This repository has been archived on 2026-04-03. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
core/server/store/extension_perm_iface.go
Jeffrey Smith 680ec3b897
All checks were successful
CI/CD / detect-changes (push) Successful in 3s
CI/CD / test-frontend (push) Successful in 5s
CI/CD / test-go-pg (push) Successful in 2m34s
CI/CD / test-sqlite (push) Successful in 2m46s
CI/CD / build-and-deploy (push) Successful in 1m55s
Feat rebrand armature (#43)
Co-authored-by: Jeffrey Smith <jasafpro@gmail.com>
Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
2026-03-31 23:25:37 +00:00

37 lines
1.4 KiB
Go

package store
import (
"context"
"armature/models"
)
// ExtensionPermissionStore manages declared and granted permissions for packages.
type ExtensionPermissionStore interface {
// DeclareForPackage upserts the declared permissions from a manifest.
// Any permissions in the DB for this package that are NOT in the
// provided list are deleted (manifest is the source of truth).
// Existing grants are preserved on upsert.
DeclareForPackage(ctx context.Context, packageID string, permissions []string) error
// ListForPackage returns all declared permissions for a package.
ListForPackage(ctx context.Context, packageID string) ([]models.ExtensionPermission, error)
// GrantedForPackage returns only granted permissions for a package.
// Used at runtime to determine which modules to inject.
GrantedForPackage(ctx context.Context, packageID string) ([]string, error)
// Grant marks a permission as granted by an admin.
Grant(ctx context.Context, packageID, permission, grantedBy string) error
// Revoke removes a grant (sets granted=false).
Revoke(ctx context.Context, packageID, permission string) error
// GrantAll grants all declared permissions for a package.
GrantAll(ctx context.Context, packageID, grantedBy string) error
// DeleteForPackage removes all permission rows for a package.
// Called when a package is uninstalled.
DeleteForPackage(ctx context.Context, packageID string) error
}