Skip to main content

IntegrationsServiceClient

Struct IntegrationsServiceClient 

Source
pub struct IntegrationsServiceClient<T> { /* private fields */ }
Expand description

IntegrationsService is the gRPC surface of the pidgr-integrations service.

Auth model:

  • DispatchToChannel: internal-mTLS only. Called by the Temporal worker on behalf of pidgr-api dispatch activities. Never exposed publicly.
  • UpsertReachability / RemoveReachability / GetReachability / ListReachabilityForUser: Cognito JWT (admin RPCs, org-scoped on the caller’s custom:org_id claim).
  • GetRegionPolicy / SetRegionPolicy / GetCostCapPolicy / SetCostCapPolicy / GetOrgWebhookConfig / SetOrgWebhookConfig / CreateChannelConnectLink: Cognito JWT (admin only, org-scoped).

Cross-org access is denied with permission_denied.

Implementations§

Source§

impl IntegrationsServiceClient<Channel>

Source

pub async fn connect<D>(dst: D) -> Result<Self, Error>
where D: TryInto<Endpoint>, D::Error: Into<StdError>,

Attempt to create a new client by connecting to a given endpoint.

Source§

impl<T> IntegrationsServiceClient<T>
where T: GrpcService<Body>, T::Error: Into<StdError>, T::ResponseBody: Body<Data = Bytes> + Send + 'static, <T::ResponseBody as Body>::Error: Into<StdError> + Send,

Source

pub fn new(inner: T) -> Self

Source

pub fn with_origin(inner: T, origin: Uri) -> Self

Source

pub fn with_interceptor<F>( inner: T, interceptor: F, ) -> IntegrationsServiceClient<InterceptedService<T, F>>
where F: Interceptor, T::ResponseBody: Default, T: Service<Request<Body>, Response = Response<<T as GrpcService<Body>>::ResponseBody>>, <T as Service<Request<Body>>>::Error: Into<StdError> + Send + Sync,

Source

pub fn send_compressed(self, encoding: CompressionEncoding) -> Self

Compress requests with the given encoding.

This requires the server to support it otherwise it might respond with an error.

Source

pub fn accept_compressed(self, encoding: CompressionEncoding) -> Self

Enable decompressing responses.

Source

pub fn max_decoding_message_size(self, limit: usize) -> Self

Limits the maximum size of a decoded message.

Default: 4MB

Source

pub fn max_encoding_message_size(self, limit: usize) -> Self

Limits the maximum size of an encoded message.

Default: usize::MAX

Source

pub async fn dispatch_to_channel( &mut self, request: impl IntoRequest<DispatchToChannelRequest>, ) -> Result<Response<DispatchToChannelResponse>, Status>

Dispatch a single rendered message to one channel. Idempotent on dispatch_id. Internal-mTLS only.

Source

pub async fn upsert_reachability( &mut self, request: impl IntoRequest<UpsertReachabilityRequest>, ) -> Result<Response<UpsertReachabilityResponse>, Status>

Upsert a reachability identifier for a (user, channel) tuple. Encrypts and HMAC-hashes server-side before insert; emits a REACHABILITY_UPSERT audit row BEFORE the registry commit.

Source

pub async fn remove_reachability( &mut self, request: impl IntoRequest<RemoveReachabilityRequest>, ) -> Result<Response<RemoveReachabilityResponse>, Status>

Remove a reachability identifier. Idempotent. Emits a REACHABILITY_REMOVE audit row BEFORE the registry delete.

Source

pub async fn get_reachability( &mut self, request: impl IntoRequest<GetReachabilityRequest>, ) -> Result<Response<GetReachabilityResponse>, Status>

Read a single reachability row’s metadata. Returns NOT_FOUND if missing. Does not return plaintext or envelope ciphertext.

Source

pub async fn list_reachability_for_user( &mut self, request: impl IntoRequest<ListReachabilityForUserRequest>, ) -> Result<Response<ListReachabilityForUserResponse>, Status>

List per-channel reachability metadata for a single user. Used by the admin per-user matrix view. Does not return plaintext or ciphertext.

Source

pub async fn get_region_policy( &mut self, request: impl IntoRequest<GetRegionPolicyRequest>, ) -> Result<Response<GetRegionPolicyResponse>, Status>

Read the per-(org, channel) region allowlist. Returns an empty list when no policy is configured — NOT a NOT_FOUND.

Source

pub async fn set_region_policy( &mut self, request: impl IntoRequest<SetRegionPolicyRequest>, ) -> Result<Response<SetRegionPolicyResponse>, Status>

Admin-only upsert of the per-(org, channel) region allowlist.

Source

pub async fn get_cost_cap_policy( &mut self, request: impl IntoRequest<GetCostCapPolicyRequest>, ) -> Result<Response<GetCostCapPolicyResponse>, Status>

Read the current calendar-month cost-cap state. Returns the channel default cap when no row exists; never NOT_FOUND.

Source

pub async fn set_cost_cap_policy( &mut self, request: impl IntoRequest<SetCostCapPolicyRequest>, ) -> Result<Response<SetCostCapPolicyResponse>, Status>

Admin-only upsert of the current calendar-month cost cap.

Source

pub async fn get_org_webhook_config( &mut self, request: impl IntoRequest<GetOrgWebhookConfigRequest>, ) -> Result<Response<GetOrgWebhookConfigResponse>, Status>

Read the org’s generic-webhook channel configuration. The signing secret is never returned. Returns an empty-url config when none exists — NOT a NOT_FOUND.

Source

pub async fn set_org_webhook_config( &mut self, request: impl IntoRequest<SetOrgWebhookConfigRequest>, ) -> Result<Response<SetOrgWebhookConfigResponse>, Status>

Admin-only upsert of the org’s generic-webhook configuration. Validates the destination URL (https-only, public hosts) and envelope-encrypts the secret at rest.

CreateChannelConnectLink mints a short-lived, HMAC-signed opt-in link a user follows to bind a third-party channel (Telegram bot-follow, Slack OAuth, LINE follow-code) to their (org, user). Wraps the api-side internal/linktoken minter. Channels other than TELEGRAM, SLACK, and LINE are rejected with invalid_argument.

Source

pub async fn create_slack_workspace_install_authorization( &mut self, request: impl IntoRequest<CreateSlackWorkspaceInstallAuthorizationRequest>, ) -> Result<Response<CreateSlackWorkspaceInstallAuthorizationResponse>, Status>

CreateSlackWorkspaceInstallAuthorization mints a short-lived HMAC token authorizing a Slack workspace install into the caller’s authorized org. The admin passes it to the integrations install-start endpoint, which verifies it and installs the bot into THAT org — fixing the multi-org mis-routing where the install always landed on the caller’s JWT home org. Cognito JWT (admin only, org-scoped); cross-org is permission_denied.

Trait Implementations§

Source§

impl<T: Clone> Clone for IntegrationsServiceClient<T>

Source§

fn clone(&self) -> IntegrationsServiceClient<T>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<T: Debug> Debug for IntegrationsServiceClient<T>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more