| | | 1 | | using AsiBackbone.Core.Constraints; |
| | | 2 | | using AsiBackbone.Core.Evaluation; |
| | | 3 | | using Microsoft.AspNetCore.Builder; |
| | | 4 | | |
| | | 5 | | namespace AsiBackbone.AspNetCore.Endpoints; |
| | | 6 | | |
| | | 7 | | /// <summary> |
| | | 8 | | /// Provides Minimal API / endpoint route-builder helpers for adding AsiBackbone governance metadata. |
| | | 9 | | /// </summary> |
| | | 10 | | public static class EndpointGovernanceRouteBuilderExtensions |
| | | 11 | | { |
| | | 12 | | /// <summary> |
| | | 13 | | /// Marks a Minimal API route handler endpoint with the host-defined decision policy that governs it. |
| | | 14 | | /// </summary> |
| | | 15 | | /// <remarks> |
| | | 16 | | /// This records a marker, not an enforcement rule. The framework does not resolve <typeparamref name="TPolicy" /> |
| | | 17 | | /// or select constraints from it: the registered <c>IGovernancePolicyEvaluator</c> evaluates every registered |
| | | 18 | | /// constraint on every governed endpoint regardless of which policy an endpoint is marked with. The marker reaches |
| | | 19 | | /// evaluation as the <c>endpoint.policy_types</c> metadata entry, where a host-supplied |
| | | 20 | | /// <see cref="IGovernanceDecisionPolicy{TContext}" /> can read it and vary its own outcome. Marking two endpoints |
| | | 21 | | /// with different policy types does not by itself make them evaluate differently. |
| | | 22 | | /// </remarks> |
| | | 23 | | /// <typeparam name="TPolicy">The host-registered decision policy that governs the endpoint.</typeparam> |
| | | 24 | | /// <param name="builder">The route handler builder.</param> |
| | | 25 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 26 | | public static RouteHandlerBuilder MarkGovernancePolicy<TPolicy>(this RouteHandlerBuilder builder) |
| | | 27 | | where TPolicy : IGovernanceDecisionPolicy<GovernanceEvaluationContext> |
| | | 28 | | { |
| | 1 | 29 | | return builder.MarkGovernancePolicy(typeof(TPolicy)); |
| | | 30 | | } |
| | | 31 | | |
| | | 32 | | /// <summary> |
| | | 33 | | /// Marks an endpoint with the host-defined policy type that governs it. |
| | | 34 | | /// </summary> |
| | | 35 | | /// <remarks> |
| | | 36 | | /// This records a marker, not an enforcement rule. See |
| | | 37 | | /// <see cref="MarkGovernancePolicy{TPolicy}(RouteHandlerBuilder)" /> for what the framework does and does not do |
| | | 38 | | /// with the recorded type. This overload accepts any type so hosts can mark endpoints with a plain marker type |
| | | 39 | | /// rather than a registered decision policy. |
| | | 40 | | /// </remarks> |
| | | 41 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 42 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 43 | | /// <param name="policyType">The host-defined policy marker or decision policy type.</param> |
| | | 44 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 45 | | public static TBuilder MarkGovernancePolicy<TBuilder>(this TBuilder builder, Type policyType) |
| | | 46 | | where TBuilder : IEndpointConventionBuilder |
| | | 47 | | { |
| | 3 | 48 | | ArgumentNullException.ThrowIfNull(policyType); |
| | 2 | 49 | | return AddEndpointMetadata(builder, new GovernancePolicyAttribute(policyType)); |
| | | 50 | | } |
| | | 51 | | |
| | | 52 | | /// <summary> |
| | | 53 | | /// Adds endpoint-scoped metadata requesting latency-optimized fast-abort policy evaluation after the first denied c |
| | | 54 | | /// </summary> |
| | | 55 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 56 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 57 | | /// <param name="enabled">Whether first-denial short-circuit metadata is enabled for the endpoint.</param> |
| | | 58 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 59 | | public static TBuilder ShortCircuitOnFirstDenial<TBuilder>(this TBuilder builder, bool enabled = true) |
| | | 60 | | where TBuilder : IEndpointConventionBuilder |
| | | 61 | | { |
| | 2 | 62 | | return AddEndpointMetadata(builder, new ShortCircuitOnFirstDenialAttribute(enabled)); |
| | | 63 | | } |
| | | 64 | | |
| | | 65 | | /// <summary> |
| | | 66 | | /// Adds liability-handshake metadata to an endpoint. |
| | | 67 | | /// </summary> |
| | | 68 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 69 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 70 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 71 | | public static TBuilder RequireAcknowledgment<TBuilder>(this TBuilder builder) |
| | | 72 | | where TBuilder : IEndpointConventionBuilder |
| | | 73 | | { |
| | 2 | 74 | | return AddEndpointMetadata(builder, new RequireAcknowledgmentAttribute()); |
| | | 75 | | } |
| | | 76 | | |
| | | 77 | | /// <summary> |
| | | 78 | | /// Adds a required capability-grant scope to an endpoint. |
| | | 79 | | /// </summary> |
| | | 80 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 81 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 82 | | /// <param name="scope">The required capability-grant scope.</param> |
| | | 83 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 84 | | public static TBuilder RequireCapabilityGrant<TBuilder>(this TBuilder builder, string scope) |
| | | 85 | | where TBuilder : IEndpointConventionBuilder |
| | | 86 | | { |
| | 1 | 87 | | return AddEndpointMetadata(builder, new RequireCapabilityGrantAttribute(scope)); |
| | | 88 | | } |
| | | 89 | | |
| | | 90 | | /// <summary> |
| | | 91 | | /// Adds governance-audit emission metadata to an endpoint. |
| | | 92 | | /// </summary> |
| | | 93 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 94 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 95 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 96 | | public static TBuilder EmitGovernanceAudit<TBuilder>(this TBuilder builder) |
| | | 97 | | where TBuilder : IEndpointConventionBuilder |
| | | 98 | | { |
| | 1 | 99 | | return AddEndpointMetadata(builder, new EmitGovernanceAuditAttribute()); |
| | | 100 | | } |
| | | 101 | | |
| | | 102 | | /// <summary> |
| | | 103 | | /// Allows an endpoint to pass through endpoint governance middleware when strict governance metadata enforcement is |
| | | 104 | | /// </summary> |
| | | 105 | | /// <typeparam name="TBuilder">The endpoint convention builder type.</typeparam> |
| | | 106 | | /// <param name="builder">The endpoint convention builder.</param> |
| | | 107 | | /// <returns>The same builder so calls can be chained.</returns> |
| | | 108 | | public static TBuilder AllowMissingGovernanceMetadata<TBuilder>(this TBuilder builder) |
| | | 109 | | where TBuilder : IEndpointConventionBuilder |
| | | 110 | | { |
| | 1 | 111 | | return AddEndpointMetadata(builder, new AllowMissingGovernanceMetadataAttribute()); |
| | | 112 | | } |
| | | 113 | | |
| | | 114 | | private static TBuilder AddEndpointMetadata<TBuilder>(TBuilder builder, object metadata) |
| | | 115 | | where TBuilder : IEndpointConventionBuilder |
| | | 116 | | { |
| | 10 | 117 | | ArgumentNullException.ThrowIfNull(builder); |
| | 9 | 118 | | ArgumentNullException.ThrowIfNull(metadata); |
| | | 119 | | |
| | 8 | 120 | | builder.Add(endpointBuilder => endpointBuilder.Metadata.Add(metadata)); |
| | 8 | 121 | | return builder; |
| | | 122 | | } |
| | | 123 | | } |