Parent directory

settings.go

2365 bytes
 1package backend
 2
 3import (
 4	"context"
 5
 6	"github.com/charmbracelet/soft-serve/pkg/access"
 7	"github.com/charmbracelet/soft-serve/pkg/db"
 8)
 9
10// AllowKeyless returns whether or not keyless access is allowed.
11//
12// If the server config sets AllowKeyless, that value always takes
13// precedence over the database — it is a live override, not a one-time
14// default, matching how InitialAdminKeys behaves. Do not cache this: a
15// memoized/TTL'd copy would delay an admin's `settings allow-keyless false`
16// from taking effect, which is a fail-open risk on an access-control check.
17//
18// It implements backend.Backend.
19func (b *Backend) AllowKeyless(ctx context.Context) bool {
20	if b.cfg.AllowKeyless != nil {
21		return *b.cfg.AllowKeyless
22	}
23
24	var allow bool
25	if err := b.db.TransactionContext(ctx, func(tx *db.Tx) error {
26		var err error
27		allow, err = b.store.GetAllowKeylessAccess(ctx, tx)
28		return err
29	}); err != nil {
30		return false
31	}
32
33	return allow
34}
35
36// SetAllowKeyless sets whether or not keyless access is allowed.
37//
38// It implements backend.Backend.
39func (b *Backend) SetAllowKeyless(ctx context.Context, allow bool) error {
40	return b.db.TransactionContext(ctx, func(tx *db.Tx) error {
41		return b.store.SetAllowKeylessAccess(ctx, tx, allow)
42	})
43}
44
45// AnonAccess returns the level of anonymous access.
46//
47// If the server config sets AnonAccess, that value always takes precedence
48// over the database — it is a live override, not a one-time default,
49// matching how InitialAdminKeys behaves. Do not cache this: a memoized/TTL'd
50// copy would delay an admin's `settings anon-access` change from taking
51// effect, which is a fail-open risk on an access-control check.
52//
53// It implements backend.Backend.
54func (b *Backend) AnonAccess(ctx context.Context) access.AccessLevel {
55	if b.cfg.AnonAccess != nil {
56		return *b.cfg.AnonAccess
57	}
58
59	var level access.AccessLevel
60	if err := b.db.TransactionContext(ctx, func(tx *db.Tx) error {
61		var err error
62		level, err = b.store.GetAnonAccess(ctx, tx)
63		return err
64	}); err != nil {
65		return access.NoAccess
66	}
67
68	return level
69}
70
71// SetAnonAccess sets the level of anonymous access.
72//
73// It implements backend.Backend.
74func (b *Backend) SetAnonAccess(ctx context.Context, level access.AccessLevel) error {
75	return b.db.TransactionContext(ctx, func(tx *db.Tx) error {
76		return b.store.SetAnonAccess(ctx, tx, level)
77	})
78}