refactor: 集中显式注入并归位凭据领域规则
This commit is contained in:
@@ -26,6 +26,8 @@ import (
|
||||
"slices"
|
||||
"strings"
|
||||
|
||||
credentialdomain "git.ddupan.top/panxiao81/ayatori/internal/database/domain/credential"
|
||||
|
||||
bao "github.com/openbao/openbao/api/v2"
|
||||
|
||||
"git.ddupan.top/panxiao81/ayatori/internal/database/application"
|
||||
@@ -80,33 +82,33 @@ func (c *Credentials) accepts(path string) bool {
|
||||
}
|
||||
|
||||
// Read 只读取调用方已确认关联的路径;成功读取不构成对既有凭据的自动认领。
|
||||
func (c *Credentials) Read(ctx context.Context, path string) (application.ApplicationCredential, error) {
|
||||
func (c *Credentials) Read(ctx context.Context, path string) (credentialdomain.ApplicationCredential, error) {
|
||||
secret, err := c.read(ctx, path)
|
||||
if err != nil {
|
||||
return application.ApplicationCredential{}, err
|
||||
return credentialdomain.ApplicationCredential{}, err
|
||||
}
|
||||
return application.ParseApplicationCredential(secret.Data)
|
||||
return credentialdomain.ParseApplicationCredential(secret.Data)
|
||||
}
|
||||
|
||||
// ReadConfirmed 读取最新值并核对已持久化的确认版本,不回退读取历史版本。
|
||||
// 确认后的删除或改写需要人工处理,不能因此重新生成密码。
|
||||
func (c *Credentials) ReadConfirmed(ctx context.Context, path string, version int64) (application.ApplicationCredential, error) {
|
||||
func (c *Credentials) ReadConfirmed(ctx context.Context, path string, version int64) (credentialdomain.ApplicationCredential, error) {
|
||||
if version < 1 {
|
||||
return application.ApplicationCredential{}, ErrConflict
|
||||
return credentialdomain.ApplicationCredential{}, ErrConflict
|
||||
}
|
||||
secret, err := c.read(ctx, path)
|
||||
if errors.Is(err, ErrNotFound) {
|
||||
return application.ApplicationCredential{}, ErrConflict
|
||||
return credentialdomain.ApplicationCredential{}, ErrConflict
|
||||
}
|
||||
if err != nil {
|
||||
return application.ApplicationCredential{}, err
|
||||
return credentialdomain.ApplicationCredential{}, err
|
||||
}
|
||||
if secret.VersionMetadata == nil || int64(secret.VersionMetadata.Version) != version {
|
||||
return application.ApplicationCredential{}, ErrConflict
|
||||
return credentialdomain.ApplicationCredential{}, ErrConflict
|
||||
}
|
||||
credential, err := application.ParseApplicationCredential(secret.Data)
|
||||
credential, err := credentialdomain.ParseApplicationCredential(secret.Data)
|
||||
if err != nil {
|
||||
return application.ApplicationCredential{}, ErrConflict
|
||||
return credentialdomain.ApplicationCredential{}, ErrConflict
|
||||
}
|
||||
return credential, nil
|
||||
}
|
||||
@@ -130,7 +132,7 @@ func (c *Credentials) read(ctx context.Context, path string) (*bao.KVSecret, err
|
||||
|
||||
// Create 只创建从未存在过的路径,并验证回读七键与提交值完全一致。
|
||||
// 任何不确定写入都不返回凭据;上层必须停止供应并持久化冲突,不能重新生成密码。
|
||||
func (c *Credentials) Create(ctx context.Context, path string, credential application.ApplicationCredential) error {
|
||||
func (c *Credentials) Create(ctx context.Context, path string, credential credentialdomain.ApplicationCredential) error {
|
||||
if !c.accepts(path) {
|
||||
return ErrInvalidLocation
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user