| | | 1 | | using ProjectTemplate.Infrastructure.Data.Entities; |
| | | 2 | | |
| | | 3 | | namespace ProjectTemplate.Infrastructure.Data.Auditing; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Includes audited values unchanged except for the personal fields the template ships, which are masked. |
| | | 7 | | /// </summary> |
| | | 8 | | /// <remarks> |
| | | 9 | | /// <para> |
| | | 10 | | /// Audit records are durable and retained, so a value written here outlives the row it describes. This policy masks |
| | | 11 | | /// the contact fields on <see cref="ExternalLoginAccount" /> because a generated application would otherwise persist |
| | | 12 | | /// an end user's email address and display name into audit history the first time an external login is created or |
| | | 13 | | /// updated, without the consumer having chosen that. Masking still records that the property changed, so the audit |
| | | 14 | | /// trail keeps its accountability value without carrying the value itself. |
| | | 15 | | /// </para> |
| | | 16 | | /// <para> |
| | | 17 | | /// Every other property is included unchanged. Applications that add entities carrying personal data should replace |
| | | 18 | | /// this policy rather than extend it, since the fields worth protecting depend on the application's own model. See |
| | | 19 | | /// the audit accountability documentation for the replacement seam. |
| | | 20 | | /// </para> |
| | | 21 | | /// </remarks> |
| | | 22 | | public sealed class DefaultApplicationAuditValuePolicy : IApplicationAuditValuePolicy |
| | | 23 | | { |
| | | 24 | | public ApplicationAuditValueDecision Evaluate( |
| | | 25 | | Type entityType, |
| | | 26 | | string propertyName, |
| | | 27 | | object? value) |
| | | 28 | | { |
| | 333 | 29 | | ArgumentNullException.ThrowIfNull(entityType); |
| | 333 | 30 | | ArgumentException.ThrowIfNullOrWhiteSpace(propertyName); |
| | | 31 | | |
| | 333 | 32 | | return IsMaskedExternalLoginAccountProperty(entityType, propertyName) |
| | 333 | 33 | | ? ApplicationAuditValueDecision.Mask |
| | 333 | 34 | | : ApplicationAuditValueDecision.Include; |
| | | 35 | | } |
| | | 36 | | |
| | | 37 | | private static bool IsMaskedExternalLoginAccountProperty(Type entityType, string propertyName) |
| | | 38 | | { |
| | 333 | 39 | | return entityType == typeof(ExternalLoginAccount) |
| | 333 | 40 | | && propertyName is nameof(ExternalLoginAccount.Email) |
| | 333 | 41 | | or nameof(ExternalLoginAccount.NormalizedEmail) |
| | 333 | 42 | | or nameof(ExternalLoginAccount.DisplayName); |
| | | 43 | | } |
| | | 44 | | } |