| | | 1 | | using AsiBackbone.Core.Constraints; |
| | | 2 | | using AsiBackbone.Core.Decisions; |
| | | 3 | | using AsiBackbone.Core.Results; |
| | | 4 | | |
| | | 5 | | namespace AsiBackbone.Core.Evaluation; |
| | | 6 | | |
| | | 7 | | /// <summary> |
| | | 8 | | /// Default policy evaluator that runs the active constraint structure and composes the result into a governance decisio |
| | | 9 | | /// </summary> |
| | | 10 | | /// <typeparam name="TContext">The framework-neutral evaluation context type.</typeparam> |
| | | 11 | | public sealed class DefaultAsiBackbonePolicyEvaluator<TContext> : IAsiBackbonePolicyEvaluator<TContext> |
| | | 12 | | where TContext : IAsiBackboneConstraintEvaluationContext |
| | | 13 | | { |
| | | 14 | | private readonly IAsiBackboneConstraint<TContext>[] constraints; |
| | | 15 | | private readonly IAsiBackboneDecisionPolicy<TContext>? decisionPolicy; |
| | | 16 | | private readonly AsiBackbonePolicyEvaluatorOptions options; |
| | | 17 | | |
| | | 18 | | /// <summary> |
| | | 19 | | /// Initializes a new instance of the <see cref="DefaultAsiBackbonePolicyEvaluator{TContext}"/> class. |
| | | 20 | | /// </summary> |
| | | 21 | | /// <param name="constraints">The constraints that make up the active policy structure.</param> |
| | | 22 | | /// <param name="decisionPolicy">Optional decision policy applied after constraint composition.</param> |
| | | 23 | | public DefaultAsiBackbonePolicyEvaluator( |
| | | 24 | | IEnumerable<IAsiBackboneConstraint<TContext>> constraints, |
| | | 25 | | IAsiBackboneDecisionPolicy<TContext>? decisionPolicy = null) |
| | 25 | 26 | | : this(constraints, decisionPolicy, options: null) |
| | | 27 | | { |
| | 24 | 28 | | } |
| | | 29 | | |
| | | 30 | | /// <summary> |
| | | 31 | | /// Initializes a new instance of the <see cref="DefaultAsiBackbonePolicyEvaluator{TContext}"/> class. |
| | | 32 | | /// </summary> |
| | | 33 | | /// <param name="constraints">The constraints that make up the active policy structure.</param> |
| | | 34 | | /// <param name="decisionPolicy">Optional decision policy applied after constraint composition.</param> |
| | | 35 | | /// <param name="options">Evaluator options applied during constraint composition.</param> |
| | 39 | 36 | | public DefaultAsiBackbonePolicyEvaluator( |
| | 39 | 37 | | IEnumerable<IAsiBackboneConstraint<TContext>> constraints, |
| | 39 | 38 | | IAsiBackboneDecisionPolicy<TContext>? decisionPolicy, |
| | 39 | 39 | | AsiBackbonePolicyEvaluatorOptions? options) |
| | | 40 | | { |
| | 39 | 41 | | ArgumentNullException.ThrowIfNull(constraints); |
| | | 42 | | |
| | | 43 | | // Keep an exact-sized private snapshot rather than wrapping a caller-owned list. |
| | | 44 | | // This avoids a per-evaluator ReadOnlyCollection<T> wrapper and prevents later caller mutations |
| | | 45 | | // from changing the evaluator's deterministic constraint order or behavior. |
| | 38 | 46 | | this.constraints = [.. constraints]; |
| | 38 | 47 | | this.decisionPolicy = decisionPolicy; |
| | 38 | 48 | | this.options = options ?? new AsiBackbonePolicyEvaluatorOptions(); |
| | 38 | 49 | | this.options.Validate(); |
| | 32 | 50 | | } |
| | | 51 | | |
| | | 52 | | /// <inheritdoc /> |
| | | 53 | | public async ValueTask<GovernanceDecision> EvaluateAsync( |
| | | 54 | | TContext context, |
| | | 55 | | CancellationToken cancellationToken = default) |
| | | 56 | | { |
| | 32 | 57 | | ArgumentNullException.ThrowIfNull(context); |
| | 31 | 58 | | cancellationToken.ThrowIfCancellationRequested(); |
| | | 59 | | |
| | 30 | 60 | | if (constraints.Length == 0 && options.DenyWhenNoConstraints) |
| | | 61 | | { |
| | 3 | 62 | | var noConstraintsDecision = GovernanceDecision.Deny( |
