acl

package
v0.19.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 30, 2026 License: AGPL-3.0 Imports: 13 Imported by: 0

Documentation

Index

Constants

View Source
const (
	PresetAllowAll           = "allow_all"
	PresetPrivateOnly        = "private_only"
	PresetGroupOnly          = "group_only"
	PresetGroupAndThreadOnly = "group_and_thread_only"
	PresetDenyAll            = "deny_all"
)
View Source
const (
	ActionChatTrigger = "chat.trigger"

	EffectAllow = "allow"
	EffectDeny  = "deny"
)

Variables

View Source
var (
	ErrInvalidRuleSubject = errors.New("invalid rule target")
	ErrInvalidSourceScope = errors.New("invalid source scope")
	ErrInvalidEffect      = errors.New("effect must be 'allow' or 'deny'")
)
View Source
var ErrUnknownPreset = errors.New("unknown acl preset")

Functions

func ApplyPreset

func ApplyPreset(ctx context.Context, queries dbstore.Queries, botID, createdByUserID, rawPreset string) error

func DefaultPresetKey

func DefaultPresetKey() string

func NormalizePresetKey

func NormalizePresetKey(raw string) string

Types

type ChannelIdentityCandidate

type ChannelIdentityCandidate struct {
	ID               string `json:"id"`
	Channel          string `json:"channel"`
	ChannelSubjectID string `json:"channel_subject_id"`
	DisplayName      string `json:"display_name,omitempty"`
	AvatarURL        string `json:"avatar_url,omitempty"`
}

type ChannelIdentityCandidateListResponse

type ChannelIdentityCandidateListResponse struct {
	Items []ChannelIdentityCandidate `json:"items"`
}

type CreateRuleRequest

type CreateRuleRequest struct {
	Enabled            bool         `json:"enabled"`
	Description        string       `json:"description,omitempty"`
	Effect             string       `json:"effect"`
	ChannelIdentityID  string       `json:"channel_identity_id,omitempty"`
	SubjectChannelType string       `json:"subject_channel_type,omitempty"`
	SourceScope        *SourceScope `json:"source_scope,omitempty"`
}

CreateRuleRequest is used to create a new ACL rule.

type DefaultEffectResponse

type DefaultEffectResponse struct {
	DefaultEffect string `json:"default_effect"`
}

type EvaluateRequest

type EvaluateRequest struct {
	BotID             string
	ChannelIdentityID string
	ChannelType       string
	SourceScope       SourceScope
}

EvaluateRequest carries all context needed to evaluate a chat.trigger.

type ListRulesResponse

type ListRulesResponse struct {
	Items []Rule `json:"items"`
}

type ManageOverride

type ManageOverride struct {
	ID                         string    `json:"id"`
	BotID                      string    `json:"bot_id"`
	ChannelIdentityID          string    `json:"channel_identity_id"`
	Granted                    bool      `json:"granted"`
	ChannelType                string    `json:"channel_type,omitempty"`
	ChannelSubjectID           string    `json:"channel_subject_id,omitempty"`
	ChannelIdentityDisplayName string    `json:"channel_identity_display_name,omitempty"`
	ChannelIdentityAvatarURL   string    `json:"channel_identity_avatar_url,omitempty"`
	CreatedAt                  time.Time `json:"created_at"`
}

ManageOverride is a local Channel Access override of the Manage capability for a channel identity on a bot. Granted=true forces ON, Granted=false forces OFF (suppressing an inherited grant). Absence of a row means "inherit".

type ObservedConversationCandidate

type ObservedConversationCandidate struct {
	RouteID               string    `json:"route_id"`
	Channel               string    `json:"channel"`
	ConversationType      string    `json:"conversation_type,omitempty"`
	ConversationID        string    `json:"conversation_id"`
	ThreadID              string    `json:"thread_id,omitempty"`
	ConversationName      string    `json:"conversation_name,omitempty"`
	ConversationAvatarURL string    `json:"conversation_avatar_url,omitempty"`
	LastObservedAt        time.Time `json:"last_observed_at"`
}

type ObservedConversationCandidateListResponse

type ObservedConversationCandidateListResponse struct {
	Items []ObservedConversationCandidate `json:"items"`
}

type Preset

type Preset struct {
	Key           string
	DefaultEffect string
	Rules         []CreateRuleRequest
}

func ResolvePreset

func ResolvePreset(raw string) (Preset, error)

type Rule

type Rule struct {
	ID                          string       `json:"id"`
	BotID                       string       `json:"bot_id"`
	Enabled                     bool         `json:"enabled"`
	Description                 string       `json:"description,omitempty"`
	Action                      string       `json:"action"`
	Effect                      string       `json:"effect"`
	ChannelIdentityID           string       `json:"channel_identity_id,omitempty"`
	SubjectChannelType          string       `json:"subject_channel_type,omitempty"`
	SourceScope                 *SourceScope `json:"source_scope,omitempty"`
	ChannelType                 string       `json:"channel_type,omitempty"`
	ChannelSubjectID            string       `json:"channel_subject_id,omitempty"`
	ChannelIdentityDisplayName  string       `json:"channel_identity_display_name,omitempty"`
	ChannelIdentityAvatarURL    string       `json:"channel_identity_avatar_url,omitempty"`
	SourceConversationName      string       `json:"source_conversation_name,omitempty"`
	SourceConversationAvatarURL string       `json:"source_conversation_avatar_url,omitempty"`
	CreatedAt                   time.Time    `json:"created_at"`
	UpdatedAt                   time.Time    `json:"updated_at"`
}

