type", "invalid_mime_type", "Invalid MIME type format"));
}
if (update) && !r::holds(&r::ne(r::field(row, "status"), r::text("purged"))) {
shadow.push(Violation::new("status", "file_purged", "Cannot update purged files"));
}
if (update) && !r::holds(&r::or(r::ne(r::field(row, "status"), r::text("quarantined")), r::has_role(ctx.actor.as_deref(), "admin").await)) {
shadow.push(Violation::new("status", "quarantine_restricted", "Only admins can modify quarantined files"));
}
GuardOutcome { refuse: Vec::new(), shadow }
}
}