| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | using AsiBackbone.Core.Actors; |
| | | 3 | | using AsiBackbone.Core.Serialization; |
| | | 4 | | using SigningMetadataValue = AsiBackbone.Core.Signing.SigningMetadata; |
| | | 5 | | |
| | | 6 | | namespace AsiBackbone.Core.Audit; |
| | | 7 | | |
| | | 8 | | /// <summary> |
| | | 9 | | /// Represents a persistence-ready audit ledger record captured from AsiBackbone decision receipt. |
| | | 10 | | /// </summary> |
| | | 11 | | public sealed class AuditLedgerRecord : IDecisionReceipt |
| | | 12 | | { |
| | 3 | 13 | | private static readonly ReadOnlyCollection<string> EmptyReasonCodes = |
| | 3 | 14 | | Array.AsReadOnly(Array.Empty<string>()); |
| | | 15 | | |
| | 3 | 16 | | private static readonly IReadOnlyDictionary<string, string> EmptyMetadata = |
| | 3 | 17 | | new ReadOnlyDictionary<string, string>( |
| | 3 | 18 | | new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 19 | | |
| | 82 | 20 | | private AuditLedgerRecord( |
| | 82 | 21 | | string recordId, |
| | 82 | 22 | | string? schemaVersion, |
| | 82 | 23 | | string eventId, |
| | 82 | 24 | | string? decisionReceiptId, |
| | 82 | 25 | | DateTimeOffset occurredUtc, |
| | 82 | 26 | | DateTimeOffset recordedUtc, |
| | 82 | 27 | | string actorId, |
| | 82 | 28 | | GovernanceActorType actorType, |
| | 82 | 29 | | string? actorDisplayName, |
| | 82 | 30 | | string operationName, |
| | 82 | 31 | | string outcome, |
| | 82 | 32 | | IReadOnlyList<string> reasonCodes, |
| | 82 | 33 | | string? correlationId, |
| | 82 | 34 | | string? traceId, |
| | 82 | 35 | | string? spanId, |
| | 82 | 36 | | string? parentSpanId, |
| | 82 | 37 | | long? decisionLatencyMs, |
| | 82 | 38 | | string? constraintSetHash, |
| | 82 | 39 | | int? constraintCount, |
| | 82 | 40 | | double? riskScore, |
| | 82 | 41 | | string? policyScope, |
| | 82 | 42 | | string? tenantHash, |
| | 82 | 43 | | string? organizationHash, |
| | 82 | 44 | | string? emitterStatus, |
| | 82 | 45 | | string? emitterProvider, |
| | 82 | 46 | | long? outboxSequence, |
| | 82 | 47 | | string? gatewayExecutionId, |
| | 82 | 48 | | string? decisionStage, |
| | 82 | 49 | | string? policyVersion, |
| | 82 | 50 | | string? policyHash, |
| | 82 | 51 | | string? handshakeId, |
| | 82 | 52 | | string? acknowledgmentId, |
| | 82 | 53 | | string? capabilityTokenId, |
| | 82 | 54 | | string? previousRecordHash, |
| | 82 | 55 | | string? recordHash, |
| | 82 | 56 | | string? signatureKeyId, |
| | 82 | 57 | | string? signatureAlgorithm, |
| | 82 | 58 | | string? signatureValue, |
| | 82 | 59 | | string? signingHash, |
| | 82 | 60 | | string? signatureKeyVersion, |
| | 82 | 61 | | string? signatureProvider, |
| | 82 | 62 | | DateTimeOffset? signedUtc, |
| | 82 | 63 | | IReadOnlyDictionary<string, string> metadata) |
| | | 64 | | { |
| | 82 | 65 | | ArgumentException.ThrowIfNullOrWhiteSpace(recordId); |
| | 82 | 66 | | ArgumentException.ThrowIfNullOrWhiteSpace(eventId); |
| | 81 | 67 | | ArgumentException.ThrowIfNullOrWhiteSpace(actorId); |
| | 80 | 68 | | ArgumentException.ThrowIfNullOrWhiteSpace(operationName); |
| | 79 | 69 | | ArgumentException.ThrowIfNullOrWhiteSpace(outcome); |
| | | 70 | | |
