Phase 4-lite C2. Lets a group own scripts (templates inherited by descendant
apps), with the create/list/manage surface — but not yet the inherited
resolution (binding + runtime), which is C3.
Capabilities: add `GroupScriptsRead` (viewer+ on the group → script:read) and
`GroupScriptsWrite` (editor+ → script:write), mirroring the group-vars tier and
resolved through the same group-ancestor walk.
API:
* New `group_scripts_api`: `POST/GET /groups/{id}/scripts` — create a
group-owned endpoint script and list a group's own (non-inherited) rows.
Phase 4-lite is endpoint-only and self-contained: `kind=module` and any
`import` are rejected (group modules + the lexical resolver are Phase 4b).
Owner resolved first (slug-or-uuid); capability bound to the resolved id.
* The by-id `/scripts/{id}` get/update/delete/logs handlers are now
owner-polymorphic via a `script_cap` helper: app-owned scripts gate on
`App*` exactly as before; group-owned on `GroupScripts*`. This is what
makes `deploy --group` idempotent (update reuses the by-id PUT) and lets a
group script be deleted by id. (C1 had these fail closed for groups.)
Repo: `list_for_group(group_id)` (the group's own rows).
CLI: `pic scripts ls --group <g>`, `pic scripts deploy --group <g>` (create or
update by name; `--app`/`--group` are mutually exclusive, exactly one
required). `pic scripts delete <id>` already works for group scripts via the
owner-polymorphic by-id route.
Live-validated against the dev DB: create → update (v2 via the by-id PUT) →
list → delete, plus module rejection and the polymorphic row shape
(`app_id NULL`, `group_id` set). Group scripts still can't be routed/triggered
or invoked — that lands in C3.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
107 lines
4.0 KiB
Rust
107 lines
4.0 KiB
Rust
//! Cross-cutting types used by every PiCloud crate.
|
|
//!
|
|
//! Keep this crate small. If something only one core needs, it belongs in
|
|
//! that core's crate. Things here must be genuinely shared (IDs, the Script
|
|
//! entity, error roots, transport DTOs).
|
|
|
|
pub mod app;
|
|
pub mod auth;
|
|
pub mod crypto;
|
|
pub mod dead_letters;
|
|
pub mod docs;
|
|
pub mod email;
|
|
pub mod error;
|
|
pub mod events;
|
|
pub mod exec_summary;
|
|
pub mod execution_log;
|
|
pub mod files;
|
|
pub mod group;
|
|
pub mod http;
|
|
pub mod ids;
|
|
pub mod inbox;
|
|
pub mod invoke;
|
|
pub mod kv;
|
|
pub mod log_sink;
|
|
pub mod modules;
|
|
pub mod outbox_writer;
|
|
pub mod pubsub;
|
|
pub mod queue;
|
|
pub mod realtime;
|
|
pub mod realtime_authority;
|
|
pub mod route;
|
|
pub mod sandbox;
|
|
pub mod script;
|
|
pub mod sdk_cx;
|
|
pub mod secrets;
|
|
pub mod services;
|
|
pub mod subscriber_token;
|
|
pub mod trigger_event;
|
|
pub mod users;
|
|
pub mod validator;
|
|
pub mod vars;
|
|
pub mod version;
|
|
|
|
/// serde `default` for `enabled`-style boolean fields that should default to
|
|
/// `true` when absent from the wire (bool's own `Default` is `false`). Shared
|
|
/// by `Script`/`Route`, the apply `Bundle` types, and the CLI manifest.
|
|
#[must_use]
|
|
pub fn default_true() -> bool {
|
|
true
|
|
}
|
|
|
|
pub use app::{App, AppDomain, DomainShape};
|
|
pub use auth::{AppRole, InstanceRole, Principal, Scope, UserId};
|
|
pub use crypto::{decrypt, encrypt, CryptoError, EncryptResult, MasterKey, MasterKeyError};
|
|
pub use dead_letters::{DeadLetterError, DeadLetterId, DeadLetterService, NoopDeadLetterService};
|
|
pub use docs::{DocId, DocRow, DocsError, DocsListPage, DocsService, NoopDocsService};
|
|
pub use email::{EmailError, EmailService, NoopEmailService, OutboundEmail};
|
|
pub use error::Error;
|
|
pub use events::{EmitError, NoopEventEmitter, ServiceEvent, ServiceEventEmitter};
|
|
pub use exec_summary::ExecResponseSummary;
|
|
pub use execution_log::{ExecutionLog, ExecutionSource, ExecutionStatus};
|
|
pub use files::{
|
|
sanitize_stored_content_type, validate_collection as validate_files_collection, FileMeta,
|
|
FileUpdate, FilesError, FilesListPage, FilesService, NewFile, NoopFilesService,
|
|
SAFE_RENDER_FALLBACK,
|
|
};
|
|
pub use group::Group;
|
|
pub use http::{HttpError, HttpRequest, HttpResponse, HttpService, NoopHttpService};
|
|
pub use ids::{
|
|
AdminUserId, ApiKeyId, AppId, AppUserId, ExecutionId, GroupId, InvitationId, QueueMessageId,
|
|
RequestId, ScriptId, TriggerId,
|
|
};
|
|
pub use inbox::{
|
|
InboxDeliveryOutcome, InboxFailureKind, InboxResolver, InboxResult, NoopInboxResolver,
|
|
};
|
|
pub use invoke::{InvokeError, InvokeService, InvokeTarget, NoopInvokeService, ResolvedScript};
|
|
pub use kv::{KvError, KvListPage, KvService, NoopKvService};
|
|
pub use log_sink::{ExecutionLogSink, LogSinkError};
|
|
pub use modules::{ModuleScript, ModuleSource, ModuleSourceError, NoopModuleSource};
|
|
pub use outbox_writer::{HttpDispatchPayload, NewHttpOutbox, OutboxWriter, OutboxWriterError};
|
|
pub use pubsub::{
|
|
topic_matches, validate_topic_pattern, NoopPubsubService, PubsubError, PubsubService,
|
|
};
|
|
pub use queue::{EnqueueOpts, NoopQueueService, QueueError, QueueService};
|
|
pub use realtime::{BroadcasterError, NoopRealtimeBroadcaster, RealtimeBroadcaster, RealtimeEvent};
|
|
pub use realtime_authority::{DenyAllRealtimeAuthority, RealtimeAuthority, SubscribeDenied};
|
|
pub use route::{DispatchMode, HostKind, PathKind, Route};
|
|
pub use sandbox::ScriptSandbox;
|
|
pub use script::{Script, ScriptKind, ScriptOwner};
|
|
pub use sdk_cx::SdkCallCx;
|
|
pub use secrets::{
|
|
validate_secret_name, NoopSecretsService, SecretsError, SecretsListPage, SecretsService,
|
|
SECRET_NAME_MAX_BYTES,
|
|
};
|
|
pub use services::Services;
|
|
pub use trigger_event::{
|
|
DeadLetterEventDetail, DocsEventOp, FilesEventOp, KvEventOp, TriggerEvent,
|
|
};
|
|
pub use users::{
|
|
AppUser, CreateUserInput, EmailTemplateOpts, GeneratedAccept, GeneratedSession, Invitation,
|
|
InviteOpts, NoopUsersService, UpdateUserInput, UsersError, UsersListOpts, UsersListPage,
|
|
UsersService,
|
|
};
|
|
pub use validator::{ScriptValidator, ValidatedScript, ValidationError};
|
|
pub use vars::{NoopVarsService, VarsError, VarsService};
|
|
pub use version::{API_VERSION, PRODUCT_VERSION, SDK_VERSION, WIRE_VERSION};
|