Rule is the full ACL rule record returned to callers.

type Service

type Service struct {
	// contains filtered or unexported fields
}

func NewService

func NewService(log *slog.Logger, queries dbstore.Queries) *Service

func (*Service) CreateRule

func (s *Service) CreateRule(ctx context.Context, botID, createdByUserID string, req CreateRuleRequest) (Rule, error)

CreateRule creates a new ACL rule.

func (*Service) DeleteManageOverride

func (s *Service) DeleteManageOverride(ctx context.Context, botID, channelIdentityID string) error

DeleteManageOverride removes a local Manage override, so the channel identity falls back to its inherited grant.

func (*Service) DeleteRule

func (s *Service) DeleteRule(ctx context.Context, ruleID string) error

DeleteRule removes an ACL rule by ID.

func (*Service) Evaluate

func (s *Service) Evaluate(ctx context.Context, req EvaluateRequest) (bool, error)

Evaluate checks whether the given request is allowed to perform chat.trigger. Rules only override the bot's default mode: deny rules matter in blacklist mode, and allow rules matter in whitelist mode.

func (*Service) GetDefaultEffect

func (s *Service) GetDefaultEffect(ctx context.Context, botID string) (string, error)

GetDefaultEffect returns the bot's fallback ACL effect.

func (*Service) GetManageOverride

func (s *Service) GetManageOverride(ctx context.Context, botID, channelIdentityID string) (granted bool, exists bool, err error)

GetManageOverride returns the local Manage override for a channel identity on a bot. exists reports whether a row is present; when false, granted is meaningless and callers should fall back to inheritance.

func (*Service) ListManageOverrides

func (s *Service) ListManageOverrides(ctx context.Context, botID string) ([]ManageOverride, error)

ListManageOverrides returns the local Manage overrides for a bot.

func (*Service) ListObservedConversationsByChannelIdentity

func (s *Service) ListObservedConversationsByChannelIdentity(ctx context.Context, botID, channelIdentityID string) ([]ObservedConversationCandidate, error)

ListObservedConversationsByChannelIdentity returns conversations observed for a specific channel identity under a bot, useful for building scoped rule source selectors.

func (*Service) ListObservedConversationsByChannelType

func (s *Service) ListObservedConversationsByChannelType(ctx context.Context, botID, channelType string) ([]ObservedConversationCandidate, error)

ListObservedConversationsByChannelType returns conversations observed on a platform type for this bot (any sender), for scoped rule building when subject is channel_type.

func (*Service) ListRules

func (s *Service) ListRules(ctx context.Context, botID string) ([]Rule, error)

ListRules returns all ACL rules for a bot, newest first.

func (*Service) SetDefaultEffect

func (s *Service) SetDefaultEffect(ctx context.Context, botID, effect string) error

SetDefaultEffect sets the bot's fallback ACL effect.

func (*Service) SetManageOverride

func (s *Service) SetManageOverride(ctx context.Context, botID, channelIdentityID string, granted bool, createdByUserID string) (ManageOverride, error)

SetManageOverride upserts a local Manage override (granted ON/OFF) for a channel identity on a bot.

func (*Service) UpdateRule

func (s *Service) UpdateRule(ctx context.Context, ruleID string, req UpdateRuleRequest) (Rule, error)

UpdateRule updates an existing ACL rule.

type SourceScope

type SourceScope struct {
	ConversationType string `json:"conversation_type,omitempty"`
	ConversationID   string `json:"conversation_id,omitempty"`
	ThreadID         string `json:"thread_id,omitempty"`
}

SourceScope narrows a rule to a specific conversation / thread. Any zero-value field means "match any". Channel filtering is handled at the rule target level.

func (SourceScope) IsZero

func (s SourceScope) IsZero() bool

func (SourceScope) Normalize

func (s SourceScope) Normalize() SourceScope

type UpdateRuleRequest

type UpdateRuleRequest struct {
	Enabled            bool         `json:"enabled"`
	Description        string       `json:"description,omitempty"`
	Effect             string       `json:"effect"`
	ChannelIdentityID  string       `json:"channel_identity_id,omitempty"`
	SubjectChannelType string       `json:"subject_channel_type,omitempty"`
	SourceScope        *SourceScope `json:"source_scope,omitempty"`
}

UpdateRuleRequest is used to update an existing ACL rule.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL