| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.Classification; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Represents provider-neutral context for resolving DLP or classification failure behavior. |
| | | 7 | | /// </summary> |
| | | 8 | | public sealed class DlpFailurePolicyContext |
| | | 9 | | { |
| | 1 | 10 | | private static readonly IReadOnlyDictionary<string, string> EmptyMetadata = |
| | 1 | 11 | | new ReadOnlyDictionary<string, string>( |
| | 1 | 12 | | new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 13 | | |
| | 53 | 14 | | private DlpFailurePolicyContext( |
| | 53 | 15 | | DlpClassificationFailureKind failureKind, |
| | 53 | 16 | | DlpIntentRiskLevel riskLevel, |
| | 53 | 17 | | string? intentCategory, |
| | 53 | 18 | | string? environment, |
| | 53 | 19 | | string? correlationId, |
| | 53 | 20 | | string? traceId, |
| | 53 | 21 | | string? policyVersion, |
| | 53 | 22 | | string? policyHash, |
| | 53 | 23 | | TimeSpan? timeout, |
| | 53 | 24 | | IReadOnlyDictionary<string, string> metadata) |
| | | 25 | | { |
| | 53 | 26 | | if (!Enum.IsDefined(failureKind)) |
| | | 27 | | { |
| | 1 | 28 | | throw new ArgumentOutOfRangeException(nameof(failureKind), failureKind, "DLP failure kind must be defined.") |
| | | 29 | | } |
| | | 30 | | |
| | 52 | 31 | | if (!Enum.IsDefined(riskLevel)) |
| | | 32 | | { |
| | 1 | 33 | | throw new ArgumentOutOfRangeException(nameof(riskLevel), riskLevel, "DLP intent risk level must be defined." |
| | | 34 | | } |
| | | 35 | | |
| | | 36 | | // The host assigns the risk tier, and every tier maps to a different failure behavior. An unassigned tier is |
| | | 37 | | // rejected here rather than treated as the lowest one, so a caller that never set it fails closed at the bounda |
| | | 38 | | // instead of resolving to the most permissive policy. |
| | 51 | 39 | | if (riskLevel == DlpIntentRiskLevel.Unspecified) |
| | | 40 | | { |
| | 1 | 41 | | throw new ArgumentOutOfRangeException( |
| | 1 | 42 | | nameof(riskLevel), |
| | 1 | 43 | | riskLevel, |
| | 1 | 44 | | "DLP intent risk level must be assigned. Supply Low, Medium, or High rather than leaving the risk level |
| | | 45 | | } |
| | | 46 | | |
| | 50 | 47 | | if (timeout < TimeSpan.Zero) |
| | | 48 | | { |
| | 1 | 49 | | throw new ArgumentOutOfRangeException(nameof(timeout), timeout, "Timeout must be greater than or equal to ze |
| | | 50 | | } |
| | | 51 | | |
| | 49 | 52 | | FailureKind = failureKind; |
| | 49 | 53 | | RiskLevel = riskLevel; |
| | 49 | 54 | | IntentCategory = NormalizeOptional(intentCategory); |
| | 49 | 55 | | Environment = NormalizeOptional(environment); |
| | 49 | 56 | | CorrelationId = NormalizeOptional(correlationId); |
| | 49 | 57 | | TraceId = NormalizeOptional(traceId); |
| | 49 | 58 | | PolicyVersion = NormalizeOptional(policyVersion); |
| | 49 | 59 | | PolicyHash = NormalizeOptional(policyHash); |
| | 49 | 60 | | Timeout = timeout; |
| | 49 | 61 | | Metadata = metadata; |
| | 49 | 62 | | } |
| | | 63 | | |
| | | 64 | | /// <summary> |
| | | 65 | | /// Gets the provider-neutral DLP or classification failure kind. |
| | | 66 | | /// </summary> |
| | | 67 | | public DlpClassificationFailureKind FailureKind { get; } |
| | | 68 | | |
| | | 69 | | /// <summary> |
| | | 70 | | /// Gets the host-assigned risk level for the intent. |
| | | 71 | | /// </summary> |
| | | 72 | | public DlpIntentRiskLevel RiskLevel { get; } |
| | | 73 | | |
| | | 74 | | /// <summary> |
| | | 75 | | /// Gets the host-defined intent category, when supplied. |
| | | 76 | | /// </summary> |
| | | 77 | | public string? IntentCategory { get; } |
| | | 78 | | |
| | | 79 | | /// <summary> |
| | | 80 | | /// Gets the host-defined environment, when supplied. |
| | | 81 | | /// </summary> |
| | | 82 | | public string? Environment { get; } |
| | | 83 | | |
| | | 84 | | /// <summary> |
| | | 85 | | /// Gets the correlation identifier associated with the governed flow, when supplied. |
| | | 86 | | /// </summary> |
| | | 87 | | public string? CorrelationId { get; } |
| | | 88 | | |
| | | 89 | | /// <summary> |
| | | 90 | | /// Gets the trace identifier associated with the governed flow, when supplied. |
| | | 91 | | /// </summary> |
| | | 92 | | public string? TraceId { get; } |
| | | 93 | | |
| | | 94 | | /// <summary> |
| | | 95 | | /// Gets the policy version associated with the governed flow, when supplied. |
| | | 96 | | /// </summary> |
| | | 97 | | public string? PolicyVersion { get; } |
