| 1 | //! What the security suite's parts share: whether a repository has the |
| 2 | //! paid features, telling people (events for webhooks and the inbox), and |
| 3 | //! the audit log. |
| 4 | |
| 5 | use g1t_contracts::audit::{AuditActor, AuditOutcome, AuditTarget, NewAuditEntry, RecordAuditArgs, Surface}; |
| 6 | use g1t_contracts::billing::{Feature, HasFeatureArgs}; |
| 7 | use g1t_contracts::events::{NewEvent, Publish}; |
| 8 | use g1t_contracts::identity::{ListMembersArgs, Member}; |
| 9 | use g1t_contracts::security_suite::{AlertType, EVENT_TYPES, PaidFeature, SecurityEvent, needs_activation}; |
| 10 | use g1t_contracts::{FailureCode, Outcome, Role, User, new_id}; |
| 11 | use g1t_kit::now_ms; |
| 12 | use worker::Result; |
| 13 | |
| 14 | use crate::Security; |
| 15 | use crate::store::RepoRow; |
| 16 | |
| 17 | /// The most workspace members an event names as able to see findings. |
| 18 | const MAX_MEMBERS_NAMED: usize = 500; |
| 19 | |
| 20 | /// A failure for want of the activation. |
| 21 | pub fn payment_required<T>(feature: PaidFeature, workspace: &str) -> Outcome<T> { |
| 22 | Outcome::fail(FailureCode::PaymentRequired, needs_activation(feature, workspace)) |
| 23 | } |
| 24 | |
| 25 | /// The page of a repository's security section: `/acme/rocket/security/…`. |
| 26 | pub fn link(repo: &RepoRow, rest: &str) -> String { |
| 27 | let rest = rest.trim_start_matches('/'); |
| 28 | if rest.is_empty() { |
| 29 | format!("/{}/{}/security", repo.namespace, repo.name) |
| 30 | } else { |
| 31 | format!("/{}/{}/security/{rest}", repo.namespace, repo.name) |
| 32 | } |
| 33 | } |
| 34 | |
| 35 | impl Security { |
| 36 | /// Whether the workspace has the Security and quality activation (or |
| 37 | /// has it included). When billing cannot say, it is taken as not: a |
| 38 | /// paid feature waits rather than running unpaid. |
| 39 | pub(crate) async fn activated(&self, namespace: &str) -> bool { |
| 40 | let answer: Result<Outcome<bool>> = g1t_kit::call( |
| 41 | &self.billing, |
| 42 | "has_feature", |
| 43 | &HasFeatureArgs { workspace: namespace.to_owned(), feature: Feature::Security }, |
| 44 | ) |
| 45 | .await; |
| 46 | match answer { |
| 47 | Ok(Outcome::Ok(on)) => on, |
| 48 | Ok(Outcome::Fail(_)) => false, |
| 49 | Err(error) => { |
| 50 | worker::console_error!("security: has_feature for {namespace}: {error}"); |
| 51 | false |
| 52 | } |
| 53 | } |
| 54 | } |
| 55 | |
| 56 | /// Whether a repository has the paid features: it is public, or its |
| 57 | /// workspace has the activation. |
| 58 | pub(crate) async fn entitled(&self, repo: &RepoRow) -> Result<bool> { |
| 59 | let (_, private) = self.store.repo_settings(&repo.repo_id).await?; |
| 60 | Ok(!private || self.activated(&repo.namespace).await) |
| 61 | } |
| 62 | |
| 63 | /// `None` when the repository may use `feature`, or the refusal. |
| 64 | pub(crate) async fn gate<T>(&self, repo: &RepoRow, feature: PaidFeature) -> Result<Option<Outcome<T>>> { |
| 65 | Ok((!self.entitled(repo).await?).then(|| payment_required(feature, &repo.namespace))) |
| 66 | } |
| 67 | |
| 68 | /// The workspace's members, as g1t sees them. |
| 69 | pub(crate) async fn members(&self, namespace: &str) -> Vec<Member> { |
| 70 | let found: Result<Outcome<Vec<Member>>> = g1t_kit::call( |
| 71 | &self.identity, |
| 72 | "list_members", |
| 73 | &ListMembersArgs { slug: namespace.to_owned(), viewer: Some(User::system(namespace)) }, |
| 74 | ) |
| 75 | .await; |
| 76 | match found { |
| 77 | Ok(Outcome::Ok(members)) => members, |
| 78 | Ok(Outcome::Fail(failure)) => { |
