onetaskgraph_plugin_api/metadata.rs
1//! The one key a narrow metadata write names, and the refusal a source that cannot make one
2//! answers with.
3//!
4//! A narrow metadata write sets one key of one record's metadata and changes nothing else
5//! about the record — see [`TaskSource::set_task_metadata`](crate::TaskSource::set_task_metadata).
6//! What a caller may name there is narrower than what a record may hold: a record read from a
7//! source carries this product's own `onetaskgraph.` keys, and a caller writing one of them
8//! through this seam would be editing the store's bookkeeping by hand.
9
10use schemars::JsonSchema;
11use serde::{Deserialize, Serialize};
12
13use crate::SourceError;
14
15/// One caller-owned metadata key: `<namespace>.<name>`, at least two non-empty segments
16/// separated by dots, whose first segment is not [`MetadataKey::RESERVED_NAMESPACE`].
17///
18/// Validated wherever one is built, deserialized included, so a plugin handed one never has
19/// to ask whether it names a key this product owns.
20#[derive(
21 Debug, Clone, PartialEq, Eq, Hash, PartialOrd, Ord, Serialize, Deserialize, JsonSchema,
22)]
23#[serde(try_from = "String", into = "String")]
24pub struct MetadataKey(String);
25
26impl MetadataKey {
27 /// The namespace this product owns, and a narrow write therefore never names.
28 ///
29 /// Every key the contract reserves lives under it — `onetaskgraph.origin`,
30 /// `onetaskgraph.repositories`, `onetaskgraph.depends_on`, `onetaskgraph.delivers`,
31 /// `onetaskgraph.delivered_by`, `onetaskgraph.item_kind`, `onetaskgraph.template`
32 /// ([`Self::TEMPLATE_KEY`]), `onetaskgraph.copies` ([`Self::COPIES_KEY`]),
33 /// `onetaskgraph.members` ([`Self::MEMBERS_KEY`]) and `onetaskgraph.member_of`
34 /// ([`Self::MEMBER_OF_KEY`]) — and so does any key it reserves later, which is why the
35 /// whole namespace is refused rather than a list.
36 pub const RESERVED_NAMESPACE: &'static str = "onetaskgraph";
37
38 /// The reserved key a task or a document rendered from a template records where it came
39 /// from under: an object holding the template's reference, the chain digest it was
40 /// rendered with, and the SHA-256 of its content and of its resolved answers.
41 ///
42 /// A key of this product's own, so no [`MetadataKey`] can name it: only a rendering write
43 /// — [`TaskSource::write_task_rendered`](crate::TaskSource::write_task_rendered) and
44 /// [`TaskSource::set_task_rendering`](crate::TaskSource::set_task_rendering) and their
45 /// document siblings — ever sets it, and a copy carries it like any other entry. The
46 /// engine builds and reads the value; a plugin only puts it where its metadata lives.
47 pub const TEMPLATE_KEY: &'static str = "onetaskgraph.template";
48
49 /// The reserved key a copied item records where it landed under: a JSON object mapping a
50 /// destination source name to the qualified id of that item's counterpart there, at
51 /// most one entry per destination.
52 ///
53 /// A key of this product's own, so [`Self::new`] refuses it like every other key in the
54 /// namespace: only the engine's copy writes it, through the narrow metadata write, and
55 /// [`Self::copies`] is how it names the key there. A plugin only puts it where its
56 /// metadata lives.
57 pub const COPIES_KEY: &'static str = "onetaskgraph.copies";
58
59 /// The reserved key a **home** project records its member projects under: a JSON list of
60 /// qualified project ids, each in a different source from the home and from the others,
61 /// so a home has at most one member per source.
62 ///
63 /// Store-owned, like every key in the namespace: only the engine's routed writes keep it —
64 /// a copy, or a `task create` routed away from its project's source — through the home's
65 /// own project write, and nothing a caller types can name it. A plugin
66 /// only puts it where its metadata lives.
67 pub const MEMBERS_KEY: &'static str = "onetaskgraph.members";
68
69 /// The reserved key a **member** project records its home under: the home's qualified id.
70 ///
71 /// Written once, when a routed write — a copy or a `task create` — creates the member, and
72 /// never by a caller.
73 pub const MEMBER_OF_KEY: &'static str = "onetaskgraph.member_of";
74
75 /// [`Self::COPIES_KEY`], as the one reserved key a narrow metadata write may carry.
76 ///
77 /// Not a way round [`Self::new`] for a caller: nothing a person types reaches this, and
78 /// the one write that sends it is the copy recording where an item landed.
