systemprompt_security/authz/repository/
mod.rs1mod entities;
18mod rules;
19
20pub use rules::ChainFingerprint;
21
22use std::sync::Arc;
23
24use sqlx::PgPool;
25use systemprompt_database::DbPool;
26
27use super::error::{AuthzError, AuthzResult};
28use super::types::{Access, EntityKind, RuleType};
29
30#[derive(Debug, Clone)]
31pub struct ExportRuleRow {
32 pub entity_type: String,
33 pub entity_id: String,
34 pub rule_type: String,
35 pub rule_value: String,
36 pub access: String,
37 pub justification: Option<String>,
38}
39
40#[derive(Debug, Clone)]
41pub struct UpsertRuleParams<'a> {
42 pub entity_type: EntityKind,
43 pub entity_id: &'a str,
44 pub rule_type: RuleType,
45 pub rule_value: &'a str,
46 pub access: Access,
47 pub justification: Option<&'a str>,
48 pub source: &'a str,
49}
50
51#[derive(Clone, Debug)]
52pub struct AccessControlRepository {
53 pool: Arc<PgPool>,
54 write_pool: Arc<PgPool>,
55}
56
57impl AccessControlRepository {
58 pub fn new(db: &DbPool) -> AuthzResult<Self> {
59 let pool = db
60 .pool_arc()
61 .map_err(|err| AuthzError::Validation(err.to_string()))?;
62 let write_pool = db
63 .write_pool_arc()
64 .map_err(|err| AuthzError::Validation(err.to_string()))?;
65 Ok(Self { pool, write_pool })
66 }
67
68 pub fn from_pool(pool: Arc<PgPool>) -> Self {
69 let write_pool = Arc::clone(&pool);
70 Self { pool, write_pool }
71 }
72}