feat(p9): route OutboundService through the Capability Broker
Task 9.3: OutboundService now delegates the execute step to CapabilityBroker (policy-gated + obligation-enforced) instead of calling a provider directly, while keeping idempotency + rate-limit + the command/attempt ledger. BLOCKED obligations → command BLOCKED; a fail-closed throw marks the command FAILED then propagates. AdaptersModule imports CapabilityModule; P4/P6/P8 egress now flows through the broker unchanged. Updated 6 spec constructions; added a DENY_OUTBOUND test. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { OutboxModule } from '../outbox/outbox.module';
|
||||
import { InteractionsModule } from '../interactions/interactions.module';
|
||||
import { CapabilityModule } from '../capability/capability.module';
|
||||
import { AdapterRegistry } from './adapter.registry';
|
||||
import { InboundService } from './inbound.service';
|
||||
import { OutboundService } from './outbound.service';
|
||||
@@ -8,7 +9,7 @@ import { RawEventProjector } from './raw-event.projector';
|
||||
import { AdaptersController } from './adapters.controller';
|
||||
|
||||
@Module({
|
||||
imports: [OutboxModule, InteractionsModule],
|
||||
imports: [OutboxModule, InteractionsModule, CapabilityModule],
|
||||
controllers: [AdaptersController],
|
||||
providers: [AdapterRegistry, InboundService, OutboundService, RawEventProjector],
|
||||
exports: [AdapterRegistry, InboundService, OutboundService],
|
||||
|
||||
@@ -7,6 +7,8 @@ import { signedFixture, emailFixture } from '@insignia/iios-adapter-sdk';
|
||||
import { AdapterRegistry } from './adapter.registry';
|
||||
import { InboundService } from './inbound.service';
|
||||
import { OutboundService } from './outbound.service';
|
||||
import { CapabilityBroker } from '../capability/capability.broker';
|
||||
import { CapabilityProviderRegistry } from '../capability/capability.registry';
|
||||
import { RawEventProjector } from './raw-event.projector';
|
||||
import { IngestService } from '../interactions/ingest.service';
|
||||
import { ActorResolver } from '../identity/actor.resolver';
|
||||
@@ -77,7 +79,7 @@ describe('Adapter inbound (P5)', () => {
|
||||
|
||||
describe('Adapter outbound (P5)', () => {
|
||||
const outbound = (limit?: number): OutboundService => {
|
||||
const s = new OutboundService(asService, registry());
|
||||
const s = new OutboundService(asService, new CapabilityBroker(makeFakePorts(), new CapabilityProviderRegistry()));
|
||||
if (limit) s.limit = limit;
|
||||
return s;
|
||||
};
|
||||
@@ -104,4 +106,13 @@ describe('Adapter outbound (P5)', () => {
|
||||
expect(b.id).toBe(a.id);
|
||||
expect(await prisma.iiosOutboundCommand.count()).toBe(1);
|
||||
});
|
||||
|
||||
it('broker obligation DENY_OUTBOUND → command BLOCKED, no send (P9)', async () => {
|
||||
const ports = makeFakePorts();
|
||||
ports.opa.setDecision({ allow: true, obligations: [{ kind: 'DENY_OUTBOUND', reason: 'recipient opted out' }] });
|
||||
const svc = new OutboundService(asService, new CapabilityBroker(ports, new CapabilityProviderRegistry()));
|
||||
const cmd = await svc.send('WEBHOOK', 'user@x', { text: 'hi' }, 'blk-1');
|
||||
expect(cmd.status).toBe('BLOCKED');
|
||||
expect(cmd.providerRef).toBe('blocked');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -1,13 +1,14 @@
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import { Injectable, NotFoundException } from '@nestjs/common';
|
||||
import { Injectable } from '@nestjs/common';
|
||||
import { Prisma } from '@prisma/client';
|
||||
import { PrismaService } from '../prisma/prisma.service';
|
||||
import { AdapterRegistry } from './adapter.registry';
|
||||
import { CapabilityBroker } from '../capability/capability.broker';
|
||||
|
||||
/**
|
||||
* Outbound to a provider — in P5 the adapter's `send` is a SANDBOX sink (no real
|
||||
* network). Per-(channelType,target) rate limiting; idempotent per command key;
|
||||
* every attempt recorded. Real delivery is gated to P6+.
|
||||
* Outbound command layer (P5). Owns idempotency + per-(channelType,target) rate
|
||||
* limiting + the delivery ledger. As of P9 the actual execute step is delegated to
|
||||
* the governed CapabilityBroker (policy gate + obligations + provider selection);
|
||||
* this layer no longer talks to a provider directly.
|
||||
*/
|
||||
@Injectable()
|
||||
export class OutboundService {
|
||||
@@ -17,7 +18,7 @@ export class OutboundService {
|
||||
|
||||
constructor(
|
||||
private readonly prisma: PrismaService,
|
||||
private readonly registry: AdapterRegistry,
|
||||
private readonly broker: CapabilityBroker,
|
||||
) {}
|
||||
|
||||
async send(
|
||||
@@ -25,10 +26,8 @@ export class OutboundService {
|
||||
target: string,
|
||||
payload: Record<string, unknown>,
|
||||
idempotencyKey: string = randomUUID(),
|
||||
scopeId?: string,
|
||||
) {
|
||||
const reg = this.registry.get(channelType);
|
||||
if (!reg) throw new NotFoundException(`unknown channel type: ${channelType}`);
|
||||
|
||||
const existing = await this.prisma.iiosOutboundCommand.findUnique({ where: { idempotencyKey } });
|
||||
if (existing) return existing;
|
||||
|
||||
@@ -43,11 +42,23 @@ export class OutboundService {
|
||||
const cmd = await this.prisma.iiosOutboundCommand.create({
|
||||
data: { channelType, target, payload: payload as Prisma.InputJsonValue, status: 'PENDING', idempotencyKey },
|
||||
});
|
||||
const result = await reg.adapter.send({ channelType, target, payload }); // sandbox — no network
|
||||
|
||||
let result;
|
||||
try {
|
||||
result = await this.broker.invoke({ capability: 'channel.send', channelType, target, payload, idempotencyKey, scopeId });
|
||||
} catch (err) {
|
||||
// Fail-closed (e.g. PolicyDeniedError): mark the command FAILED, record the attempt, propagate.
|
||||
await this.prisma.$transaction([
|
||||
this.prisma.iiosOutboundCommand.update({ where: { id: cmd.id }, data: { status: 'FAILED' } }),
|
||||
this.prisma.iiosDeliveryAttempt.create({ data: { commandId: cmd.id, attemptNo: 1, status: 'FAILED', errorCode: (err as Error).name } }),
|
||||
]);
|
||||
throw err;
|
||||
}
|
||||
|
||||
const [updated] = await this.prisma.$transaction([
|
||||
this.prisma.iiosOutboundCommand.update({ where: { id: cmd.id }, data: { status: 'SENT', providerRef: result.providerRef } }),
|
||||
this.prisma.iiosOutboundCommand.update({ where: { id: cmd.id }, data: { status: result.outcome, providerRef: result.providerRef } }),
|
||||
this.prisma.iiosDeliveryAttempt.create({
|
||||
data: { commandId: cmd.id, attemptNo: 1, status: 'SENT', providerRef: result.providerRef, latencyMs: result.latencyMs },
|
||||
data: { commandId: cmd.id, attemptNo: 1, status: result.outcome, providerRef: result.providerRef, latencyMs: result.latencyMs, errorCode: result.errorCode },
|
||||
}),
|
||||
]);
|
||||
return updated;
|
||||
|
||||
Reference in New Issue
Block a user