79 #[must_use]
80 // llmlint: ignore[invalid_states_unrepresentable] A key type of its own would change the
81 // signature of the three narrow metadata writes on `TaskSource`, which every plugin
82 // implements and this crate keeps still (AGENTS.md); the reserved key reaches that seam
83 // only through this one named constructor, while `new`, deserialization, the command line
84 // and both SDKs refuse it, and the stdio boundary admits it only with a value that is links.
85 pub fn copies() -> Self {
86 Self(Self::COPIES_KEY.to_owned())
87 }
88
89 /// Whether this is [`Self::COPIES_KEY`].
90 #[must_use]
91 pub fn is_copies(&self) -> bool {
92 self.0 == Self::COPIES_KEY
93 }
94
95 /// One key, once it is established it is a caller's own dotted key.
96 ///
97 /// # Errors
98 ///
99 /// Returns a message saying why, and what to write instead, when the key has no dot, has
100 /// an empty segment, or is in [`Self::RESERVED_NAMESPACE`].
101 pub fn new(key: impl Into<String>) -> Result<Self, String> {
102 let key = key.into();
103 let segments: Vec<&str> = key.split('.').collect();
104 if segments.len() < 2 {
105 return Err(format!(
106 "the metadata key {key:?} has no namespace: a key is `<namespace>.<name>`, two \
107 or more non-empty segments separated by dots; next: name it under a namespace \
108 of your own, such as `myapp.{key}`"
109 ));
110 }
111 if segments.iter().any(|segment| segment.is_empty()) {
112 return Err(format!(
113 "the metadata key {key:?} has an empty segment: a key is `<namespace>.<name>`, \
114 two or more non-empty segments separated by dots; next: remove the extra dot"
115 ));
116 }
117 if segments[0] == Self::RESERVED_NAMESPACE {
118 return Err(format!(
119 "the metadata key {key:?} is in the `{}.` namespace, which this product owns \
120 and keeps in step itself; next: name the key under a namespace of your own",
121 Self::RESERVED_NAMESPACE
122 ));
123 }
124 Ok(Self(key))
125 }
126
127 /// The key as a record's metadata map spells it.
128 #[must_use]
129 pub fn as_str(&self) -> &str {
130 &self.0
131 }
132}
133
134impl TryFrom<String> for MetadataKey {
135 type Error = String;
136
137 fn try_from(key: String) -> Result<Self, Self::Error> {
138 Self::new(key)
139 }
140}
141
142impl From<MetadataKey> for String {
143 fn from(key: MetadataKey) -> Self {
144 key.0
145 }
146}
147
148impl std::fmt::Display for MetadataKey {
149 fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
150 self.0.fmt(formatter)
151 }
152}
153
154/// Which kind of record a narrow metadata write names.
155///
156/// The three a record can be, and no fourth: a refusal, a not-found error or a protocol guard
157/// that names the record takes one of these rather than a noun, so it cannot name something
158/// that is not a record.
159#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
160pub enum MetadataRecord {
161 /// A task, written through [`TaskSource::set_task_metadata`](crate::TaskSource::set_task_metadata).
162 Task,
163 /// A project, written through
164 /// [`TaskSource::set_project_metadata`](crate::TaskSource::set_project_metadata).
165 Project,
166 /// A document, written through
167 /// [`TaskSource::set_document_metadata`](crate::TaskSource::set_document_metadata).
168 Document,
169}
170
171impl MetadataRecord {
172 /// The record's noun as a message spells it: `task`, `project` or `document`.
173 #[must_use]
174 pub const fn noun(self) -> &'static str {
175 match self {
176 Self::Task => "task",
177 Self::Project => "project",
178 Self::Document => "document",
179 }
180 }
181}
182
183impl std::fmt::Display for MetadataRecord {
184 fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
185 formatter.write_str(self.noun())
186 }
187}
188
189/// The refusal a source answers a narrow metadata write with when it cannot make one on its
190/// own.
191///
192/// It reads `the linear plugin cannot write a document's metadata on its own`, naming the
193/// record. Spelled once beside [`unwritable_field`](crate::unwritable_field) for that
194/// function's reason: the trait's defaults and the engine's refusal of a plugin whose
195/// handshake does not declare the write say the same thing in the same words.
196#[must_use]
197pub fn unwritable_metadata(kind: &str, record: MetadataRecord) -> SourceError {
198 SourceError::Refused {
199 message: format!("the {kind} plugin cannot write a {record}'s metadata on its own"),
200 }
201}