use anyhow::Result;
use reblessive::tree::Stk;
use crate::catalog::Error;
use crate::catalog::providers::AuthorisationProvider;
use crate::ctx::FrozenContext;
use crate::dbs::Options;
use crate::doc::CursorDoc;
use crate::expr::Base;
use crate::expr::statements::remove::access::RemoveAccessStatement;
use crate::iam::{Action, ResourceKind};
use crate::legacy::expr_to_ident;
use crate::val::Value;
pub(crate) async fn remove_access_statement_compute(
this: &RemoveAccessStatement,
stk: &mut Stk,
ctx: &FrozenContext,
opt: &Options,
doc: Option<&CursorDoc>,
) -> Result<Value> {
ctx.is_allowed(opt, Action::Edit, ResourceKind::Actor, this.base)?;
let name = expr_to_ident(stk, ctx, opt, doc, &this.name, "access name").await?;
match &this.base {
Base::Root => {
let txn = ctx.tx();
let Some(ac) = txn.get_root_access(&name, None).await? else {
if this.if_exists {
return Ok(Value::None);
} else {
return Err(anyhow::Error::new(Error::AccessRootNotFound {
ac: name,
}));
}
};
txn.del_root_access(&ac.name).await?;
txn.clear_cache();
Ok(Value::None)
}
Base::Ns => {
let txn = ctx.tx();
let ns = ctx.get_ns_id(opt).await?;
let Some(ac) = txn.get_ns_access(ns, &name, None).await? else {
if this.if_exists {
return Ok(Value::None);
} else {
let ns = opt.ns()?;
return Err(anyhow::Error::new(Error::AccessNsNotFound {
ac: name,
ns: ns.to_string(),
}));
}
};
txn.del_ns_access(ns, &ac.name).await?;
txn.clear_cache();
Ok(Value::None)
}
Base::Db => {
let txn = ctx.tx();
let (ns, db) = ctx.expect_ns_db_ids(opt).await?;
let Some(ac) = txn.get_db_access(ns, db, &name, None).await? else {
if this.if_exists {
return Ok(Value::None);
} else {
let (ns, db) = opt.ns_db()?;
return Err(anyhow::Error::new(Error::AccessDbNotFound {
ac: name,
ns: ns.to_string(),
db: db.to_string(),
}));
}
};
txn.del_db_access(ns, db, &ac.name).await?;
txn.clear_cache();
Ok(Value::None)
}
}
}