feat(interceptors): §9.4 service interceptors — thin KV allow/deny slice

Smallest honest vertical slice of §9.4: a `[[interceptors]]` block (app OR
group) binds a script to run BEFORE `kv::set`/`delete`; it reads the operation
context (`ctx.request.body`: service, action, collection, key, value, caller
ids) and returns `#{ allowed, reason }` — `allowed == false` denies the op (the
write never runs, the caller gets a runtime error).

Reuses two existing mechanisms rather than inventing new ones:
- Registration mirrors extension points (§5.5): a marker table
  `0073_interceptors.sql` (owner-polymorphic app_id/group_id XOR, keyed
  (service, op) → script), `interceptor_repo` (insert/delete/list + the
  nearest-owner-wins `resolve_before` chain walk), reconciled through the
  declarative apply exactly like `vars` (create/update/delete, prunable).
- Execution reuses the `invoke()` re-entry path: the new `InterceptorService`
  (shared trait + Postgres-backed impl) only RESOLVES the script name (keeping
  executor-core Postgres-free); the executor's `sdk::interceptor::run_before`
  resolves that name and runs it via `run_resolved_blocking` (extracted from
  `invoke_blocking` — shared depth bound + AST cache). An un-hooked write pays
  one indexed `Ok(None)` resolve; no interceptor ⇒ zero overhead.

Nearest-owner-wins so an app overrides a group's interceptor, and a group
interceptor is inherited by every descendant app — the chain walk is the
isolation boundary (a sibling subtree never matches). `validate_bundle_for`
restricts the MVP to `service = "kv"`, `op ∈ {set, delete}`, one marker per
(service, op).

Deferred (documented in §9.4): the `data` transform return, services other
than kv, `after_*` hooks, chaining + circular-dependency guard, the timeout
policy, and a `pic interceptors ls` read surface (needs a server route).

Pinned by `tests/interceptors.rs` (deny blocks the write; allow passes;
group→app inheritance), schema snapshot re-blessed. 154/154 journeys pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-13 20:44:50 +02:00
parent fcd9451ab1
commit 2fc9476f9e
24 changed files with 1015 additions and 45 deletions

View File

@@ -22,13 +22,13 @@ use std::sync::Arc;
use crate::{
DeadLetterService, DocsService, EmailService, FilesService, GroupDocsService,
GroupFilesService, GroupKvService, GroupPubsubService, GroupQueueService, HttpService,
InvokeService, KvService, ModuleSource, NoopDeadLetterService, NoopDocsService,
NoopEmailService, NoopEventEmitter, NoopFilesService, NoopGroupDocsService,
InterceptorService, InvokeService, KvService, ModuleSource, NoopDeadLetterService,
NoopDocsService, NoopEmailService, NoopEventEmitter, NoopFilesService, NoopGroupDocsService,
NoopGroupFilesService, NoopGroupKvService, NoopGroupPubsubService, NoopGroupQueueService,
NoopHttpService, NoopInvokeService, NoopKvService, NoopModuleSource, NoopPubsubService,
NoopQueueService, NoopSecretsService, NoopUsersService, NoopVarsService, NoopWorkflowService,
PubsubService, QueueService, SecretsService, ServiceEventEmitter, UsersService, VarsService,
WorkflowService,
NoopHttpService, NoopInterceptorService, NoopInvokeService, NoopKvService, NoopModuleSource,
NoopPubsubService, NoopQueueService, NoopSecretsService, NoopUsersService, NoopVarsService,
NoopWorkflowService, PubsubService, QueueService, SecretsService, ServiceEventEmitter,
UsersService, VarsService, WorkflowService,
};
/// SDK service bundle. See module docs for the lifecycle and the v1.1.x
@@ -152,6 +152,12 @@ pub struct Services {
/// run of a named workflow in the caller's app. Wired via
/// [`Services::with_workflow`]; defaults to `NoopWorkflowService`.
pub workflow: Arc<dyn WorkflowService>,
/// §9.4 Service Interceptors — resolves which (if any) interceptor script
/// guards a `(service, op)` before it runs. Wired via
/// [`Services::with_interceptors`]; defaults to `NoopInterceptorService`
/// (nothing intercepted).
pub interceptors: Arc<dyn InterceptorService>,
}
impl Services {
@@ -200,9 +206,18 @@ impl Services {
group_pubsub: Arc::new(NoopGroupPubsubService),
group_queue: Arc::new(NoopGroupQueueService),
workflow: Arc::new(NoopWorkflowService),
interceptors: Arc::new(NoopInterceptorService),
}
}
/// Set the §9.4 interceptor resolver (picloud binary wires the
/// Postgres-backed impl; tests leave the noop default = nothing hooked).
#[must_use]
pub fn with_interceptors(mut self, interceptors: Arc<dyn InterceptorService>) -> Self {
self.interceptors = interceptors;
self
}
/// Set the v1.2 Workflows service (picloud binary wires the Postgres-backed
/// impl; tests leave the noop default).
#[must_use]