| | 78 | 71 | | RecordId = recordId.Trim(); |
| | 78 | 72 | | SchemaVersion = GovernanceSchemaVersions.Normalize(schemaVersion); |
| | 78 | 73 | | EventId = eventId.Trim(); |
| | 78 | 74 | | DecisionReceiptId = NormalizeOptional(decisionReceiptId) ?? EventId; |
| | 78 | 75 | | OccurredUtc = occurredUtc.ToUniversalTime(); |
| | 78 | 76 | | RecordedUtc = recordedUtc.ToUniversalTime(); |
| | 78 | 77 | | ActorId = actorId.Trim(); |
| | 78 | 78 | | ActorType = actorType; |
| | 78 | 79 | | ActorDisplayName = NormalizeOptional(actorDisplayName); |
| | 78 | 80 | | OperationName = operationName.Trim(); |
| | 78 | 81 | | Outcome = outcome.Trim(); |
| | 78 | 82 | | ReasonCodes = reasonCodes; |
| | 78 | 83 | | CorrelationId = NormalizeOptional(correlationId); |
| | 78 | 84 | | TraceId = NormalizeOptional(traceId); |
| | 78 | 85 | | SpanId = NormalizeOptional(spanId); |
| | 78 | 86 | | ParentSpanId = NormalizeOptional(parentSpanId); |
| | 78 | 87 | | DecisionLatencyMs = NormalizeNonNegative(decisionLatencyMs, nameof(decisionLatencyMs)); |
| | 78 | 88 | | ConstraintSetHash = NormalizeOptional(constraintSetHash); |
| | 78 | 89 | | ConstraintCount = NormalizeNonNegative(constraintCount, nameof(constraintCount)); |
| | 78 | 90 | | RiskScore = NormalizeRiskScore(riskScore); |
| | 78 | 91 | | PolicyScope = NormalizeOptional(policyScope); |
| | 78 | 92 | | TenantHash = NormalizeOptional(tenantHash); |
| | 78 | 93 | | OrganizationHash = NormalizeOptional(organizationHash); |
| | 78 | 94 | | EmitterStatus = NormalizeOptional(emitterStatus); |
| | 78 | 95 | | EmitterProvider = NormalizeOptional(emitterProvider); |
| | 78 | 96 | | OutboxSequence = NormalizeNonNegative(outboxSequence, nameof(outboxSequence)); |
| | 78 | 97 | | GatewayExecutionId = NormalizeOptional(gatewayExecutionId); |
| | 78 | 98 | | DecisionStage = NormalizeOptional(decisionStage); |
| | 78 | 99 | | PolicyVersion = NormalizeOptional(policyVersion); |
| | 78 | 100 | | PolicyHash = NormalizeOptional(policyHash); |
| | 78 | 101 | | HandshakeId = NormalizeOptional(handshakeId); |
| | 78 | 102 | | AcknowledgmentId = NormalizeOptional(acknowledgmentId); |
| | 78 | 103 | | CapabilityTokenId = NormalizeOptional(capabilityTokenId); |
| | 78 | 104 | | PreviousRecordHash = NormalizeOptional(previousRecordHash); |
| | 78 | 105 | | RecordHash = NormalizeOptional(recordHash); |
| | 78 | 106 | | SignatureKeyId = NormalizeOptional(signatureKeyId); |
| | 78 | 107 | | SignatureAlgorithm = NormalizeOptional(signatureAlgorithm); |
| | 78 | 108 | | SignatureValue = NormalizeOptional(signatureValue); |
| | 78 | 109 | | SigningHash = NormalizeOptional(signingHash); |
| | 78 | 110 | | SignatureKeyVersion = NormalizeOptional(signatureKeyVersion); |
| | 78 | 111 | | SignatureProvider = NormalizeOptional(signatureProvider); |
| | 78 | 112 | | SignedUtc = signedUtc?.ToUniversalTime(); |
| | 78 | 113 | | SigningMetadata = SigningMetadataValue.Create( |
| | 78 | 114 | | SigningHash, |
| | 78 | 115 | | null, |
| | 78 | 116 | | SignatureValue, |
| | 78 | 117 | | SignatureAlgorithm, |
| | 78 | 118 | | SignatureKeyId, |
| | 78 | 119 | | SignatureKeyVersion, |
| | 78 | 120 | | SignatureProvider, |
| | 78 | 121 | | SignedUtc); |
