namespace Admin.NET.Plugin.AiDOP.DataPlatform.Inbound;
///
/// 推送授权该走哪条路。纯判断,不碰库:调用方按结果决定建身份还是只插授权行。
///
public enum InboundGrantIssuanceKind
{
/// 未带访问标识,新建身份并签发密钥。
CreateIdentity,
/// 访问标识属于目标租户,只为新实体加授权行。
ReuseIdentity,
/// 访问标识在开放接口身份中不存在。
RejectUnknownKey,
/// 访问标识属于别的租户。用它发授权会把数据写进那个租户。
RejectCrossTenant,
}
public sealed record InboundGrantIssuancePlan(
InboundGrantIssuanceKind Kind,
string AccessKey,
string AccessSecret);
public static class InboundGrantIssuance
{
public static InboundGrantIssuancePlan Plan(
string requestedAccessKey,
long tenantId,
long boundTenantId,
bool identityExists,
Func newKey,
Func newSecret)
{
if (string.IsNullOrWhiteSpace(requestedAccessKey))
return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.CreateIdentity, newKey(), newSecret());
var key = requestedAccessKey.Trim();
if (!identityExists)
return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectUnknownKey, key, "");
if (boundTenantId != tenantId)
return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectCrossTenant, key, "");
return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.ReuseIdentity, key, "");
}
}