| | | 1 | | using AsiBackbone.Core.Actors; |
| | | 2 | | using AsiBackbone.Core.Constraints; |
| | | 3 | | using AsiBackbone.Core.Decisions; |
| | | 4 | | using AsiBackbone.Core.Signing; |
| | | 5 | | |
| | | 6 | | namespace AsiBackbone.Core.Audit; |
| | | 7 | | |
| | | 8 | | /// <summary> |
| | | 9 | | /// Provides a fluent construction path for complex <see cref="DecisionReceipt" /> values. |
| | | 10 | | /// </summary> |
| | | 11 | | /// <remarks> |
| | | 12 | | /// The builder is intended for ergonomic object creation in host code, samples, and tests. It preserves the immutable |
| | | 13 | | /// <see cref="DecisionReceipt" /> value model by producing a new residue when <see cref="Build" /> is called. |
| | | 14 | | /// </remarks> |
| | | 15 | | public sealed class DecisionReceiptBuilder |
| | | 16 | | { |
| | | 17 | | private readonly IGovernanceActorContext actor; |
| | | 18 | | private readonly string operationName; |
| | | 19 | | private readonly string outcome; |
| | 29 | 20 | | private readonly List<string> reasonCodes = []; |
| | | 21 | | |
| | | 22 | | private Dictionary<string, string>? metadata; |
| | | 23 | | private string? eventId; |
| | | 24 | | private DateTimeOffset? occurredUtc; |
| | | 25 | | private string? correlationId; |
| | | 26 | | private string? traceId; |
| | | 27 | | private string? policyVersion; |
| | | 28 | | private string? policyHash; |
| | | 29 | | private string? decisionReceiptId; |
| | | 30 | | private string? spanId; |
| | | 31 | | private string? parentSpanId; |
| | | 32 | | private long? decisionLatencyMs; |
| | | 33 | | private string? constraintSetHash; |
| | | 34 | | private int? constraintCount; |
| | | 35 | | private double? riskScore; |
| | | 36 | | private string? policyScope; |
| | | 37 | | private string? tenantHash; |
| | | 38 | | private string? organizationHash; |
| | | 39 | | private string? emitterStatus; |
| | | 40 | | private string? emitterProvider; |
| | | 41 | | private long? outboxSequence; |
| | | 42 | | private string? gatewayExecutionId; |
| | | 43 | | private string? decisionStage; |
| | | 44 | | private string? schemaVersion; |
| | | 45 | | |
| | 29 | 46 | | private DecisionReceiptBuilder( |
| | 29 | 47 | | IGovernanceActorContext actor, |
| | 29 | 48 | | string operationName, |
| | 29 | 49 | | string outcome, |
| | 29 | 50 | | IEnumerable<string>? reasonCodes = null) |
| | | 51 | | { |
| | 29 | 52 | | ArgumentNullException.ThrowIfNull(actor); |
| | | 53 | | |
| | 29 | 54 | | this.actor = actor; |
| | 29 | 55 | | this.operationName = operationName; |
| | 29 | 56 | | this.outcome = outcome; |
| | 29 | 57 | | _ = WithReasonCodes(reasonCodes); |
| | 29 | 58 | | } |
| | | 59 | | |
| | | 60 | | /// <summary> |
| | | 61 | | /// Creates a builder for a host-defined audit outcome. |
| | | 62 | | /// </summary> |
| | | 63 | | public static DecisionReceiptBuilder Create( |
| | | 64 | | IGovernanceActorContext actor, |
| | | 65 | | string operationName, |
| | | 66 | | string outcome) |
| | | 67 | | { |
| | 8 | 68 | | return new DecisionReceiptBuilder(actor, operationName, outcome); |
| | | 69 | | } |
| | | 70 | | |
| | | 71 | | /// <summary> |
| | | 72 | | /// Creates a builder initialized from a governance decision. |
| | | 73 | | /// </summary> |
| | | 74 | | public static DecisionReceiptBuilder FromDecision( |
| | | 75 | | IGovernanceActorContext actor, |
| | | 76 | | string operationName, |
| | | 77 | | GovernanceDecision decision) |
| | | 78 | | { |
| | 17 | 79 | | ArgumentNullException.ThrowIfNull(decision); |
| | | 80 | | |
| | 16 | 81 | | return new DecisionReceiptBuilder( |
| | 16 | 82 | | actor, |
| | 16 | 83 | | operationName, |
| | 16 | 84 | | CanonicalEnumWireNames.ForDecisionOutcome(decision.Outcome), |
