backbone-bucket 0.4.6

Bucket Bounded Context: File Storage Module for Backbone Framework
Documentation
//! Application service for StoredFile entities
//!
//! Generated by metaphor-schema. Do not edit manually.
//!
//! Type alias over `GenericCrudService` — all CRUD logic lives in backbone-core.
//! For custom behaviour, create `stored_file_service_custom.rs` (preserved on regen).

use backbone_core::GenericCrudService;

use crate::presentation::dto::{CreateStoredFileDto, UpdateStoredFileDto};
use crate::domain::entity::StoredFile;
use crate::infrastructure::persistence::StoredFileRepository;

/// Application service for StoredFile entities.
///
/// All 12 standard CRUD operations (list, create, get, update, patch,
/// soft_delete, restore, empty_trash, bulk_create, upsert, find_by_id,
/// list_deleted) are provided by `GenericCrudService`.
///
/// Custom extensions go in `stored_file_service_custom.rs`:
///
/// ```rust,ignore
/// pub struct StoredFileServiceCustom {
///     inner: Arc<StoredFileService>,
///     // add domain-specific dependencies here
/// }
/// ```
pub type StoredFileService = GenericCrudService<
    StoredFile,
    CreateStoredFileDto,
    UpdateStoredFileDto,
    StoredFileRepository,
>;

/// The row rules the schema declares for StoredFile, checked against the row a create or
/// update would store. The generated build attaches it to [`StoredFileService`]. Every rule
/// runs in shadow: a break is logged under `backbone::write_guard` and the write goes ahead.
pub struct StoredFileRowRules;

#[async_trait::async_trait]
impl backbone_core::write_guard::WriteGuard<StoredFile> for StoredFileRowRules {
    async fn check(
        &self,
        ctx: &backbone_core::write_guard::WriteCtx<'_, StoredFile>,
    ) -> backbone_core::write_guard::GuardOutcome {
        use backbone_core::row_rule as r;
        use backbone_core::violation::Violation;
        use backbone_core::write_guard::{GuardOutcome, WriteKind};
        let (create, update) = (ctx.kind == WriteKind::Create, ctx.kind == WriteKind::Update);
        let Some(after) = ctx.after.filter(|_| create || update) else {
            return GuardOutcome::allow();
        };
        let Ok(row) = serde_json::to_value(after) else {
            return GuardOutcome::allow();
        };
        let row = &row;
        let old = ctx.before.and_then(|b| serde_json::to_value(b).ok());
        let mut shadow = Vec::new();
        // `status` belongs to a state machine: only its verbs move it
        if update && ctx.transition.is_none() && r::changed(old.as_ref(), row, &["status"]) {
            shadow.push(Violation::new("status", "state_field_verbs_only", "the state field moves only through its verbs"));
        }
        // `path_length` (stored_file.hook.yaml:170)
        if (create || update) && !r::holds(&r::le(r::length(r::field(row, "path")), r::Val::Num(1024.0_f64))) {
            shadow.push(Violation::new("path", "path_too_long", "File path too long (max 1024 characters)"));
        }
        // `no_path_traversal` (stored_file.hook.yaml:176)
        if (create || update) && !r::holds(&r::not(r::contains(r::field(row, "path"), r::text("..")))) {
            shadow.push(Violation::new("path", "path_traversal", "Path traversal not allowed"));
        }
        // `filename_length` (stored_file.hook.yaml:182)
        if (create) && !r::holds(&r::le(r::length(r::field(row, "original_name")), r::Val::Num(255.0_f64))) {
            shadow.push(Violation::new("original_name", "filename_too_long", "File name too long (max 255 characters)"));
        }
        // `valid_mime_type` (stored_file.hook.yaml:188)
        if (create) && !r::holds(&r::matches(r::field(row, "mime_type"), "^[a-z]+/[a-z0-9.+-]+$")) {
            shadow.push(Violation::new("mime_type", "invalid_mime_type", "Invalid MIME type format"));
        }
        // `file_not_purged` (stored_file.hook.yaml:194)
        if (update) && !r::holds(&r::ne(r::field(row, "status"), r::text("purged"))) {
            shadow.push(Violation::new("status", "file_purged", "Cannot update purged files"));
        }
        // `quarantine_admin_only` (stored_file.hook.yaml:200)
        if (update) && !r::holds(&r::or(r::ne(r::field(row, "status"), r::text("quarantined")), r::has_role(ctx.actor.as_deref(), "admin").await)) {
            shadow.push(Violation::new("status", "quarantine_restricted", "Only admins can modify quarantined files"));
        }
        GuardOutcome { refuse: Vec::new(), shadow }
    }
}