fix(manager-core): F-Q-003 promote authz::script_gate helper, migrate 7 service call sites
Replace nine open-coded `if cx.principal.is_some() {
authz::require(...).await.map_err(...) }` blocks with a single
`authz::script_gate(repo, cx, cap, forbidden_fn, backend_fn)` helper.
The helper enshrines the script-as-gate semantics (anonymous public-
HTTP scripts skip the check) and the AuthzDenied::{Denied,Repo}
mapping in one place — eliminating drift between services.
Call sites migrated:
- kv_service::check_read / check_write
- docs_service::check_read / check_write
- files_service::check_read / check_write
- pubsub_service::check_publish
- queue_service::enqueue
The pubsub_service::mint_subscriber_token path keeps the explicit
match because it does a separate `principal` early-bind for other
validation; converting it would obscure intent.
AUDIT.md anchor: F-Q-003. Depends on F-Q-004 (Backend variant) and
F-Q-005 (Repo-passthrough pattern).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -55,27 +55,25 @@ impl DocsServiceImpl {
|
||||
}
|
||||
|
||||
async fn check_read(&self, cx: &SdkCallCx) -> Result<(), DocsError> {
|
||||
if let Some(ref principal) = cx.principal {
|
||||
match authz::require(&*self.authz, principal, Capability::AppDocsRead(cx.app_id)).await
|
||||
{
|
||||
Ok(()) => {}
|
||||
Err(authz::AuthzDenied::Denied) => return Err(DocsError::Forbidden),
|
||||
Err(authz::AuthzDenied::Repo(e)) => return Err(DocsError::Backend(e.to_string())),
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
authz::script_gate(
|
||||
&*self.authz,
|
||||
cx,
|
||||
Capability::AppDocsRead(cx.app_id),
|
||||
|| DocsError::Forbidden,
|
||||
DocsError::Backend,
|
||||
)
|
||||
.await
|
||||
}
|
||||
|
||||
async fn check_write(&self, cx: &SdkCallCx) -> Result<(), DocsError> {
|
||||
if let Some(ref principal) = cx.principal {
|
||||
match authz::require(&*self.authz, principal, Capability::AppDocsWrite(cx.app_id)).await
|
||||
{
|
||||
Ok(()) => {}
|
||||
Err(authz::AuthzDenied::Denied) => return Err(DocsError::Forbidden),
|
||||
Err(authz::AuthzDenied::Repo(e)) => return Err(DocsError::Backend(e.to_string())),
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
authz::script_gate(
|
||||
&*self.authz,
|
||||
cx,
|
||||
Capability::AppDocsWrite(cx.app_id),
|
||||
|| DocsError::Forbidden,
|
||||
DocsError::Backend,
|
||||
)
|
||||
.await
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user