| | 16 | 85 | | decision.ReasonCodes) |
| | 16 | 86 | | .WithCorrelationId(decision.CorrelationId) |
| | 16 | 87 | | .WithTraceId(decision.TraceId) |
| | 16 | 88 | | .WithPolicyVersion(decision.PolicyVersion) |
| | 16 | 89 | | .WithPolicyHash(decision.PolicyHash); |
| | | 90 | | } |
| | | 91 | | |
| | | 92 | | /// <summary> |
| | | 93 | | /// Creates a builder initialized from a constraint evaluation result. |
| | | 94 | | /// </summary> |
| | | 95 | | public static DecisionReceiptBuilder FromConstraint( |
| | | 96 | | IGovernanceActorContext actor, |
| | | 97 | | string operationName, |
| | | 98 | | ConstraintEvaluationResult constraintResult) |
| | | 99 | | { |
| | 6 | 100 | | ArgumentNullException.ThrowIfNull(constraintResult); |
| | | 101 | | |
| | 5 | 102 | | return new DecisionReceiptBuilder( |
| | 5 | 103 | | actor, |
| | 5 | 104 | | operationName, |
| | 5 | 105 | | CanonicalEnumWireNames.ForConstraintOutcome(constraintResult.Outcome), |
| | 5 | 106 | | constraintResult.ReasonCodes); |
| | | 107 | | } |
| | | 108 | | |
| | | 109 | | /// <summary> |
| | | 110 | | /// Sets the audit event identifier. |
| | | 111 | | /// </summary> |
| | | 112 | | public DecisionReceiptBuilder WithEventId(string? value) |
| | | 113 | | { |
| | 22 | 114 | | eventId = value; |
| | 22 | 115 | | return this; |
| | | 116 | | } |
| | | 117 | | |
| | | 118 | | /// <summary> |
| | | 119 | | /// Sets the event occurrence timestamp. |
| | | 120 | | /// </summary> |
| | | 121 | | public DecisionReceiptBuilder WithOccurredUtc(DateTimeOffset? value) |
| | | 122 | | { |
| | 12 | 123 | | occurredUtc = value; |
| | 12 | 124 | | return this; |
| | | 125 | | } |
| | | 126 | | |
| | | 127 | | /// <summary> |
| | | 128 | | /// Replaces the reason-code collection. |
| | | 129 | | /// </summary> |
| | | 130 | | public DecisionReceiptBuilder WithReasonCodes(IEnumerable<string>? values) |
| | | 131 | | { |
| | 29 | 132 | | reasonCodes.Clear(); |
| | | 133 | | |
| | 29 | 134 | | if (values is not null) |
| | | 135 | | { |
| | 21 | 136 | | reasonCodes.AddRange(values); |
| | | 137 | | } |
| | | 138 | | |
| | 29 | 139 | | return this; |
| | | 140 | | } |
| | | 141 | | |
| | | 142 | | /// <summary> |
| | | 143 | | /// Adds one reason code to the builder. |
| | | 144 | | /// </summary> |
| | | 145 | | public DecisionReceiptBuilder AddReasonCode(string value) |
| | | 146 | | { |
| | 4 | 147 | | reasonCodes.Add(value); |
| | 4 | 148 | | return this; |
| | | 149 | | } |
| | | 150 | | |
| | | 151 | | /// <summary> |
| | | 152 | | /// Sets the correlation identifier. |
| | | 153 | | /// </summary> |
| | | 154 | | public DecisionReceiptBuilder WithCorrelationId(string? value) |
| | | 155 | | { |
| | 27 | 156 | | correlationId = value; |
| | 27 | 157 | | return this; |
| | | 158 | | } |
| | | 159 | | |
| | | 160 | | /// <summary> |
| | | 161 | | /// Sets the trace identifier. |
| | | 162 | | /// </summary> |
| | | 163 | | public DecisionReceiptBuilder WithTraceId(string? value) |
| | | 164 | | { |
| | 27 | 165 | | traceId = value; |
| | 27 | 166 | | return this; |
| | | 167 | | } |
| | | 168 | | |
| | | 169 | | /// <summary> |
| | | 170 | | /// Sets the policy version. |
| | | 171 | | /// </summary> |
| | | 172 | | public DecisionReceiptBuilder WithPolicyVersion(string? value) |
| | | 173 | | { |
| | 18 | 174 | | policyVersion = value; |
| | 18 | 175 | | return this; |
| | | 176 | | } |
| | | 177 | | |
| | | 178 | | /// <summary> |
| | | 179 | | /// Sets the policy hash. |
| | | 180 | | /// </summary> |
| | | 181 | | public DecisionReceiptBuilder WithPolicyHash(string? value) |
| | | 182 | | { |
| | 18 | 183 | | policyHash = value; |
| | 18 | 184 | | return this; |