| 79 | worker::console_error!("security: members of {namespace}: {}", failure.message); |
| 80 | Vec::new() |
| 81 | } |
| 82 | Err(error) => { |
| 83 | worker::console_error!("security: members of {namespace}: {error}"); |
| 84 | Vec::new() |
| 85 | } |
| 86 | } |
| 87 | } |
| 88 | |
| 89 | /// Publishes a security event, for webhooks and the inbox. New alerts |
| 90 | /// name the workspace's owners to tell, and its members as those who |
| 91 | /// may see findings. Failing to publish never fails the change. |
| 92 | pub(crate) async fn publish(&self, kind: &str, repo: &RepoRow, mut event: SecurityEvent, actor_id: Option<String>) { |
| 93 | let Some(kind) = EVENT_TYPES.iter().copied().find(|known| *known == kind) else { |
| 94 | worker::console_error!("security: no event called {kind}"); |
| 95 | return; |
| 96 | }; |
| 97 | let Some(events) = &self.events else { return }; |
| 98 | let mut data = serde_json::to_value(&event).unwrap_or_default(); |
| 99 | if kind.ends_with(".created") || kind == "secret_scanning.bypass_requested" { |
| 100 | let members = self.members(&repo.namespace).await; |
| 101 | if event.notify.is_empty() { |
| 102 | event.notify = members |
| 103 | .iter() |
| 104 | .filter(|member| member.role == Role::Owner) |
| 105 | .map(|member| member.username.clone()) |
| 106 | .collect(); |
| 107 | } |
| 108 | data = serde_json::to_value(&event).unwrap_or_default(); |
| 109 | data["members"] = serde_json::json!( |
| 110 | members.iter().take(MAX_MEMBERS_NAMED).map(|member| member.username.clone()).collect::<Vec<_>>() |
| 111 | ); |
| 112 | } |
| 113 | let published: Result<serde_json::Value> = g1t_kit::call( |
| 114 | events, |
| 115 | "publish", |
| 116 | &Publish { |
| 117 | events: vec![NewEvent { kind, source: "security", repo_id: Some(repo.repo_id.clone()), actor: actor_id, data }], |
| 118 | }, |
| 119 | ) |
| 120 | .await; |
| 121 | if let Err(error) = published { |
| 122 | worker::console_error!("security: {kind} for {} not published: {error}", repo.repo_id); |
| 123 | } |
| 124 | } |
| 125 | |
| 126 | /// Publishes `<type>.<action>` for one alert. |
| 127 | pub(crate) async fn alert_event(&self, alert_type: AlertType, action: &str, repo: &RepoRow, event: SecurityEvent, actor_id: Option<String>) { |
| 128 | let kind = format!("{}.{action}", alert_type.event_prefix()); |
| 129 | self.publish(&kind, repo, event, actor_id).await; |
| 130 | } |
| 131 | |
| 132 | /// Records a security decision in the workspace's audit log. |
| 133 | pub(crate) async fn audit(&self, actor: &User, action: &str, repo: Option<&RepoRow>, namespace: &str, path: Option<&str>, message: &str) { |
| 134 | let Some(events) = &self.events else { return }; |
| 135 | let entry = NewAuditEntry { |
| 136 | actor: AuditActor::of(actor), |
| 137 | action: action.to_owned(), |
| 138 | surface: Surface::Web, |
| 139 | target: AuditTarget { |
| 140 | workspace: namespace.to_owned(), |
| 141 | repo: repo.map(|repo| format!("{}/{}", repo.namespace, repo.name)), |
| 142 | path: path.map(str::to_owned), |
| 143 | ..AuditTarget::default() |
| 144 | }, |
| 145 | outcome: AuditOutcome::Allowed, |
| 146 | rule: "security".to_owned(), |
| 147 | result: Some("ok".to_owned()), |
| 148 | message: Some(message.chars().take(500).collect()), |
| 149 | request_id: new_id("req", now_ms()), |
| 150 | }; |
| 151 | let recorded: Result<u32> = g1t_kit::call(events, "audit_record", &RecordAuditArgs { entries: vec![entry] }).await; |
| 152 | if let Err(error) = recorded { |
| 153 | worker::console_error!("security: audit entry {action} not recorded: {error}"); |
| 154 | } |
| 155 | } |
| 156 | } |