Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
63.64% covered (warning)
63.64%
7 / 11
50.00% covered (danger)
50.00%
1 / 2
CRAP
0.00% covered (danger)
0.00%
0 / 1
Action
63.64% covered (warning)
63.64%
7 / 11
50.00% covered (danger)
50.00%
1 / 2
16.82
0.00% covered (danger)
0.00%
0 / 1
 fromPermission
0.00% covered (danger)
0.00%
0 / 4
0.00% covered (danger)
0.00%
0 / 1
30
 permission
100.00% covered (success)
100.00%
7 / 7
100.00% covered (success)
100.00%
1 / 1
6
1<?php
2
3declare(strict_types=1);
4
5namespace LambdaTwelve\OneRecord\Server\Spi;
6
7use LambdaTwelve\OneRecord\Api\Permission;
8
9/**
10 * Everything an access policy may be asked about. The first four are the
11 * spec's permissions on a logistics object; the rest are the server's other
12 * decisions, including the two endpoints the spec marks "internal only".
13 */
14enum Action: string
15{
16    case ReadLogisticsObject = 'GET_LOGISTICS_OBJECT';
17    case ChangeLogisticsObject = 'PATCH_LOGISTICS_OBJECT';
18    case PostLogisticsEvent = 'POST_LOGISTICS_EVENT';
19    case ReadLogisticsEvent = 'GET_LOGISTICS_EVENT';
20
21    /** GET /logistics-objects/{id}/audit-trail: inherits from the object unless the host separates them. */
22    case ReadAuditTrail = 'READ_AUDIT_TRAIL';
23
24    /** POST /logistics-objects: "internal only" per spec; denied unless the policy says otherwise. */
25    case CreateLogisticsObject = 'CREATE_LOGISTICS_OBJECT';
26
27    /** PATCH /action-requests/{id}: the holder accepting or rejecting over HTTP; "internal only". */
28    case DecideActionRequest = 'DECIDE_ACTION_REQUEST';
29
30    /** GET/HEAD /action-requests/{id} by someone other than its requestor. */
31    case ReadActionRequest = 'READ_ACTION_REQUEST';
32
33    /** DELETE /action-requests/{id} by someone other than its requestor (the holder's side). */
34    case RevokeActionRequest = 'REVOKE_ACTION_REQUEST';
35
36    public static function fromPermission(Permission $permission): self
37    {
38        return match ($permission) {
39            Permission::GetLogisticsObject => self::ReadLogisticsObject,
40            Permission::PatchLogisticsObject => self::ChangeLogisticsObject,
41            Permission::PostLogisticsEvent => self::PostLogisticsEvent,
42            Permission::GetLogisticsEvent => self::ReadLogisticsEvent,
43        };
44    }
45
46    public function permission(): ?Permission
47    {
48        return match ($this) {
49            self::ReadLogisticsObject => Permission::GetLogisticsObject,
50            self::ChangeLogisticsObject => Permission::PatchLogisticsObject,
51            self::PostLogisticsEvent => Permission::PostLogisticsEvent,
52            self::ReadLogisticsEvent => Permission::GetLogisticsEvent,
53            default => null,
54        };
55    }
56}