| | | 1 | | using AsiBackbone.Core.Acknowledgments; |
| | | 2 | | using AsiBackbone.Core.Actors; |
| | | 3 | | using AsiBackbone.Core.Decisions; |
| | | 4 | | using Microsoft.Extensions.Options; |
| | | 5 | | |
| | | 6 | | namespace AsiBackbone.AspNetCore.Acknowledgments; |
| | | 7 | | |
| | | 8 | | /// <summary> |
| | | 9 | | /// Provides the default ASP.NET Core-friendly acknowledgment challenge service. |
| | | 10 | | /// </summary> |
| | | 11 | | public sealed class DefaultAcknowledgmentChallengeService : IAcknowledgmentChallengeService |
| | | 12 | | { |
| | | 13 | | private const string ChallengeMismatchCode = "acknowledgment.challenge.mismatch"; |
| | | 14 | | private const string ChallengeActorMismatchCode = "acknowledgment.challenge.actor_mismatch"; |
| | | 15 | | private const string ChallengeCodeMismatchCode = "acknowledgment.challenge.code_mismatch"; |
| | | 16 | | |
| | | 17 | | private readonly AcknowledgmentChallengeOptions options; |
| | | 18 | | |
| | | 19 | | /// <summary> |
| | | 20 | | /// Initializes a new instance of the <see cref="DefaultAcknowledgmentChallengeService" /> class. |
| | | 21 | | /// </summary> |
| | | 22 | | /// <param name="options">The acknowledgment challenge options.</param> |
| | 68 | 23 | | public DefaultAcknowledgmentChallengeService(IOptions<AcknowledgmentChallengeOptions> options) |
| | | 24 | | { |
| | 68 | 25 | | this.options = options?.Value ?? throw new ArgumentNullException(nameof(options)); |
| | 67 | 26 | | this.options.Validate(); |
| | 66 | 27 | | } |
| | | 28 | | |
| | | 29 | | /// <inheritdoc /> |
| | | 30 | | public AcknowledgmentChallenge CreateChallenge( |
| | | 31 | | IGovernanceActorContext actor, |
| | | 32 | | string operationName, |
| | | 33 | | GovernanceDecision decision, |
| | | 34 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 35 | | { |
| | 38 | 36 | | ArgumentNullException.ThrowIfNull(actor); |
| | 36 | 37 | | ArgumentNullException.ThrowIfNull(decision); |
| | | 38 | | |
| | 35 | 39 | | if (!decision.RequiresAcknowledgment) |
| | | 40 | | { |
| | 1 | 41 | | throw new InvalidOperationException("Only acknowledgment-required governance decisions can be converted into |
| | | 42 | | } |
| | | 43 | | |
| | 34 | 44 | | if (!AcknowledgmentActorBinding.IsSufficient(actor)) |
| | | 45 | | { |
| | 6 | 46 | | throw new InvalidOperationException( |
| | 6 | 47 | | $"{AcknowledgmentActorBinding.FailureCode}: {AcknowledgmentActorBinding.FailureMessage}"); |
| | | 48 | | } |
| | | 49 | | |
| | 28 | 50 | | var request = AcknowledgmentRequest.FromDecision( |
| | 28 | 51 | | actor, |
| | 28 | 52 | | operationName, |
| | 28 | 53 | | decision, |
| | 28 | 54 | | options.RequiredAcknowledgmentCode, |
| | 28 | 55 | | options.RequiredAcknowledgmentText, |
| | 28 | 56 | | options.RiskLevel, |
| | 28 | 57 | | options.RiskCategory, |
| | 28 | 58 | | metadata: metadata); |
| | | 59 | | |
| | 28 | 60 | | return AcknowledgmentChallenge.FromAcknowledgmentRequest(request, options); |
| | | 61 | | } |
| | | 62 | | |
| | | 63 | | /// <inheritdoc /> |
| | | 64 | | public AcknowledgmentChallengeResult HandleResponse( |
| | | 65 | | AcknowledgmentChallenge challenge, |
| | | 66 | | IGovernanceActorContext actor, |
| | | 67 | | AcknowledgmentChallengeRequest response, |
| | | 68 | | DateTimeOffset? occurredUtc = null) |
| | | 69 | | { |
| | 25 | 70 | | ArgumentNullException.ThrowIfNull(challenge); |
| | 24 | 71 | | ArgumentNullException.ThrowIfNull(actor); |
| | 23 | 72 | | ArgumentNullException.ThrowIfNull(response); |
| | | 73 | | |