| | | 98 | | |
| | | 99 | | /// <summary> |
| | | 100 | | /// Gets the policy hash associated with the governed flow, when supplied. |
| | | 101 | | /// </summary> |
| | | 102 | | public string? PolicyHash { get; } |
| | | 103 | | |
| | | 104 | | /// <summary> |
| | | 105 | | /// Gets the timeout value associated with the failure, when applicable. |
| | | 106 | | /// </summary> |
| | | 107 | | public TimeSpan? Timeout { get; } |
| | | 108 | | |
| | | 109 | | /// <summary> |
| | | 110 | | /// Gets provider-neutral host metadata associated with the failure. |
| | | 111 | | /// </summary> |
| | | 112 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 113 | | |
| | | 114 | | /// <summary> |
| | | 115 | | /// Gets a value indicating whether timeout context is present. |
| | | 116 | | /// </summary> |
| | 2 | 117 | | public bool HasTimeout => Timeout.HasValue; |
| | | 118 | | |
| | | 119 | | /// <summary> |
| | | 120 | | /// Gets a value indicating whether metadata is present. |
| | | 121 | | /// </summary> |
| | 5 | 122 | | public bool HasMetadata => Metadata.Count > 0; |
| | | 123 | | |
| | | 124 | | /// <summary> |
| | | 125 | | /// Creates a provider-neutral DLP or classification failure policy context. |
| | | 126 | | /// </summary> |
| | | 127 | | public static DlpFailurePolicyContext Create( |
| | | 128 | | DlpClassificationFailureKind failureKind, |
| | | 129 | | DlpIntentRiskLevel riskLevel, |
| | | 130 | | string? intentCategory = null, |
| | | 131 | | string? environment = null, |
| | | 132 | | string? correlationId = null, |
| | | 133 | | string? traceId = null, |
| | | 134 | | string? policyVersion = null, |
| | | 135 | | string? policyHash = null, |
| | | 136 | | TimeSpan? timeout = null, |
| | | 137 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 138 | | { |
| | 53 | 139 | | return new DlpFailurePolicyContext( |
| | 53 | 140 | | failureKind, |
| | 53 | 141 | | riskLevel, |
| | 53 | 142 | | intentCategory, |
| | 53 | 143 | | environment, |
| | 53 | 144 | | correlationId, |
| | 53 | 145 | | traceId, |
| | 53 | 146 | | policyVersion, |
| | 53 | 147 | | policyHash, |
| | 53 | 148 | | timeout, |
| | 53 | 149 | | NormalizeMetadata(metadata)); |
| | | 150 | | } |
| | | 151 | | |
| | | 152 | | /// <summary> |
| | | 153 | | /// Creates timeout-specific failure policy context. |
| | | 154 | | /// </summary> |
| | | 155 | | public static DlpFailurePolicyContext TimeoutFailure( |
| | | 156 | | DlpIntentRiskLevel riskLevel, |
| | | 157 | | TimeSpan? timeout = null, |
| | | 158 | | string? intentCategory = null, |
| | | 159 | | string? environment = null, |
| | | 160 | | string? correlationId = null, |
| | | 161 | | string? traceId = null, |
| | | 162 | | string? policyVersion = null, |
| | | 163 | | string? policyHash = null, |
| | | 164 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 165 | | { |
| | 6 | 166 | | return Create( |
| | 6 | 167 | | DlpClassificationFailureKind.Timeout, |
| | 6 | 168 | | riskLevel, |
| | 6 | 169 | | intentCategory, |
| | 6 | 170 | | environment, |
| | 6 | 171 | | correlationId, |
| | 6 | 172 | | traceId, |
| | 6 | 173 | | policyVersion, |
| | 6 | 174 | | policyHash, |
| | 6 | 175 | | timeout, |
| | 6 | 176 | | metadata); |
| | | 177 | | } |
| | | 178 | | |
| | | 179 | | private static string? NormalizeOptional(string? value) |
| | | 180 | | { |
| | 294 | 181 | | return string.IsNullOrWhiteSpace(value) |
| | 294 | 182 | | ? null |
| | 294 | 183 | | : value.Trim(); |
| | | 184 | | } |
| | | 185 | | |
| | | 186 | | private static IReadOnlyDictionary<string, string> NormalizeMetadata( |
| | | 187 | | IReadOnlyDictionary<string, string>? metadata) |
| | | 188 | | { |
| | 53 | 189 | | if (metadata is null || metadata.Count == 0) |
| | | 190 | | { |
| | 49 | 191 | | return EmptyMetadata; |
| | | 192 | | } |
| | | 193 | | |
| | 4 | 194 | | Dictionary<string, string> normalizedMetadata = new(StringComparer.Ordinal); |
| | | 195 | | |
| | 24 | 196 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 197 | | { |
| | 8 | 198 | | if (string.IsNullOrWhiteSpace(item.Key)) |
| | | 199 | | { |
| | | 200 | | continue; |
| | | 201 | | } |
| | | 202 | | |
| | 5 | 203 | | normalizedMetadata[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 204 | | } |
| | | 205 | | |
| | 4 | 206 | | return normalizedMetadata.Count == 0 |
| | 4 | 207 | | ? EmptyMetadata |
| | 4 | 208 | | : new ReadOnlyDictionary<string, string>(normalizedMetadata); |
| | | 209 | | } |
| | | 210 | | } |