| | | 185 | | } |
| | | 186 | | |
| | | 187 | | /// <summary> |
| | | 188 | | /// Replaces the metadata collection. |
| | | 189 | | /// </summary> |
| | | 190 | | public DecisionReceiptBuilder WithMetadata(IReadOnlyDictionary<string, string>? values) |
| | | 191 | | { |
| | 15 | 192 | | metadata = null; |
| | | 193 | | |
| | 15 | 194 | | if (values is not null) |
| | | 195 | | { |
| | 46 | 196 | | foreach (KeyValuePair<string, string> item in values) |
| | | 197 | | { |
| | 9 | 198 | | (metadata ??= new Dictionary<string, string>(StringComparer.Ordinal))[item.Key] = item.Value; |
| | | 199 | | } |
| | | 200 | | } |
| | | 201 | | |
| | 15 | 202 | | return this; |
| | | 203 | | } |
| | | 204 | | |
| | | 205 | | /// <summary> |
| | | 206 | | /// Adds or replaces one metadata value. |
| | | 207 | | /// </summary> |
| | | 208 | | public DecisionReceiptBuilder AddMetadata(string key, string value) |
| | | 209 | | { |
| | 8 | 210 | | (metadata ??= new Dictionary<string, string>(StringComparer.Ordinal))[key] = value; |
| | 8 | 211 | | return this; |
| | | 212 | | } |
| | | 213 | | |
| | | 214 | | /// <summary> |
| | | 215 | | /// Sets the stable decision receipt identifier. |
| | | 216 | | /// </summary> |
| | | 217 | | public DecisionReceiptBuilder WithDecisionReceiptId(string? value) |
| | | 218 | | { |
| | 2 | 219 | | decisionReceiptId = value; |
| | 2 | 220 | | return this; |
| | | 221 | | } |
| | | 222 | | |
| | | 223 | | /// <summary> |
| | | 224 | | /// Sets the span identifier. |
| | | 225 | | /// </summary> |
| | | 226 | | public DecisionReceiptBuilder WithSpanId(string? value) |
| | | 227 | | { |
| | 2 | 228 | | spanId = value; |
| | 2 | 229 | | return this; |
| | | 230 | | } |
| | | 231 | | |
| | | 232 | | /// <summary> |
| | | 233 | | /// Sets the parent span identifier. |
| | | 234 | | /// </summary> |
| | | 235 | | public DecisionReceiptBuilder WithParentSpanId(string? value) |
| | | 236 | | { |
| | 2 | 237 | | parentSpanId = value; |
| | 2 | 238 | | return this; |
| | | 239 | | } |
| | | 240 | | |
| | | 241 | | /// <summary> |
| | | 242 | | /// Sets the decision latency in milliseconds. |
| | | 243 | | /// </summary> |
| | | 244 | | public DecisionReceiptBuilder WithDecisionLatencyMs(long? value) |
| | | 245 | | { |
| | 2 | 246 | | decisionLatencyMs = value; |
| | 2 | 247 | | return this; |
| | | 248 | | } |
| | | 249 | | |
| | | 250 | | /// <summary> |
| | | 251 | | /// Sets the evaluated constraint-set hash. |
| | | 252 | | /// </summary> |
| | | 253 | | public DecisionReceiptBuilder WithConstraintSetHash(string? value) |
| | | 254 | | { |
| | 2 | 255 | | constraintSetHash = value; |
| | 2 | 256 | | return this; |
| | | 257 | | } |
| | | 258 | | |
| | | 259 | | /// <summary> |
| | | 260 | | /// Sets the evaluated constraint count. |
| | | 261 | | /// </summary> |
| | | 262 | | public DecisionReceiptBuilder WithConstraintCount(int? value) |
| | | 263 | | { |
| | 2 | 264 | | constraintCount = value; |
| | 2 | 265 | | return this; |
| | | 266 | | } |
| | | 267 | | |
| | | 268 | | /// <summary> |
| | | 269 | | /// Sets the host-defined risk score. |
| | | 270 | | /// </summary> |
| | | 271 | | public DecisionReceiptBuilder WithRiskScore(double? value) |
| | | 272 | | { |
| | 2 | 273 | | riskScore = value; |
| | 2 | 274 | | return this; |
| | | 275 | | } |
| | | 276 | | |
| | | 277 | | /// <summary> |
| | | 278 | | /// Sets the host-defined policy scope. |
| | | 279 | | /// </summary> |
| | | 280 | | public DecisionReceiptBuilder WithPolicyScope(string? value) |
| | | 281 | | { |
| | 2 | 282 | | policyScope = value; |
| | 2 | 283 | | return this; |
| | | 284 | | } |
| | | 285 | | |
| | | 286 | | /// <summary> |
| | | 287 | | /// Sets the privacy-preserving tenant hash. |