| | 22 | 74 | | if (!string.Equals(challenge.HandshakeId, response.HandshakeId?.Trim(), StringComparison.Ordinal)) |
| | | 75 | | { |
| | 4 | 76 | | return AcknowledgmentChallengeResult.Failure( |
| | 4 | 77 | | ChallengeMismatchCode, |
| | 4 | 78 | | "The acknowledgment response did not match the active challenge."); |
| | | 79 | | } |
| | | 80 | | |
| | 18 | 81 | | if (!AcknowledgmentActorBinding.IsSufficient(challenge.AcknowledgmentRequest) |
| | 18 | 82 | | || !AcknowledgmentActorBinding.IsSufficient(actor)) |
| | | 83 | | { |
| | 3 | 84 | | return AcknowledgmentChallengeResult.Failure( |
| | 3 | 85 | | AcknowledgmentActorBinding.FailureCode, |
| | 3 | 86 | | AcknowledgmentActorBinding.FailureMessage); |
| | | 87 | | } |
| | | 88 | | |
| | | 89 | | // The acknowledgment is the accountability record for the operation, so it must be produced by the actor the |
| | | 90 | | // challenge was issued to. Previously any actor could satisfy any challenge it could name, and the persisted |
| | | 91 | | // acknowledgment attributed the liability to whoever answered rather than to whoever was challenged. |
| | 15 | 92 | | if (!IsChallengedActor(challenge, actor)) |
| | | 93 | | { |
| | 3 | 94 | | return AcknowledgmentChallengeResult.Failure( |
| | 3 | 95 | | ChallengeActorMismatchCode, |
| | 3 | 96 | | "The acknowledgment response was not submitted by the actor the challenge was issued to."); |
| | | 97 | | } |
| | | 98 | | |
| | 12 | 99 | | if (!string.Equals(challenge.RequiredAcknowledgmentCode, response.AcknowledgmentCode?.Trim(), StringComparison.O |
| | | 100 | | { |
| | 6 | 101 | | return AcknowledgmentChallengeResult.Failure( |
| | 6 | 102 | | ChallengeCodeMismatchCode, |
| | 6 | 103 | | "The acknowledgment response did not contain the required acknowledgment code."); |
| | | 104 | | } |
| | | 105 | | |
| | 6 | 106 | | var acknowledgment = AcknowledgmentResponse.Create( |
| | 6 | 107 | | challenge.AcknowledgmentRequest, |
| | 6 | 108 | | actor, |
| | 6 | 109 | | response.Acknowledged, |
| | 6 | 110 | | occurredUtc: occurredUtc, |
| | 6 | 111 | | metadata: response.Metadata); |
| | | 112 | | |
| | 6 | 113 | | return AcknowledgmentChallengeResult.Success(acknowledgment); |
| | | 114 | | } |
| | | 115 | | |
| | | 116 | | /// <summary> |
| | | 117 | | /// Determines whether the responding actor is the actor the challenge was issued to. |
| | | 118 | | /// </summary> |
| | | 119 | | /// <remarks> |
| | | 120 | | /// Both the identifier and the actor type participate, because the same identifier under a different actor type is |
| | | 121 | | /// different principal. A single reason code covers both comparisons so a caller cannot use the failure to probe |
| | | 122 | | /// which component differed. |
| | | 123 | | /// </remarks> |
| | | 124 | | /// <param name="challenge">The active acknowledgment challenge.</param> |
| | | 125 | | /// <param name="actor">The actor that submitted the acknowledgment response.</param> |
| | | 126 | | /// <returns><see langword="true" /> when the responding actor matches the challenged actor.</returns> |
| | | 127 | | private static bool IsChallengedActor( |
| | | 128 | | AcknowledgmentChallenge challenge, |
| | | 129 | | IGovernanceActorContext actor) |
| | | 130 | | { |
| | 15 | 131 | | AcknowledgmentRequest request = challenge.AcknowledgmentRequest; |
| | | 132 | | |
| | 15 | 133 | | return string.Equals(request.ActorId, actor.ActorId?.Trim(), StringComparison.Ordinal) |
| | 15 | 134 | | && request.ActorType == actor.ActorType; |
| | | 135 | | } |
| | | 136 | | } |