#![deny(clippy::wildcard_enum_match_arm)]
use common::{LeafError, internal_todo};
use surrealdb_types::{AuthError, Error as TypesError};
#[derive(Debug, thiserror::Error)]
pub(crate) enum Error {
#[error("There was an error creating the token")]
TokenMakingFailed,
#[error("No record was returned")]
NoRecordFound,
#[error("Username or Password was not provided")]
MissingUserOrPass,
#[error("No signin target to either SC or DB or NS or KV")]
NoSigninTarget,
#[error("The password did not verify")]
InvalidPass,
#[error("There was a problem with authentication")]
InvalidAuth,
#[error("There was an unexpected error while performing authentication")]
UnexpectedAuth,
#[error("There was a problem with signing up")]
InvalidSignup,
#[error("The token has expired")]
ExpiredToken,
#[error("The access method cannot be used in the requested operation")]
AccessMethodMismatch,
#[error("The access method does not exist")]
AccessNotFound,
#[error("This access method has an invalid duration")]
AccessInvalidDuration,
#[error("This access method results in an invalid expiration")]
AccessInvalidExpiration,
#[error("The record access signup query failed")]
AccessRecordSignupQueryFailed,
#[error("The record access signin query failed")]
AccessRecordSigninQueryFailed,
#[error("This record access method does not allow signup")]
AccessRecordNoSignup,
#[error("This record access method does not allow signin")]
AccessRecordNoSignin,
#[error("This bearer access method requires a key to be provided")]
AccessBearerMissingKey,
#[error("This bearer access grant has an invalid format")]
AccessGrantBearerInvalid,
}
impl From<base64::DecodeError> for Error {
fn from(_: base64::DecodeError) -> Error {
Error::InvalidAuth
}
}
impl From<jsonwebtoken::errors::Error> for Error {
fn from(_: jsonwebtoken::errors::Error) -> Error {
Error::InvalidAuth
}
}
impl LeafError for Error {
fn map_kind(self, message: String) -> TypesError {
match self {
Error::ExpiredToken => TypesError::not_allowed(message, AuthError::TokenExpired),
Error::InvalidAuth => TypesError::not_allowed(message, AuthError::InvalidAuth),
Error::UnexpectedAuth => TypesError::not_allowed(message, AuthError::UnexpectedAuth),
Error::MissingUserOrPass => {
TypesError::not_allowed(message, AuthError::MissingUserOrPass)
}
Error::NoSigninTarget => TypesError::not_allowed(message, AuthError::NoSigninTarget),
Error::InvalidPass => TypesError::not_allowed(message, AuthError::InvalidPass),
Error::TokenMakingFailed => {
TypesError::not_allowed(message, AuthError::TokenMakingFailed)
}
Error::InvalidSignup => TypesError::not_allowed(message, AuthError::InvalidSignup),
Error::AccessRecordNoSignup | Error::AccessRecordNoSignin => {
TypesError::not_allowed(message, None)
}
Error::NoRecordFound => TypesError::not_found(message, None),
Error::AccessRecordSignupQueryFailed | Error::AccessRecordSigninQueryFailed => {
TypesError::query(message, None)
}
Error::AccessMethodMismatch
| Error::AccessNotFound
| Error::AccessInvalidDuration
| Error::AccessInvalidExpiration
| Error::AccessBearerMissingKey
| Error::AccessGrantBearerInvalid => internal_todo(message),
}
}
}