use serde_yaml::Value as YamlValue;
use super::secrets::SecretPatternError;
use super::types::GovernancePolicy;
pub type PolicyFactory =
fn(&YamlValue) -> Result<Box<dyn GovernancePolicy>, PolicyConfigurationError>;
#[derive(Debug, thiserror::Error)]
pub enum PolicyConfigurationError {
#[error("unknown access scope `{scope}` in require_approval exempt_scopes")]
UnknownExemptScope { scope: String },
#[error(
"require_approval condition on `{tool}` at `{path}` has no operand its `{operator}` \
operator can use"
)]
UnusableCondition {
tool: String,
path: String,
operator: &'static str,
},
#[error(
"secret_scan is in enforce mode but compiles no secret patterns; declare `patterns` or \
set `mode: warn`"
)]
ToothlessSecretScan,
#[error("{context}: {source}")]
Yaml {
context: &'static str,
#[source]
source: serde_yaml::Error,
},
#[error(transparent)]
SecretPatterns(#[from] SecretPatternError),
}
#[derive(Debug, Clone, Copy)]
pub struct PolicyRegistration {
pub id: &'static str,
pub factory: PolicyFactory,
}
inventory::collect!(PolicyRegistration);
#[doc(hidden)]
pub use inventory;
#[macro_export]
macro_rules! register_governance_policy {
($id:expr, $factory:expr) => {
$crate::policy::registry::inventory::submit! {
$crate::policy::PolicyRegistration {
id: $id,
factory: $factory,
}
}
};
}