Smallest honest vertical slice of §9.4: a `[[interceptors]]` block (app OR
group) binds a script to run BEFORE `kv::set`/`delete`; it reads the operation
context (`ctx.request.body`: service, action, collection, key, value, caller
ids) and returns `#{ allowed, reason }` — `allowed == false` denies the op (the
write never runs, the caller gets a runtime error).
Reuses two existing mechanisms rather than inventing new ones:
- Registration mirrors extension points (§5.5): a marker table
`0073_interceptors.sql` (owner-polymorphic app_id/group_id XOR, keyed
(service, op) → script), `interceptor_repo` (insert/delete/list + the
nearest-owner-wins `resolve_before` chain walk), reconciled through the
declarative apply exactly like `vars` (create/update/delete, prunable).
- Execution reuses the `invoke()` re-entry path: the new `InterceptorService`
(shared trait + Postgres-backed impl) only RESOLVES the script name (keeping
executor-core Postgres-free); the executor's `sdk::interceptor::run_before`
resolves that name and runs it via `run_resolved_blocking` (extracted from
`invoke_blocking` — shared depth bound + AST cache). An un-hooked write pays
one indexed `Ok(None)` resolve; no interceptor ⇒ zero overhead.
Nearest-owner-wins so an app overrides a group's interceptor, and a group
interceptor is inherited by every descendant app — the chain walk is the
isolation boundary (a sibling subtree never matches). `validate_bundle_for`
restricts the MVP to `service = "kv"`, `op ∈ {set, delete}`, one marker per
(service, op).
Deferred (documented in §9.4): the `data` transform return, services other
than kv, `after_*` hooks, chaining + circular-dependency guard, the timeout
policy, and a `pic interceptors ls` read surface (needs a server route).
Pinned by `tests/interceptors.rs` (deny blocks the write; allow passes;
group→app inheritance), schema snapshot re-blessed. 154/154 journeys pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
74 lines
2.5 KiB
Rust
74 lines
2.5 KiB
Rust
//! SDK plumbing — types and the per-call registration entry point.
|
|
//!
|
|
//! `executor-core` is responsible for building the per-invocation Rhai
|
|
//! engine and wiring stateful services into it. v1.1.0 ships the
|
|
//! shapes (`Services` bundle, `SdkCallCx`, `register_all` entry point)
|
|
//! but no actual services — subsequent v1.1.x PRs (KV in v1.1.1,
|
|
//! docs in v1.1.2, …) extend `register_all` rather than re-threading
|
|
//! plumbing through `engine.rs`.
|
|
//!
|
|
//! Bridge functions (`json_to_dynamic` / `dynamic_to_json`) also live
|
|
//! here so service modules can convert values without `engine.rs`
|
|
//! being the only home for the conversion logic.
|
|
|
|
pub mod bridge;
|
|
pub mod cx;
|
|
pub mod dead_letters;
|
|
pub mod docs;
|
|
pub mod email;
|
|
pub mod files;
|
|
pub mod http;
|
|
pub mod interceptor;
|
|
pub mod invoke;
|
|
pub mod kv;
|
|
pub mod pubsub;
|
|
pub mod queue;
|
|
pub mod retry;
|
|
pub mod secrets;
|
|
pub mod stdlib;
|
|
pub mod users;
|
|
pub mod vars;
|
|
pub mod workflow;
|
|
|
|
pub use bridge::{dynamic_to_json, json_to_dynamic};
|
|
pub use cx::SdkCallCx;
|
|
|
|
use std::sync::Arc;
|
|
|
|
use picloud_shared::Services;
|
|
use rhai::Engine as RhaiEngine;
|
|
|
|
use crate::engine::Engine;
|
|
use crate::sandbox::Limits;
|
|
|
|
/// Single hook every v1.1.x stateful service registers into. Called
|
|
/// once per invocation, just after `build_engine` constructs the
|
|
/// sandboxed Rhai engine and just before script compilation.
|
|
///
|
|
/// v1.1.9 adds the `limits` + `self_engine` parameters needed by the
|
|
/// `invoke` bridge for synchronous re-entry. `self_engine` is `None`
|
|
/// in harnesses that didn't call `Engine::set_self_weak` after
|
|
/// construction; the invoke bridge surfaces a clear error in that case.
|
|
pub fn register_all(
|
|
engine: &mut RhaiEngine,
|
|
services: &Services,
|
|
cx: Arc<SdkCallCx>,
|
|
limits: Limits,
|
|
self_engine: Option<Arc<Engine>>,
|
|
) {
|
|
kv::register(engine, services, cx.clone(), limits, self_engine.clone());
|
|
docs::register(engine, services, cx.clone());
|
|
dead_letters::register(engine, services, cx.clone());
|
|
http::register(engine, services, cx.clone());
|
|
files::register(engine, services, cx.clone());
|
|
pubsub::register(engine, services, cx.clone());
|
|
queue::register(engine, services, cx.clone());
|
|
retry::register(engine, services, cx.clone());
|
|
secrets::register(engine, services, cx.clone());
|
|
vars::register(engine, services, cx.clone());
|
|
email::register(engine, services, cx.clone());
|
|
users::register(engine, services, cx.clone());
|
|
workflow::register(engine, services, cx.clone());
|
|
invoke::register(engine, services, cx, limits, self_engine);
|
|
}
|