settings.go
2365 bytes
1package backend
2
3import (
4 "context"
5
6 "github.com/charmbracelet/soft-serve/pkg/access"
7 "github.com/charmbracelet/soft-serve/pkg/db"
8)
9
10// AllowKeyless returns whether or not keyless access is allowed.
11//
12// If the server config sets AllowKeyless, that value always takes
13// precedence over the database — it is a live override, not a one-time
14// default, matching how InitialAdminKeys behaves. Do not cache this: a
15// memoized/TTL'd copy would delay an admin's `settings allow-keyless false`
16// from taking effect, which is a fail-open risk on an access-control check.
17//
18// It implements backend.Backend.
19func (b *Backend) AllowKeyless(ctx context.Context) bool {
20 if b.cfg.AllowKeyless != nil {
21 return *b.cfg.AllowKeyless
22 }
23
24 var allow bool
25 if err := b.db.TransactionContext(ctx, func(tx *db.Tx) error {
26 var err error
27 allow, err = b.store.GetAllowKeylessAccess(ctx, tx)
28 return err
29 }); err != nil {
30 return false
31 }
32
33 return allow
34}
35
36// SetAllowKeyless sets whether or not keyless access is allowed.
37//
38// It implements backend.Backend.
39func (b *Backend) SetAllowKeyless(ctx context.Context, allow bool) error {
40 return b.db.TransactionContext(ctx, func(tx *db.Tx) error {
41 return b.store.SetAllowKeylessAccess(ctx, tx, allow)
42 })
43}
44
45// AnonAccess returns the level of anonymous access.
46//
47// If the server config sets AnonAccess, that value always takes precedence
48// over the database — it is a live override, not a one-time default,
49// matching how InitialAdminKeys behaves. Do not cache this: a memoized/TTL'd
50// copy would delay an admin's `settings anon-access` change from taking
51// effect, which is a fail-open risk on an access-control check.
52//
53// It implements backend.Backend.
54func (b *Backend) AnonAccess(ctx context.Context) access.AccessLevel {
55 if b.cfg.AnonAccess != nil {
56 return *b.cfg.AnonAccess
57 }
58
59 var level access.AccessLevel
60 if err := b.db.TransactionContext(ctx, func(tx *db.Tx) error {
61 var err error
62 level, err = b.store.GetAnonAccess(ctx, tx)
63 return err
64 }); err != nil {
65 return access.NoAccess
66 }
67
68 return level
69}
70
71// SetAnonAccess sets the level of anonymous access.
72//
73// It implements backend.Backend.
74func (b *Backend) SetAnonAccess(ctx context.Context, level access.AccessLevel) error {
75 return b.db.TransactionContext(ctx, func(tx *db.Tx) error {
76 return b.store.SetAnonAccess(ctx, tx, level)
77 })
78}