| | | 288 | | /// </summary> |
| | | 289 | | public DecisionReceiptBuilder WithTenantHash(string? value) |
| | | 290 | | { |
| | 2 | 291 | | tenantHash = value; |
| | 2 | 292 | | return this; |
| | | 293 | | } |
| | | 294 | | |
| | | 295 | | /// <summary> |
| | | 296 | | /// Sets the privacy-preserving organization hash. |
| | | 297 | | /// </summary> |
| | | 298 | | public DecisionReceiptBuilder WithOrganizationHash(string? value) |
| | | 299 | | { |
| | 2 | 300 | | organizationHash = value; |
| | 2 | 301 | | return this; |
| | | 302 | | } |
| | | 303 | | |
| | | 304 | | /// <summary> |
| | | 305 | | /// Sets the provider-neutral emitter status. |
| | | 306 | | /// </summary> |
| | | 307 | | public DecisionReceiptBuilder WithEmitterStatus(string? value) |
| | | 308 | | { |
| | 2 | 309 | | emitterStatus = value; |
| | 2 | 310 | | return this; |
| | | 311 | | } |
| | | 312 | | |
| | | 313 | | /// <summary> |
| | | 314 | | /// Sets the provider-neutral emitter provider name. |
| | | 315 | | /// </summary> |
| | | 316 | | public DecisionReceiptBuilder WithEmitterProvider(string? value) |
| | | 317 | | { |
| | 2 | 318 | | emitterProvider = value; |
| | 2 | 319 | | return this; |
| | | 320 | | } |
| | | 321 | | |
| | | 322 | | /// <summary> |
| | | 323 | | /// Sets the outbox sequence. |
| | | 324 | | /// </summary> |
| | | 325 | | public DecisionReceiptBuilder WithOutboxSequence(long? value) |
| | | 326 | | { |
| | 2 | 327 | | outboxSequence = value; |
| | 2 | 328 | | return this; |
| | | 329 | | } |
| | | 330 | | |
| | | 331 | | /// <summary> |
| | | 332 | | /// Sets the gateway execution identifier. |
| | | 333 | | /// </summary> |
| | | 334 | | public DecisionReceiptBuilder WithGatewayExecutionId(string? value) |
| | | 335 | | { |
| | 2 | 336 | | gatewayExecutionId = value; |
| | 2 | 337 | | return this; |
| | | 338 | | } |
| | | 339 | | |
| | | 340 | | /// <summary> |
| | | 341 | | /// Sets the provider-neutral decision stage. |
| | | 342 | | /// </summary> |
| | | 343 | | public DecisionReceiptBuilder WithDecisionStage(string? value) |
| | | 344 | | { |
| | 2 | 345 | | decisionStage = value; |
| | 2 | 346 | | return this; |
| | | 347 | | } |
| | | 348 | | |
| | | 349 | | /// <summary> |
| | | 350 | | /// Sets the decision receipt schema version. |
| | | 351 | | /// </summary> |
| | | 352 | | public DecisionReceiptBuilder WithSchemaVersion(string? value) |
| | | 353 | | { |
| | 2 | 354 | | schemaVersion = value; |
| | 2 | 355 | | return this; |
| | | 356 | | } |
| | | 357 | | |
| | | 358 | | /// <summary> |
| | | 359 | | /// Builds an immutable decision receipt value. |
| | | 360 | | /// </summary> |
| | | 361 | | public DecisionReceipt Build() |
| | | 362 | | { |
| | 31 | 363 | | return DecisionReceipt.Create( |
| | 31 | 364 | | actor, |
| | 31 | 365 | | operationName, |
| | 31 | 366 | | outcome, |
| | 31 | 367 | | reasonCodes, |
| | 31 | 368 | | eventId, |
| | 31 | 369 | | occurredUtc, |
| | 31 | 370 | | correlationId, |
| | 31 | 371 | | traceId, |
| | 31 | 372 | | policyVersion, |
| | 31 | 373 | | policyHash, |
| | 31 | 374 | | metadata, |
| | 31 | 375 | | decisionReceiptId, |
| | 31 | 376 | | spanId, |
| | 31 | 377 | | parentSpanId, |
| | 31 | 378 | | decisionLatencyMs, |
| | 31 | 379 | | constraintSetHash, |
| | 31 | 380 | | constraintCount, |
| | 31 | 381 | | riskScore, |
| | 31 | 382 | | policyScope, |
| | 31 | 383 | | tenantHash, |
| | 31 | 384 | | organizationHash, |
| | 31 | 385 | | emitterStatus, |
| | 31 | 386 | | emitterProvider, |
| | 31 | 387 | | outboxSequence, |
| | 31 | 388 | | gatewayExecutionId, |
| | 31 | 389 | | decisionStage, |
| | 31 | 390 | | schemaVersion); |
| | | 391 | | } |
| | | 392 | | } |