2024-01-01 14:58:21 -05:00
|
|
|
// Copyright 2018-2024 the Deno authors. All rights reserved. MIT license.
|
2020-09-05 20:34:02 -04:00
|
|
|
|
2024-03-12 13:42:26 -04:00
|
|
|
use ::deno_permissions::parse_sys_kind;
|
2024-09-16 16:39:37 -04:00
|
|
|
use ::deno_permissions::PermissionDescriptorParser;
|
2024-03-12 13:42:26 -04:00
|
|
|
use ::deno_permissions::PermissionState;
|
|
|
|
use ::deno_permissions::PermissionsContainer;
|
2020-09-14 12:48:57 -04:00
|
|
|
use deno_core::error::custom_error;
|
|
|
|
use deno_core::error::AnyError;
|
2023-09-11 18:10:43 -04:00
|
|
|
use deno_core::op2;
|
2020-09-10 09:57:45 -04:00
|
|
|
use deno_core::OpState;
|
2020-09-16 12:43:08 -04:00
|
|
|
use serde::Deserialize;
|
2023-08-03 07:19:19 -04:00
|
|
|
use serde::Serialize;
|
2024-09-16 16:39:37 -04:00
|
|
|
use std::sync::Arc;
|
2019-08-14 11:03:02 -04:00
|
|
|
|
2023-03-17 14:22:15 -04:00
|
|
|
deno_core::extension!(
|
|
|
|
deno_permissions,
|
|
|
|
ops = [
|
|
|
|
op_query_permission,
|
|
|
|
op_revoke_permission,
|
|
|
|
op_request_permission,
|
2023-03-18 18:30:04 -04:00
|
|
|
],
|
2024-09-16 16:39:37 -04:00
|
|
|
options = {
|
|
|
|
permission_desc_parser: Arc<dyn PermissionDescriptorParser>,
|
|
|
|
},
|
|
|
|
state = |state, options| {
|
|
|
|
state.put(options.permission_desc_parser);
|
|
|
|
},
|
2023-03-17 14:22:15 -04:00
|
|
|
);
|
2019-10-11 14:41:54 -04:00
|
|
|
|
2019-10-27 11:22:53 -04:00
|
|
|
#[derive(Deserialize)]
|
2021-03-18 14:42:01 -04:00
|
|
|
pub struct PermissionArgs {
|
2019-10-27 11:22:53 -04:00
|
|
|
name: String,
|
|
|
|
path: Option<String>,
|
2020-12-30 17:35:28 -05:00
|
|
|
host: Option<String>,
|
2021-04-13 07:25:21 -04:00
|
|
|
variable: Option<String>,
|
2022-09-28 08:46:50 -04:00
|
|
|
kind: Option<String>,
|
2021-04-09 18:12:00 -04:00
|
|
|
command: Option<String>,
|
2019-10-27 11:22:53 -04:00
|
|
|
}
|
|
|
|
|
2023-08-03 07:19:19 -04:00
|
|
|
#[derive(Serialize)]
|
|
|
|
pub struct PermissionStatus {
|
|
|
|
state: String,
|
|
|
|
partial: bool,
|
|
|
|
}
|
|
|
|
|
|
|
|
impl From<PermissionState> for PermissionStatus {
|
|
|
|
fn from(state: PermissionState) -> Self {
|
|
|
|
PermissionStatus {
|
|
|
|
state: if state == PermissionState::GrantedPartial {
|
|
|
|
PermissionState::Granted.to_string()
|
|
|
|
} else {
|
|
|
|
state.to_string()
|
|
|
|
},
|
|
|
|
partial: state == PermissionState::GrantedPartial,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-09-11 18:10:43 -04:00
|
|
|
#[op2]
|
|
|
|
#[serde]
|
2019-10-27 11:22:53 -04:00
|
|
|
pub fn op_query_permission(
|
2020-09-10 09:57:45 -04:00
|
|
|
state: &mut OpState,
|
2023-09-11 18:10:43 -04:00
|
|
|
#[serde] args: PermissionArgs,
|
2023-08-03 07:19:19 -04:00
|
|
|
) -> Result<PermissionStatus, AnyError> {
|
2024-09-16 16:39:37 -04:00
|
|
|
let permissions_container = state.borrow::<PermissionsContainer>();
|
|
|
|
// todo(dsherret): don't have this function use the properties of
|
|
|
|
// permission container
|
|
|
|
let desc_parser = &permissions_container.descriptor_parser;
|
|
|
|
let permissions = permissions_container.inner.lock();
|
2020-05-29 11:27:43 -04:00
|
|
|
let path = args.path.as_deref();
|
2020-08-18 16:29:32 -04:00
|
|
|
let perm = match args.name.as_ref() {
|
2024-09-16 16:39:37 -04:00
|
|
|
