Code Coverage |
||||||||||
Lines |
Functions and Methods |
Classes and Traits |
||||||||
| Total | |
63.64% |
7 / 11 |
|
50.00% |
1 / 2 |
CRAP | |
0.00% |
0 / 1 |
| Action | |
63.64% |
7 / 11 |
|
50.00% |
1 / 2 |
16.82 | |
0.00% |
0 / 1 |
| fromPermission | |
0.00% |
0 / 4 |
|
0.00% |
0 / 1 |
30 | |||
| permission | |
100.00% |
7 / 7 |
|
100.00% |
1 / 1 |
6 | |||
| 1 | <?php |
| 2 | |
| 3 | declare(strict_types=1); |
| 4 | |
| 5 | namespace LambdaTwelve\OneRecord\Server\Spi; |
| 6 | |
| 7 | use LambdaTwelve\OneRecord\Api\Permission; |
| 8 | |
| 9 | /** |
| 10 | * Everything an access policy may be asked about. The first four are the |
| 11 | * spec's permissions on a logistics object; the rest are the server's other |
| 12 | * decisions, including the two endpoints the spec marks "internal only". |
| 13 | */ |
| 14 | enum Action: string |
| 15 | { |
| 16 | case ReadLogisticsObject = 'GET_LOGISTICS_OBJECT'; |
| 17 | case ChangeLogisticsObject = 'PATCH_LOGISTICS_OBJECT'; |
| 18 | case PostLogisticsEvent = 'POST_LOGISTICS_EVENT'; |
| 19 | case ReadLogisticsEvent = 'GET_LOGISTICS_EVENT'; |
| 20 | |
| 21 | /** GET /logistics-objects/{id}/audit-trail: inherits from the object unless the host separates them. */ |
| 22 | case ReadAuditTrail = 'READ_AUDIT_TRAIL'; |
| 23 | |
| 24 | /** POST /logistics-objects: "internal only" per spec; denied unless the policy says otherwise. */ |
| 25 | case CreateLogisticsObject = 'CREATE_LOGISTICS_OBJECT'; |
| 26 | |
| 27 | /** PATCH /action-requests/{id}: the holder accepting or rejecting over HTTP; "internal only". */ |
| 28 | case DecideActionRequest = 'DECIDE_ACTION_REQUEST'; |
| 29 | |
| 30 | /** GET/HEAD /action-requests/{id} by someone other than its requestor. */ |
| 31 | case ReadActionRequest = 'READ_ACTION_REQUEST'; |
| 32 | |
| 33 | /** DELETE /action-requests/{id} by someone other than its requestor (the holder's side). */ |
| 34 | case RevokeActionRequest = 'REVOKE_ACTION_REQUEST'; |
| 35 | |
| 36 | public static function fromPermission(Permission $permission): self |
| 37 | { |
| 38 | return match ($permission) { |
| 39 | Permission::GetLogisticsObject => self::ReadLogisticsObject, |
| 40 | Permission::PatchLogisticsObject => self::ChangeLogisticsObject, |
| 41 | Permission::PostLogisticsEvent => self::PostLogisticsEvent, |
| 42 | Permission::GetLogisticsEvent => self::ReadLogisticsEvent, |
| 43 | }; |
| 44 | } |
| 45 | |
| 46 | public function permission(): ?Permission |
| 47 | { |
| 48 | return match ($this) { |
| 49 | self::ReadLogisticsObject => Permission::GetLogisticsObject, |
| 50 | self::ChangeLogisticsObject => Permission::PatchLogisticsObject, |
| 51 | self::PostLogisticsEvent => Permission::PostLogisticsEvent, |
| 52 | self::ReadLogisticsEvent => Permission::GetLogisticsEvent, |
| 53 | default => null, |
| 54 | }; |
| 55 | } |
| 56 | } |