PlanTempusApp/Database/Core/DDL/SetupIdentitySystem.cs

150 lines
5.3 KiB
C#
Raw Normal View History

2025-02-06 16:58:13 +01:00
using Insight.Database;
using System.Data;
2025-02-11 17:07:01 +01:00
namespace Database.Core.DDL
2025-02-06 16:58:13 +01:00
{
/// <summary>
/// This is by purpose not async await
/// It is intended that this is created with the correct Application User, which is why the schema name is omitted.
/// </summary>
public class SetupIdentitySystem : IDbConfigure<SetupIdentitySystem.Command>
{
public class Command
{
public required string Schema { get; init; }
}
readonly IDbConnection _db;
IDbTransaction _transaction = null;
Command _command;
public SetupIdentitySystem(IDbConnection db)
{
_db = db;
}
/// <summary>
/// Creates the system tables in the specified schema within a transaction.
/// </summary>
/// <param name="schema">The schema name where the tables will be created.</param>
public void With(Command command)
{
_command = command;
using (_transaction = _db.OpenWithTransaction())
{
try
{
CreateUsersTable();
CreateOrganizationsTable();
CreateUserOrganizationsTable();
SetupRLS();
_transaction.Commit();
}
catch (Exception ex)
{
_transaction.Rollback();
throw new InvalidOperationException("Failed to SetupIdentitySystem. Transaction is rolled back", ex);
}
}
}
private void ExecuteSql(string sql)
{
if (string.IsNullOrEmpty(sql))
throw new ArgumentNullException(nameof(sql));
_db.ExecuteSql(sql);
}
/// <summary>
/// Creates the users table
/// </summary>
void CreateUsersTable()
{
var sql = @$"
CREATE TABLE IF NOT EXISTS {_command.Schema}.users (
2025-02-06 16:58:13 +01:00
id SERIAL PRIMARY KEY,
email VARCHAR(256) NOT NULL UNIQUE,
password_hash VARCHAR(256) NOT NULL,
security_stamp VARCHAR(36) NOT NULL,
email_confirmed BOOLEAN NOT NULL DEFAULT FALSE,
access_failed_count INTEGER NOT NULL DEFAULT 0,
lockout_enabled BOOLEAN NOT NULL DEFAULT TRUE,
lockout_end TIMESTAMPTZ NULL,
is_active BOOLEAN NOT NULL DEFAULT TRUE,
created_at TIMESTAMPTZ NOT NULL DEFAULT CURRENT_TIMESTAMP,
last_login_at TIMESTAMPTZ NULL
);";
ExecuteSql(sql);
2025-02-06 16:58:13 +01:00
}
2025-02-06 16:58:13 +01:00
/// <summary>
/// Creates the organizations table
/// </summary>
void CreateOrganizationsTable()
{
var sql = @$"
CREATE TABLE IF NOT EXISTS {_command.Schema}.organizations (
2025-02-06 16:58:13 +01:00
id SERIAL PRIMARY KEY,
connection_string VARCHAR(500) NOT NULL,
is_active BOOLEAN NOT NULL DEFAULT TRUE,
created_by INTEGER NOT NULL REFERENCES {_command.Schema}.users(id),
2025-02-06 16:58:13 +01:00
created_at TIMESTAMPTZ NOT NULL DEFAULT CURRENT_TIMESTAMP
);";
ExecuteSql(sql);
2025-02-06 16:58:13 +01:00
}
2025-02-06 16:58:13 +01:00
/// <summary>
/// Creates the user_organizations table
/// </summary>
void CreateUserOrganizationsTable()
{
var sql = @$"
CREATE TABLE IF NOT EXISTS {_command.Schema}.user_organizations (
user_id INTEGER NOT NULL REFERENCES {_command.Schema}.users(id),
organization_id INTEGER NOT NULL REFERENCES {_command.Schema}.organizations(id),
2025-02-06 16:58:13 +01:00
pin_code VARCHAR(10) NULL,
created_at TIMESTAMPTZ NOT NULL DEFAULT CURRENT_TIMESTAMP,
2025-02-14 20:14:01 +01:00
PRIMARY KEY (user_id, organization_id)
2025-02-06 16:58:13 +01:00
);";
ExecuteSql(sql);
}
/// <summary>
/// Sets up Row Level Security (RLS) for the organizations and user_organizations tables.
/// </summary>
void SetupRLS()
{
var sql = new[]
{
$"ALTER TABLE {_command.Schema}.organizations ENABLE ROW LEVEL SECURITY;",
$"ALTER TABLE {_command.Schema}.user_organizations ENABLE ROW LEVEL SECURITY;",
$"DROP POLICY IF EXISTS organization_access ON {_command.Schema}.organizations;",
@$"CREATE POLICY organization_access ON {_command.Schema}.organizations
2025-02-06 16:58:13 +01:00
USING (id IN (
2025-02-14 20:14:01 +01:00
SELECT organization_id
FROM {_command.Schema}.user_organizations
2025-02-06 16:58:13 +01:00
WHERE user_id = current_setting('app.user_id', TRUE)::INTEGER
)) WITH CHECK (true);",
$"DROP POLICY IF EXISTS user_organization_access ON {_command.Schema}.user_organizations;",
@$"CREATE POLICY user_organization_access ON {_command.Schema}.user_organizations
USING (user_id = current_setting('app.user_id', TRUE)::INTEGER) WITH CHECK (true);"
};
2025-02-06 16:58:13 +01:00
foreach (var statement in sql)
{
ExecuteSql(statement);
}
}
2025-02-06 16:58:13 +01:00
}
2025-02-06 16:58:13 +01:00
}