| | 78 | 122 | | Metadata = metadata; |
| | 78 | 123 | | } |
| | | 124 | | |
| | | 125 | | public string RecordId { get; } |
| | | 126 | | |
| | | 127 | | public string SchemaVersion { get; } |
| | | 128 | | |
| | | 129 | | public string EventId { get; } |
| | | 130 | | |
| | | 131 | | public string DecisionReceiptId { get; } |
| | | 132 | | |
| | | 133 | | public DateTimeOffset OccurredUtc { get; } |
| | | 134 | | |
| | | 135 | | public DateTimeOffset RecordedUtc { get; } |
| | | 136 | | |
| | | 137 | | public string ActorId { get; } |
| | | 138 | | |
| | | 139 | | public GovernanceActorType ActorType { get; } |
| | | 140 | | |
| | | 141 | | public string? ActorDisplayName { get; } |
| | | 142 | | |
| | | 143 | | public string OperationName { get; } |
| | | 144 | | |
| | | 145 | | public string Outcome { get; } |
| | | 146 | | |
| | | 147 | | public IReadOnlyList<string> ReasonCodes { get; } |
| | | 148 | | |
| | | 149 | | public string? CorrelationId { get; } |
| | | 150 | | |
| | | 151 | | public string? TraceId { get; } |
| | | 152 | | |
| | | 153 | | public string? SpanId { get; } |
| | | 154 | | |
| | | 155 | | public string? ParentSpanId { get; } |
| | | 156 | | |
| | | 157 | | public long? DecisionLatencyMs { get; } |
| | | 158 | | |
| | | 159 | | public string? ConstraintSetHash { get; } |
| | | 160 | | |
| | | 161 | | public int? ConstraintCount { get; } |
| | | 162 | | |
| | | 163 | | public double? RiskScore { get; } |
| | | 164 | | |
| | | 165 | | public string? PolicyScope { get; } |
| | | 166 | | |
| | | 167 | | public string? TenantHash { get; } |
| | | 168 | | |
| | | 169 | | public string? OrganizationHash { get; } |
| | | 170 | | |
| | | 171 | | public string? EmitterStatus { get; } |
| | | 172 | | |
| | | 173 | | public string? EmitterProvider { get; } |
| | | 174 | | |
| | | 175 | | public long? OutboxSequence { get; } |
| | | 176 | | |
| | | 177 | | public string? GatewayExecutionId { get; } |
| | | 178 | | |
| | | 179 | | public string? DecisionStage { get; } |
| | | 180 | | |
| | | 181 | | public string? PolicyVersion { get; } |
| | | 182 | | |
| | | 183 | | public string? PolicyHash { get; } |
| | | 184 | | |
| | | 185 | | public string? HandshakeId { get; } |
| | | 186 | | |
| | | 187 | | public string? AcknowledgmentId { get; } |
| | | 188 | | |
| | | 189 | | public string? CapabilityTokenId { get; } |
| | | 190 | | |
| | | 191 | | public string? PreviousRecordHash { get; } |
| | | 192 | | |
| | | 193 | | public string? RecordHash { get; } |
| | | 194 | | |
| | | 195 | | public string? SigningHash { get; } |
| | | 196 | | |
| | | 197 | | public string? SignatureKeyId { get; } |
| | | 198 | | |
| | | 199 | | public string? SignatureKeyVersion { get; } |
| | | 200 | | |
| | | 201 | | public string? SignatureAlgorithm { get; } |
| | | 202 | | |
| | | 203 | | public string? SignatureValue { get; } |
| | | 204 | | |
| | | 205 | | public string? SignatureProvider { get; } |
| | | 206 | | |
| | | 207 | | public DateTimeOffset? SignedUtc { get; } |
| | | 208 | | |
| | | 209 | | public SigningMetadataValue SigningMetadata { get; } |
| | | 210 | | |
| | | 211 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 212 | | |