"read" => permissions.read.query(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_read(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"write" => permissions.write.query(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_write(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-03-17 17:45:12 -04:00
|
|
|
"net" => permissions.net.query(
|
|
|
|
match args.host.as_deref() {
|
2020-12-30 17:35:28 -05:00
|
|
|
None => None,
|
2024-09-16 16:39:37 -04:00
|
|
|
Some(h) => Some(desc_parser.parse_net_descriptor(h)?),
|
2020-12-30 17:35:28 -05:00
|
|
|
}
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-04-13 07:25:21 -04:00
|
|
|
"env" => permissions.env.query(args.variable.as_deref()),
|
2022-09-29 06:34:16 -04:00
|
|
|
"sys" => permissions
|
|
|
|
.sys
|
|
|
|
.query(args.kind.as_deref().map(parse_sys_kind).transpose()?),
|
2024-09-16 16:39:37 -04:00
|
|
|
"run" => permissions.run.query(
|
|
|
|
args
|
|
|
|
.command
|
|
|
|
.as_deref()
|
|
|
|
.map(|request| desc_parser.parse_run_query(request))
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"ffi" => permissions.ffi.query(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_ffi(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2020-08-25 18:22:15 -04:00
|
|
|
n => {
|
2020-09-14 12:48:57 -04:00
|
|
|
return Err(custom_error(
|
2020-08-25 18:22:15 -04:00
|
|
|
"ReferenceError",
|
2023-01-27 10:43:16 -05:00
|
|
|
format!("No such permission name: {n}"),
|
2020-08-25 18:22:15 -04:00
|
|
|
))
|
|
|
|
}
|
2020-08-18 16:29:32 -04:00
|
|
|
};
|
2023-08-03 07:19:19 -04:00
|
|
|
Ok(PermissionStatus::from(perm))
|
2019-08-14 11:03:02 -04:00
|
|
|
}
|
|
|
|
|
2023-09-11 18:10:43 -04:00
|
|
|
#[op2]
|
|
|
|
#[serde]
|
2019-08-14 11:03:02 -04:00
|
|
|
pub fn op_revoke_permission(
|
2020-09-10 09:57:45 -04:00
|
|
|
state: &mut OpState,
|
2023-09-11 18:10:43 -04:00
|
|
|
#[serde] args: PermissionArgs,
|
2023-08-03 07:19:19 -04:00
|
|
|
) -> Result<PermissionStatus, AnyError> {
|
2024-09-16 16:39:37 -04:00
|
|
|
// todo(dsherret): don't have this function use the properties of
|
|
|
|
// permission container
|
|
|
|
let permissions_container = state.borrow_mut::<PermissionsContainer>();
|
|
|
|
let desc_parser = &permissions_container.descriptor_parser;
|
|
|
|
let mut permissions = permissions_container.inner.lock();
|
2020-05-29 11:27:43 -04:00
|
|
|
let path = args.path.as_deref();
|
2020-08-18 16:29:32 -04:00
|
|
|
let perm = match args.name.as_ref() {
|
2024-09-16 16:39:37 -04:00
|
|
|
"read" => permissions.read.revoke(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_read(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"write" => permissions.write.revoke(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_write(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-03-17 17:45:12 -04:00
|
|
|
"net" => permissions.net.revoke(
|
|
|
|
match args.host.as_deref() {
|
2020-12-30 17:35:28 -05:00
|
|
|
None => None,
|
2024-09-16 16:39:37 -04:00
|
|
|
Some(h) => Some(desc_parser.parse_net_descriptor(h)?),
|
2020-12-30 17:35:28 -05:00
|
|
|
}
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-04-13 07:25:21 -04:00
|
|
|
"env" => permissions.env.revoke(args.variable.as_deref()),
|
2022-09-28 08:46:50 -04:00
|
|
|
"sys" => permissions
|
|
|
|
.sys
|
2022-09-29 06:34:16 -04:00
|
|
|
.revoke(args.kind.as_deref().map(parse_sys_kind).transpose()?),
|
2024-09-16 16:39:37 -04:00
|
|
|
"run" => permissions.run.revoke(
|
|
|
|
args
|
|
|
|
.command
