producedview

package
v1.140.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package producedview holds the read-side views over the producer relation (#1569): what one script has produced, and which script producers still exist.

The relation in internal/producedby is deliberately keyless in both directions -- no foreign key to scripts, to portal assets or to resources -- so that deleting any of them leaves the record of what wrote what standing. The cost of that is exactly what this package pays: a row names an id, and a surface that wants to display it has to resolve that id against what exists now, and be able to say when nothing does.

It sits apart from the surfaces that render it because both ends need it and they live in different places: the file end is served by the portal's producer routes, the script end beside the script routes.

Index

Constants

View Source
const (
	TargetAsset      = producedby.TargetAsset
	TargetCollection = producedby.TargetCollection
	TargetResource   = producedby.TargetResource
)

The kinds an Item's TargetKind takes, as the relation records them. They are restated here so a surface that renders items reads the vocabulary from the view it reads the items from.

Variables

This section is empty.

Functions

func SharedWith added in v1.140.0

func SharedWith(shares portaldomain.ShareStore) func(ctx context.Context, asset *portaldomain.Asset, userID, email string) bool

SharedWith reports whether an asset is shared with a person, directly or through a collection holding it, as the portal opens it; nil when the deployment keeps no shares. Asset fetch reads it for a person (#2027).

Types

type Access added in v1.140.0

type Access struct {
	// contains filtered or unexported fields
}

Access decides which produced files a reader may open, by the rules the file's own surfaces apply: an asset to its owner, an administrator and the people it or a collection holding it is shared with; a collection to its owner, an administrator and its share recipients; a resource by the resource scopes (resource.CanAccessResource). The portal and fetch name a script's outputs through it, so the two cannot disagree about what one reader is shown.

func NewAccess added in v1.140.0

func NewAccess(assets AssetGetter, collections CollectionNames, shares portaldomain.ShareStore, resources ResourceNames) *Access

NewAccess builds the rules over the stores files resolve through. Any store may be nil; a file of a kind with no store opens for no one.

func (*Access) For added in v1.140.0

func (a *Access) For(v Viewer) Opener

For returns the Opener for one reader.

type AssetGetter added in v1.140.0

type AssetGetter interface {
	Get(ctx context.Context, id string) (*portaldomain.Asset, error)
}

AssetGetter resolves one asset id to its record.

type AssetNames

type AssetNames interface {
	GetByIDs(ctx context.Context, ids []string) (map[string]*portaldomain.Asset, error)
}

AssetNames resolves asset ids to the assets they name, in one read.

type CollectionNames added in v1.129.0

type CollectionNames interface {
	Get(ctx context.Context, id string) (*portaldomain.Collection, error)
}

CollectionNames resolves one collection id to its record. The store answers a missing id with an error wrapping sql.ErrNoRows and a removed one with a record carrying its deletion time; both read as gone here.

type Item

type Item struct {
	// TargetKind is TargetAsset, TargetCollection or TargetResource; TargetID
	// is the id within that kind.
	TargetKind string `json:"target_kind"`
	TargetID   string `json:"target_id"`
	// Name is what the file is called now, empty when it no longer exists.
	Name string `json:"name,omitempty"`
	// OwnerEmail is the address the file's row records as its owner, for an
	// asset or a collection. It is what says whether the script's owner can
	// reach the file: a transfer moves the script and, unless it was asked to,
	// leaves the address on every file the script wrote as it was (#1588).
	// Empty for a resource, which is filed by library rather than by address,
	// and for a file that no longer exists.
	OwnerEmail string `json:"owner_email,omitempty"`
	// Created marks a file this producer brought into existence, as against one
	// it has only changed since.
	Created      bool      `json:"created"`
	FirstWriteAt time.Time `json:"first_write_at"`
	LastWriteAt  time.Time `json:"last_write_at"`
	WriteCount   int       `json:"write_count"`
	// LastVersion is the file version this producer last wrote, or zero for a
	// file whose kind does not number its writes.
	LastVersion int `json:"last_version"`
	// Deleted reports a file that has since been removed. The row stays: that
	// this producer wrote it is still true, and somebody deciding whether to
	// retire a script needs to see what it wrote that is already gone.
	Deleted bool `json:"deleted,omitempty"`
}

Item is one file a producer has produced or modified.

type Opener added in v1.140.0

type Opener interface {
	CanOpen(ctx context.Context, it Item) bool
}

Opener answers whether one reader may open a file a script produced. Each surface brings its own: the portal's share graph for a person in the portal, the same rules fetch applies for a caller over MCP.

type Produced added in v1.140.0

type Produced struct {
	// Open are the files the reader can open, named.
	Open []Item
	// Hidden counts the others, which are not named.
	Hidden int
	// More is true when the script wrote more files than limit, which are
	// neither listed nor counted.
	More bool
}

Produced is what one script produced as one reader may see it, among the limit files it wrote most recently.

type Reader

type Reader struct {
	// contains filtered or unexported fields
}

Reader composes the producer relation with what the ids in it resolve to now.

Every collaborator is optional. A deployment with no asset store leaves an asset row unnamed rather than unlisted: that this script wrote something is the fact the list exists to report, and not being able to say what it is called is a smaller loss than dropping the row.

func New

func New(producers producedby.Store, assets AssetNames, resources ResourceNames, collections CollectionNames, scripts ScriptLookup) *Reader

New builds the reader, or nil when there is no producer record to read.

func (*Reader) Names

func (r *Reader) Names(ctx context.Context, ids []string) (map[string]string, error)

Names resolves script ids to the names those scripts carry now. An id absent from the result is a script that no longer exists.

A lookup that fails is reported as an error rather than as a missing script: a database that is briefly unavailable must not make every producer read as deleted.

func (*Reader) Produced

func (r *Reader) Produced(ctx context.Context, scriptID string, limit int) ([]Item, error)

Produced lists everything one script has produced or modified, most recently written first.

func (*Reader) ProducedFor added in v1.140.0

func (r *Reader) ProducedFor(ctx context.Context, scriptID string, limit int, o Opener) (Produced, error)

ProducedFor lists what one script produced as one reader may see it (#2027): the files the reader can open, named, and how many others there are, counted and not named, the rule the reference Used-by panels follow (#1475). A file since deleted is neither listed nor counted. The script's definition is everyone's to read; what its runs wrote is not, so a reader never learns the name of an asset that was not shared with them.

type ResourceNames

type ResourceNames interface {
	Get(ctx context.Context, id string) (*resource.Resource, error)
}

ResourceNames resolves one resource id to its record.

type ScriptLookup

type ScriptLookup interface {
	GetByID(ctx context.Context, id string) (*script.Script, error)
}

ScriptLookup resolves one script id to its record. A nil record with a nil error is the store's not-found contract and means the script is gone.

type Viewer added in v1.140.0

type Viewer struct {
	UserID string
	Email  string
	// Admin is whether the reader administers the platform, which opens every
	// asset and collection.
	Admin bool
	// Claims are the reader's resource claims (resource.BuildClaims).
	Claims resource.Claims
	// Unattended is a managed-script run reading for the person it acts for:
	// it opens that person's own files and inherits neither the share graph
	// nor an administrator's reach.
	Unattended bool
}

Viewer is the reader a file is judged for.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL