w4c-workflows-api/Services/Security/NodePermissionDecision.cs
2026-09-12 01:02:46 +03:00

24 lines
899 B
C#

namespace w4c_workflows.Services.Security;
/// <summary>
/// Result of checking one blueprint against the node permission policy. A denied
/// decision carries a stable <see cref="Code"/> (for failure routing and tests)
/// and a human-readable <see cref="Reason"/> for the run log and the authoring
/// UI.
/// </summary>
public sealed record NodePermissionDecision
{
public required bool Allowed { get; init; }
/// <summary>Stable machine code, e.g. <c>node_type_blocked</c>.</summary>
public string? Code { get; init; }
/// <summary>Human-readable explanation, safe to surface to the workflow author.</summary>
public string? Reason { get; init; }
public static NodePermissionDecision Permit() => new() { Allowed = true };
public static NodePermissionDecision Deny(string code, string reason)
=> new() { Allowed = false, Code = code, Reason = reason };
}