| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546 |
- namespace Admin.NET.Plugin.AiDOP.DataPlatform.Inbound;
- /// <summary>
- /// 推送授权该走哪条路。纯判断,不碰库:调用方按结果决定建身份还是只插授权行。
- /// </summary>
- public enum InboundGrantIssuanceKind
- {
- /// <summary>未带访问标识,新建身份并签发密钥。</summary>
- CreateIdentity,
- /// <summary>访问标识属于目标租户,只为新实体加授权行。</summary>
- ReuseIdentity,
- /// <summary>访问标识在开放接口身份中不存在。</summary>
- RejectUnknownKey,
- /// <summary>访问标识属于别的租户。用它发授权会把数据写进那个租户。</summary>
- RejectCrossTenant,
- }
- public sealed record InboundGrantIssuancePlan(
- InboundGrantIssuanceKind Kind,
- string AccessKey,
- string AccessSecret);
- public static class InboundGrantIssuance
- {
- public static InboundGrantIssuancePlan Plan(
- string requestedAccessKey,
- long tenantId,
- long boundTenantId,
- bool identityExists,
- Func<string> newKey,
- Func<string> newSecret)
- {
- if (string.IsNullOrWhiteSpace(requestedAccessKey))
- return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.CreateIdentity, newKey(), newSecret());
- var key = requestedAccessKey.Trim();
- if (!identityExists)
- return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectUnknownKey, key, "");
- if (boundTenantId != tenantId)
- return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.RejectCrossTenant, key, "");
- return new InboundGrantIssuancePlan(InboundGrantIssuanceKind.ReuseIdentity, key, "");
- }
- }
|