| | 3 | 63 | | options.NoConstraintsReasonCode, |
| | 3 | 64 | | options.NoConstraintsReasonMessage, |
| | 3 | 65 | | correlationId: context.CorrelationId, |
| | 3 | 66 | | policyVersion: context.PolicyVersion, |
| | 3 | 67 | | policyHash: context.PolicyHash); |
| | | 68 | | |
| | 3 | 69 | | return decisionPolicy is null |
| | 3 | 70 | | ? noConstraintsDecision |
| | 3 | 71 | | : await decisionPolicy |
| | 3 | 72 | | .ApplyAsync( |
| | 3 | 73 | | context, |
| | 3 | 74 | | noConstraintsDecision, |
| | 3 | 75 | | Array.AsReadOnly(Array.Empty<ConstraintEvaluationResult>()), |
| | 3 | 76 | | cancellationToken) |
| | 3 | 77 | | .ConfigureAwait(false); |
| | | 78 | | } |
| | | 79 | | |
| | 27 | 80 | | List<ConstraintEvaluationResult> results = new(constraints.Length); |
| | 27 | 81 | | List<OperationReason> denials = []; |
| | 27 | 82 | | List<OperationReason> warnings = []; |
| | | 83 | | |
| | 160 | 84 | | foreach (IAsiBackboneConstraint<TContext> constraint in constraints) |
| | | 85 | | { |
| | 55 | 86 | | cancellationToken.ThrowIfCancellationRequested(); |
| | | 87 | | |
| | 54 | 88 | | ConstraintEvaluationResult result = await constraint |
| | 54 | 89 | | .EvaluateAsync(context, cancellationToken) |
| | 54 | 90 | | .ConfigureAwait(false); |
| | | 91 | | |
| | 54 | 92 | | results.Add(result); |
| | | 93 | | |
| | 54 | 94 | | if (result.IsDenied) |
| | | 95 | | { |
| | 13 | 96 | | denials.AddRange(result.Reasons); |
| | | 97 | | |
| | 13 | 98 | | if (options.ShortCircuitOnFirstDenial) |
| | | 99 | | { |
| | 3 | 100 | | break; |
| | | 101 | | } |
| | | 102 | | } |
| | 41 | 103 | | else if (result.IsWarning) |
| | | 104 | | { |
| | 15 | 105 | | warnings.AddRange(result.Reasons); |
| | | 106 | | } |
| | | 107 | | } |
| | | 108 | | |
| | 26 | 109 | | GovernanceDecision composedDecision = Compose( |
| | 26 | 110 | | context, |
| | 26 | 111 | | denials, |
| | 26 | 112 | | warnings, |
| | 26 | 113 | | includeWarningsWhenDenied: options.ShortCircuitOnFirstDenial); |
| | | 114 | | |
| | 26 | 115 | | return decisionPolicy is null |
| | 26 | 116 | | ? composedDecision |
| | 26 | 117 | | : await decisionPolicy |
| | 26 | 118 | | .ApplyAsync(context, composedDecision, Array.AsReadOnly([.. results]), cancellationToken) |
| | 26 | 119 | | .ConfigureAwait(false); |
| | 29 | 120 | | } |
| | | 121 | | |
| | | 122 | | private static GovernanceDecision Compose( |
| | | 123 | | TContext context, |
| | | 124 | | List<OperationReason> denials, |
| | | 125 | | List<OperationReason> warnings, |
| | | 126 | | bool includeWarningsWhenDenied) |
| | | 127 | | { |
| | 26 | 128 | | if (denials.Count > 0) |
| | | 129 | | { |
| | 11 | 130 | | IEnumerable<OperationReason> denialReasons = includeWarningsWhenDenied && warnings.Count > 0 |
| | 11 | 131 | | ? warnings.Concat(denials) |
| | 11 | 132 | | : denials; |
| | | 133 | | |
| | 11 | 134 | | return GovernanceDecision.Deny( |
| | 11 | 135 | | denialReasons, |
| | 11 | 136 | | correlationId: context.CorrelationId, |
| | 11 | 137 | | policyVersion: context.PolicyVersion, |
| | 11 | 138 | | policyHash: context.PolicyHash); |
| | | 139 | | } |
| | | 140 | | |
| | 15 | 141 | | return warnings.Count > 0 |
| | 15 | 142 | | ? GovernanceDecision.Warning( |
| | 15 | 143 | | warnings, |
| | 15 | 144 | | correlationId: context.CorrelationId, |
| | 15 | 145 | | policyVersion: context.PolicyVersion, |
| | 15 | 146 | | policyHash: context.PolicyHash) |
| | 15 | 147 | | : GovernanceDecision.Allow( |
| | 15 | 148 | | correlationId: context.CorrelationId, |
| | 15 | 149 | | policyVersion: context.PolicyVersion, |
| | 15 | 150 | | policyHash: context.PolicyHash); |
| | | 151 | | } |
| | | 152 | | } |