InboundGrantIssuance.cs 1.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. namespace Admin.NET.Plugin.AiDOP.DataPlatform.Inbound;
  2. /// <summary>
  3. /// 推送授权该走哪条路。纯判断,不碰库:调用方按结果决定建身份还是只插授权行。
  4. /// </summary>
  5. public enum InboundGrantIssuanceKind
  6. {
  7. /// <summary>未带访问标识,新建身份并签发密钥。</summary>
  8. CreateIdentity,
  9. /// <summary>访问标识属于目标租户,只为新实体加授权行。</summary>
  10. ReuseIdentity,
  11. /// <summary>访问标识在开放接口身份中不存在。</summary>
  12. RejectUnknownKey,
  13. /// <summary>访问标识属于别的租户。用它发授权会把数据写进那个租户。</summary>
  14. RejectCrossTenant,
  15. }
  16. public sealed record InboundGrantIssuancePlan(
  17. InboundGrantIssuanceKind Kind,
  18. string AccessKey,
  19. string AccessSecret);
  20. public static class InboundGrantIssuance
  21. {
  22. public static InboundGrantIssuancePlan Plan(
  23. string requestedAccessKey,
  24. long tenantId,
  25. long boundTenantId,
  26. bool identityExists,
  27. Func<string> newKey,
  28. Func<string> newSecret)
  29. {
  30. if (string.IsNullOrWhiteSpace(requestedAccessKey))
  31. return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.CreateIdentity, newKey(), newSecret());
  32. var key = requestedAccessKey.Trim();
  33. if (!identityExists)
  34. return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectUnknownKey, key, "");
  35. if (boundTenantId != tenantId)
  36. return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectCrossTenant, key, "");
  37. return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.ReuseIdentity, key, "");
  38. }
  39. }