| | 6 | 213 | | public bool HasReasonCodes => ReasonCodes.Count > 0; |
| | | 214 | | |
| | 10 | 215 | | public bool HasMetadata => Metadata.Count > 0; |
| | | 216 | | |
| | | 217 | | public static AuditLedgerRecord FromDecisionReceipt( |
| | | 218 | | IDecisionReceipt receipt, |
| | | 219 | | string? recordId = null, |
| | | 220 | | DateTimeOffset? recordedUtc = null, |
| | | 221 | | string? handshakeId = null, |
| | | 222 | | string? acknowledgmentId = null, |
| | | 223 | | string? capabilityTokenId = null, |
| | | 224 | | string? previousRecordHash = null, |
| | | 225 | | string? recordHash = null, |
| | | 226 | | string? signatureKeyId = null, |
| | | 227 | | string? signatureAlgorithm = null, |
| | | 228 | | string? signatureValue = null, |
| | | 229 | | string? signingHash = null, |
| | | 230 | | string? signatureKeyVersion = null, |
| | | 231 | | string? signatureProvider = null, |
| | | 232 | | DateTimeOffset? signedUtc = null, |
| | | 233 | | IReadOnlyDictionary<string, string>? metadata = null, |
| | | 234 | | string? schemaVersion = null) |
| | | 235 | | { |
| | 83 | 236 | | ArgumentNullException.ThrowIfNull(receipt); |
| | | 237 | | |
| | 82 | 238 | | return new AuditLedgerRecord( |
| | 82 | 239 | | NormalizeIdentifier(recordId), |
| | 82 | 240 | | schemaVersion ?? receipt.SchemaVersion, |
| | 82 | 241 | | receipt.EventId, |
| | 82 | 242 | | receipt.DecisionReceiptId, |
| | 82 | 243 | | receipt.OccurredUtc, |
| | 82 | 244 | | recordedUtc ?? DateTimeOffset.UtcNow, |
| | 82 | 245 | | receipt.ActorId, |
| | 82 | 246 | | receipt.ActorType, |
| | 82 | 247 | | receipt.ActorDisplayName, |
| | 82 | 248 | | receipt.OperationName, |
| | 82 | 249 | | receipt.Outcome, |
| | 82 | 250 | | NormalizeReasonCodes(receipt.ReasonCodes), |
| | 82 | 251 | | receipt.CorrelationId, |
| | 82 | 252 | | receipt.TraceId, |
| | 82 | 253 | | receipt.SpanId, |
| | 82 | 254 | | receipt.ParentSpanId, |
| | 82 | 255 | | receipt.DecisionLatencyMs, |
| | 82 | 256 | | receipt.ConstraintSetHash, |
| | 82 | 257 | | receipt.ConstraintCount, |
| | 82 | 258 | | receipt.RiskScore, |
| | 82 | 259 | | receipt.PolicyScope, |
| | 82 | 260 | | receipt.TenantHash, |
| | 82 | 261 | | receipt.OrganizationHash, |
| | 82 | 262 | | receipt.EmitterStatus, |
| | 82 | 263 | | receipt.EmitterProvider, |
| | 82 | 264 | | receipt.OutboxSequence, |
| | 82 | 265 | | receipt.GatewayExecutionId, |
| | 82 | 266 | | receipt.DecisionStage, |
| | 82 | 267 | | receipt.PolicyVersion, |
| | 82 | 268 | | receipt.PolicyHash, |
| | 82 | 269 | | handshakeId, |
| | 82 | 270 | | acknowledgmentId, |
| | 82 | 271 | | capabilityTokenId, |
| | 82 | 272 | | previousRecordHash, |
| | 82 | 273 | | recordHash, |
| | 82 | 274 | | signatureKeyId, |
| | 82 | 275 | | signatureAlgorithm, |
| | 82 | 276 | | signatureValue, |
| | 82 | 277 | | signingHash, |
| | 82 | 278 | | signatureKeyVersion, |
| | 82 | 279 | | signatureProvider, |
| | 82 | 280 | | signedUtc, |
| | 82 | 281 | | NormalizeMetadata(receipt.Metadata, metadata)); |
| | | 282 | | } |
| | | 283 | | |
| | | 284 | | private static string NormalizeIdentifier(string? identifier) |
| | | 285 | | { |
| | 82 | 286 | | return string.IsNullOrWhiteSpace(identifier) |