|
|
|
|
.as_deref()
|
|
|
|
.map(|request| desc_parser.parse_run_query(request))
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"ffi" => permissions.ffi.revoke(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_ffi(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2020-08-25 18:22:15 -04:00
|
|
|
n => {
|
2020-09-14 12:48:57 -04:00
|
|
|
return Err(custom_error(
|
2020-08-25 18:22:15 -04:00
|
|
|
"ReferenceError",
|
2023-01-27 10:43:16 -05:00
|
|
|
format!("No such permission name: {n}"),
|
2020-08-25 18:22:15 -04:00
|
|
|
))
|
|
|
|
}
|
2020-08-18 16:29:32 -04:00
|
|
|
};
|
2023-08-03 07:19:19 -04:00
|
|
|
Ok(PermissionStatus::from(perm))
|
2019-08-14 11:03:02 -04:00
|
|
|
}
|
2019-11-11 10:33:29 -05:00
|
|
|
|
2023-09-11 18:10:43 -04:00
|
|
|
#[op2]
|
|
|
|
#[serde]
|
2019-11-11 10:33:29 -05:00
|
|
|
pub fn op_request_permission(
|
2020-09-10 09:57:45 -04:00
|
|
|
state: &mut OpState,
|
2023-09-11 18:10:43 -04:00
|
|
|
#[serde] args: PermissionArgs,
|
2023-08-03 07:19:19 -04:00
|
|
|
) -> Result<PermissionStatus, AnyError> {
|
2024-09-16 16:39:37 -04:00
|
|
|
// todo(dsherret): don't have this function use the properties of
|
|
|
|
// permission container
|
|
|
|
let permissions_container = state.borrow_mut::<PermissionsContainer>();
|
|
|
|
let desc_parser = &permissions_container.descriptor_parser;
|
|
|
|
let mut permissions = permissions_container.inner.lock();
|
2020-05-29 11:27:43 -04:00
|
|
|
let path = args.path.as_deref();
|
2019-11-11 10:33:29 -05:00
|
|
|
let perm = match args.name.as_ref() {
|
2024-09-16 16:39:37 -04:00
|
|
|
"read" => permissions.read.request(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_read(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"write" => permissions.write.request(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_write(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-03-17 17:45:12 -04:00
|
|
|
"net" => permissions.net.request(
|
|
|
|
match args.host.as_deref() {
|
2020-12-30 17:35:28 -05:00
|
|
|
None => None,
|
2024-09-16 16:39:37 -04:00
|
|
|
Some(h) => Some(desc_parser.parse_net_descriptor(h)?),
|
2020-12-30 17:35:28 -05:00
|
|
|
}
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2021-04-13 07:25:21 -04:00
|
|
|
"env" => permissions.env.request(args.variable.as_deref()),
|
2022-09-28 08:46:50 -04:00
|
|
|
"sys" => permissions
|
|
|
|
.sys
|
2022-09-29 06:34:16 -04:00
|
|
|
.request(args.kind.as_deref().map(parse_sys_kind).transpose()?),
|
2024-09-16 16:39:37 -04:00
|
|
|
"run" => permissions.run.request(
|
|
|
|
args
|
|
|
|
.command
|
|
|
|
.as_deref()
|
|
|
|
.map(|request| desc_parser.parse_run_query(request))
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
|
|
|
"ffi" => permissions.ffi.request(
|
|
|
|
path
|
|
|
|
.map(|path| {
|
|
|
|
Result::<_, AnyError>::Ok(
|
|
|
|
desc_parser.parse_path_query(path)?.into_ffi(),
|
|
|
|
)
|
|
|
|
})
|
|
|
|
.transpose()?
|
|
|
|
.as_ref(),
|
|
|
|
),
|
2020-08-25 18:22:15 -04:00
|
|
|
n => {
|
2020-09-14 12:48:57 -04:00
|
|
|
return Err(custom_error(
|
2020-08-25 18:22:15 -04:00
|
|
|
"ReferenceError",
|
2023-01-27 10:43:16 -05:00
|
|
|
format!("No such permission name: {n}"),
|
2020-08-25 18:22:15 -04:00
|
|
|
))
|
|
|
|
}
|
2020-08-18 16:29:32 -04:00
|
|
|
};
|
2023-08-03 07:19:19 -04:00
|
|
|
Ok(PermissionStatus::from(perm))
|
2019-11-11 10:33:29 -05:00
|
|
|
}
|