Skip to main content

surrealdb_expr/expr/statements/
access.rs

1use surrealdb_strand::Strand;
2use surrealdb_types::{SqlFormat, ToSql};
3
4use crate::expr::{Base, Cond, RecordIdLit};
5use crate::val::Duration;
6
7// Keys and their identifiers are generated randomly from a 62-character pool.
8pub static GRANT_BEARER_CHARACTER_POOL: &[u8] =
9	b"0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";
10// The key identifier should not have collisions to prevent confusion.
11// However, collisions should be handled gracefully when issuing grants.
12// The first character of the key identifier will not be a digit to prevent parsing issues.
13// With 12 characters from the pool, one alphabetic, the key identifier part has ~68 bits of
14// entropy.
15pub static GRANT_BEARER_ID_LENGTH: usize = 12;
16// With 24 characters from the pool, the key part has ~140 bits of entropy.
17pub static GRANT_BEARER_KEY_LENGTH: usize = 24;
18
19#[derive(Clone, Debug, Eq, PartialEq, Hash)]
20pub enum AccessStatement {
21	Grant(AccessStatementGrant),   // Create access grant.
22	Show(AccessStatementShow),     // Show access grants.
23	Revoke(AccessStatementRevoke), // Revoke access grant.
24	Purge(AccessStatementPurge),   // Purge access grants.
25}
26
27#[derive(Clone, Debug, Eq, PartialEq, Hash)]
28pub struct AccessStatementGrant {
29	pub ac: Strand,
30	pub base: Option<Base>,
31	pub subject: Subject,
32}
33
34#[derive(Clone, Debug, Default, Eq, PartialEq, Hash)]
35pub struct AccessStatementShow {
36	pub ac: Strand,
37	pub base: Option<Base>,
38	pub gr: Option<Strand>,
39	pub cond: Option<Cond>,
40}
41
42#[derive(Clone, Debug, Default, Eq, PartialEq, Hash)]
43pub struct AccessStatementRevoke {
44	pub ac: Strand,
45	pub base: Option<Base>,
46	pub gr: Option<Strand>,
47	pub cond: Option<Cond>,
48}
49
50#[derive(Clone, Debug, Default, Eq, PartialEq, Hash)]
51pub struct AccessStatementPurge {
52	pub ac: Strand,
53	pub base: Option<Base>,
54	pub kind: PurgeKind,
55	pub grace: Duration,
56}
57
58#[derive(Clone, Debug, Default, Eq, PartialEq, Hash)]
59#[cfg_attr(feature = "arbitrary", derive(arbitrary::Arbitrary))]
60pub enum PurgeKind {
61	#[default]
62	Expired,
63	Revoked,
64	Both,
65}
66
67#[derive(Clone, Debug, Eq, PartialEq, Hash)]
68pub enum Subject {
69	Record(RecordIdLit),
70	User(Strand),
71}
72
73impl ToSql for AccessStatement {
74	fn fmt_sql(&self, f: &mut String, fmt: SqlFormat) {
75		let sql_stmt: crate::sql::statements::AccessStatement = self.clone().into();
76		sql_stmt.fmt_sql(f, fmt);
77	}
78}