namespace Admin.NET.Plugin.AiDOP.DataPlatform.Inbound; /// /// 推送授权该走哪条路。纯判断,不碰库:调用方按结果决定建身份还是只插授权行。 /// public enum InboundGrantIssuanceKind { /// 未带访问标识,新建身份并签发密钥。 CreateIdentity, /// 访问标识属于目标租户,只为新实体加授权行。 ReuseIdentity, /// 访问标识在开放接口身份中不存在。 RejectUnknownKey, /// 访问标识属于别的租户。用它发授权会把数据写进那个租户。 RejectCrossTenant, } public sealed record InboundGrantIssuancePlan( InboundGrantIssuanceKind Kind, string AccessKey, string AccessSecret); public static class InboundGrantIssuance { public static InboundGrantIssuancePlan Plan( string requestedAccessKey, long tenantId, long boundTenantId, bool identityExists, Func newKey, Func newSecret) { if (string.IsNullOrWhiteSpace(requestedAccessKey)) return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.CreateIdentity, newKey(), newSecret()); var key = requestedAccessKey.Trim(); if (!identityExists) return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectUnknownKey, key, ""); if (boundTenantId != tenantId) return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectCrossTenant, key, ""); return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.ReuseIdentity, key, ""); } }