-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
-
44
-
45
-
46
-
47
-
48
-
49
-
50
-
51
-
52
-
53
-
54
-
55
-
56
-
57
-
58
-
59
-
60
-
61
-
62
-
63
-
64
-
65
-
66
-
67
-
68
-
69
-
70
-
71
-
72
-
73
-
74
-
75
-
76
-
77
-
78
-
79
-
80
-
81
-
82
-
83
-
84
-
85
-
86
-
87
-
88
-
89
-
90
-
91
-
92
-
93
-
94
-
95
-
96
-
97
-
98
-
99
-
100
-
101
-
102
-
103
-
104
-
105
-
106
-
107
-
108
-
109
-
110
-
111
-
112
-
113
-
114
-
115
-
116
-
117
-
118
-
119
-
120
-
121
-
122
-
123
-
124
-
125
-
126
-
127
-
128
-
129
-
130
-
131
-
132
-
133
-
134
-
135
-
136
-
137
-
138
-
139
-
140
-
141
-
142
-
143
-
144
-
145
-
146
-
147
-
148
-
149
-
150
-
151
-
152
-
153
-
154
-
155
-
156
-
157
-
158
-
159
-
160
-
161
-
162
-
163
-
164
-
165
-
166
-
167
-
168
-
169
-
170
-
171
-
172
-
173
-
174
-
175
-
176
-
177
-
178
-
179
-
180
-
181
// SPDX-FileCopyrightText: 2025 Shota FUJI <pockawoooh@gmail.com>
// SPDX-License-Identifier: AGPL-3.0-only
package workspace
import (
"crypto/rand"
"google.golang.org/protobuf/proto"
"pocka.jp/x/yamori/backend/crypto"
eventV1 "pocka.jp/x/yamori/proto/go/backend/events/v1"
workspaceEvent "pocka.jp/x/yamori/proto/go/backend/events/workspace/v1"
"pocka.jp/x/yamori/proto/go/backend/workspace/v1/types"
)
func GenerateAdminCreationPassword(password string) *eventV1.Event {
hash, salt := crypto.SaltAndHashPassword([]byte(password))
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_AdminCreationPasswordGenerated{
AdminCreationPasswordGenerated: &workspaceEvent.AdminCreationPasswordGenerated{
PasswordHash: hash,
PasswordSalt: salt,
},
},
},
},
}
}
func ExpireAdminCreationPassword() *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_AdminCreationPasswordExpired{
AdminCreationPasswordExpired: &workspaceEvent.AdminCreationPasswordExpired{},
},
},
},
}
}
func CreateUser(id string, name string, displayName string, keyID []byte) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_UserCreated{
UserCreated: &workspaceEvent.UserCreated{
Id: proto.String(id),
Name: proto.String(name),
DisplayName: proto.String(displayName),
KeyId: keyID,
},
},
},
},
}
}
func ConfigurePasswordLogin(userID string, password string) *eventV1.Event {
hash, salt := crypto.SaltAndHashPassword([]byte(password))
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_PasswordLoginConfigured{
PasswordLoginConfigured: &workspaceEvent.PasswordLoginConfigured{
UserId: proto.String(userID),
PasswordHash: hash,
PasswordSalt: salt,
},
},
},
},
}
}
func GrantAdminAccess(userID string) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_AdminAccessGranted{
AdminAccessGranted: &workspaceEvent.AdminAccessGranted{
UserId: proto.String(userID),
},
},
},
},
}
}
func ConfigureRandomLoginJwtSecret() *eventV1.Event {
secret := make([]byte, 48)
rand.Read(secret)
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_LoginJwtSecretConfigured{
LoginJwtSecretConfigured: &workspaceEvent.LoginJwtSecretConfigured{
Secret: secret,
},
},
},
},
}
}
func GrantPermission(userID string, permissions []types.Permission) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_UserPermissionsGranted{
UserPermissionsGranted: &workspaceEvent.UserPermissionsGranted{
UserId: proto.String(userID),
Permissions: permissions,
},
},
},
},
}
}
func RevokePermission(userID string, permissions []types.Permission) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_UserPermissionsRevoked{
UserPermissionsRevoked: &workspaceEvent.UserPermissionsRevoked{
UserId: proto.String(userID),
Permissions: permissions,
},
},
},
},
}
}
func ConfigureAbbreviations(abbr *workspaceEvent.AbbreviationsConfigured) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_AbbreviationsConfigured{
AbbreviationsConfigured: abbr,
},
},
},
}
}
func SetDisplayName(displayName string) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_WorkspaceDisplayNameSet{
WorkspaceDisplayNameSet: &workspaceEvent.WorkspaceDisplayNameSet{
DisplayName: proto.String(displayName),
},
},
},
},
}
}
func DefineCustomAttributeDefinition(id string, displayName string) *eventV1.Event {
return &eventV1.Event{
Event: &eventV1.Event_WorkspaceEvent{
WorkspaceEvent: &workspaceEvent.Event{
Event: &workspaceEvent.Event_CustomAttributeDefined{
CustomAttributeDefined: &workspaceEvent.CustomAttributeDefined{
Id: proto.String(id),
DisplayName: proto.String(displayName),
},
},
},
},
}
}