Some checks failed
Main Confidence / confidence (push) Failing after 57s
## Summary - add the provider boundary catalog, boundary support types, and guardrails for platform-core versus provider-owned seams - harden provider gateway, identity resolution, operation registry, and start-gate behavior to require explicit provider bindings - add unit and feature coverage for boundary classification, runtime preservation, unsupported paths, and platform-core leakage guards - add the full Spec Kit artifact set for spec 237 and update roadmap/spec-candidate tracking ## Validation - `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Unit/Providers/ProviderBoundaryClassificationTest.php tests/Unit/Providers/ProviderBoundaryGuardrailTest.php tests/Feature/Providers/ProviderBoundaryHardeningTest.php tests/Feature/Providers/UnsupportedProviderBoundaryPathTest.php tests/Feature/Guards/ProviderBoundaryPlatformCoreGuardTest.php` - `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Unit/Providers/ProviderGatewayTest.php tests/Unit/Providers/ProviderIdentityResolverTest.php tests/Unit/Providers/ProviderOperationStartGateTest.php` - `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent` - browser smoke: `http://localhost/admin/provider-connections?tenant_id=18000000-0000-4000-8000-000000000180` loaded with the local smoke user, the empty-state CTA reached the canonical create route, and cancel returned to the scoped list Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de> Reviewed-on: #273
72 lines
2.6 KiB
PHP
72 lines
2.6 KiB
PHP
<?php
|
|
|
|
namespace App\Services\Providers;
|
|
|
|
use App\Models\ProviderConnection;
|
|
use App\Services\Graph\GraphClientInterface;
|
|
use App\Services\Graph\GraphResponse;
|
|
use Illuminate\Support\Str;
|
|
use RuntimeException;
|
|
|
|
final class ProviderGateway
|
|
{
|
|
public function __construct(
|
|
private readonly GraphClientInterface $graph,
|
|
private readonly ProviderIdentityResolver $identityResolver,
|
|
) {}
|
|
|
|
public function getOrganization(ProviderConnection $connection): GraphResponse
|
|
{
|
|
return $this->graph->getOrganization($this->graphOptions($connection));
|
|
}
|
|
|
|
public function getPolicy(ProviderConnection $connection, string $policyType, string $policyId, array $options = []): GraphResponse
|
|
{
|
|
return $this->graph->getPolicy($policyType, $policyId, $this->graphOptions($connection, $options));
|
|
}
|
|
|
|
public function listPolicies(ProviderConnection $connection, string $policyType, array $options = []): GraphResponse
|
|
{
|
|
return $this->graph->listPolicies($policyType, $this->graphOptions($connection, $options));
|
|
}
|
|
|
|
public function applyPolicy(
|
|
ProviderConnection $connection,
|
|
string $policyType,
|
|
string $policyId,
|
|
array $payload,
|
|
array $options = [],
|
|
): GraphResponse {
|
|
return $this->graph->applyPolicy($policyType, $policyId, $payload, $this->graphOptions($connection, $options));
|
|
}
|
|
|
|
public function getServicePrincipalPermissions(ProviderConnection $connection, array $options = []): GraphResponse
|
|
{
|
|
return $this->graph->getServicePrincipalPermissions($this->graphOptions($connection, $options));
|
|
}
|
|
|
|
public function request(ProviderConnection $connection, string $method, string $path, array $options = []): GraphResponse
|
|
{
|
|
return $this->graph->request($method, $path, $this->graphOptions($connection, $options));
|
|
}
|
|
|
|
/**
|
|
* @return array<string, mixed>
|
|
*/
|
|
public function graphOptions(ProviderConnection $connection, array $overrides = []): array
|
|
{
|
|
$resolution = $this->identityResolver->resolve($connection);
|
|
|
|
if (! $resolution->resolved || $resolution->effectiveClientId === null || $resolution->clientSecret === null) {
|
|
throw new RuntimeException($resolution->message ?? 'Provider identity could not be resolved.');
|
|
}
|
|
|
|
return array_merge([
|
|
'tenant' => $resolution->tenantContext,
|
|
'client_id' => $resolution->effectiveClientId,
|
|
'client_secret' => $resolution->clientSecret,
|
|
'client_request_id' => (string) Str::uuid(),
|
|
], $overrides);
|
|
}
|
|
}
|