| | 82 | 287 | | ? Guid.NewGuid().ToString("N") |
| | 82 | 288 | | : identifier.Trim(); |
| | | 289 | | } |
| | | 290 | | |
| | | 291 | | private static string? NormalizeOptional(string? value) |
| | | 292 | | { |
| | 2106 | 293 | | return string.IsNullOrWhiteSpace(value) |
| | 2106 | 294 | | ? null |
| | 2106 | 295 | | : value.Trim(); |
| | | 296 | | } |
| | | 297 | | |
| | | 298 | | private static long? NormalizeNonNegative(long? value, string parameterName) |
| | | 299 | | { |
| | 156 | 300 | | return value < 0 |
| | 156 | 301 | | ? throw new ArgumentOutOfRangeException(parameterName, value, "Value must be greater than or equal to zero." |
| | 156 | 302 | | : value; |
| | | 303 | | } |
| | | 304 | | |
| | | 305 | | private static int? NormalizeNonNegative(int? value, string parameterName) |
| | | 306 | | { |
| | 78 | 307 | | return value < 0 |
| | 78 | 308 | | ? throw new ArgumentOutOfRangeException(parameterName, value, "Value must be greater than or equal to zero." |
| | 78 | 309 | | : value; |
| | | 310 | | } |
| | | 311 | | |
| | | 312 | | private static double? NormalizeRiskScore(double? riskScore) |
| | | 313 | | { |
| | 78 | 314 | | return riskScore is null |
| | 78 | 315 | | ? null |
| | 78 | 316 | | : double.IsNaN(riskScore.Value) || double.IsInfinity(riskScore.Value) || riskScore.Value < 0 |
| | 78 | 317 | | ? throw new ArgumentOutOfRangeException(nameof(riskScore), riskScore, "Risk score must be a finite value gre |
| | 78 | 318 | | : riskScore; |
| | | 319 | | } |
| | | 320 | | |
| | | 321 | | private static ReadOnlyCollection<string> NormalizeReasonCodes(IEnumerable<string>? reasonCodes) |
| | | 322 | | { |
| | 82 | 323 | | string[] normalizedReasonCodes = reasonCodes? |
| | 82 | 324 | | .Where(reasonCode => !string.IsNullOrWhiteSpace(reasonCode)) |
| | 82 | 325 | | .Select(reasonCode => reasonCode.Trim()) |
| | 82 | 326 | | .ToArray() ?? []; |
| | | 327 | | |
| | 82 | 328 | | return normalizedReasonCodes.Length == 0 |
| | 82 | 329 | | ? EmptyReasonCodes |
| | 82 | 330 | | : Array.AsReadOnly(normalizedReasonCodes); |
| | | 331 | | } |
| | | 332 | | |
| | | 333 | | private static IReadOnlyDictionary<string, string> NormalizeMetadata( |
| | | 334 | | params IReadOnlyDictionary<string, string>?[] metadataSets) |
| | | 335 | | { |
| | 82 | 336 | | Dictionary<string, string> normalizedMetadata = new(StringComparer.Ordinal); |
| | | 337 | | |
| | 492 | 338 | | foreach (IReadOnlyDictionary<string, string>? metadata in metadataSets) |
| | | 339 | | { |
| | 164 | 340 | | if (metadata is null || metadata.Count == 0) |
| | | 341 | | { |
| | | 342 | | continue; |
| | | 343 | | } |
| | | 344 | | |
| | 168 | 345 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 346 | | { |
| | 48 | 347 | | if (string.IsNullOrWhiteSpace(item.Key)) |
| | | 348 | | { |
| | | 349 | | continue; |
| | | 350 | | } |
| | | 351 | | |
| | 45 | 352 | | normalizedMetadata[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 353 | | } |
| | | 354 | | } |
| | | 355 | | |
| | 82 | 356 | | return normalizedMetadata.Count == 0 |
| | 82 | 357 | | ? EmptyMetadata |
| | 82 | 358 | | : new ReadOnlyDictionary<string, string>(normalizedMetadata); |
| | | 359 | | } |
| | | 360 | | } |