path mgmt/v1alpha1/account_setting.proto
package mgmt.v1alpha1
Messages
AccountSetting
A setting of an account: a value that varies by account, part of which may be a secret,
and that a human sets once.
Deployment settings — what holds for everybody, such as the Temporal url or the limits —
stay in environment variables: they are infrastructure, not product.
| Name | Type | Description |
|---|
account_id | string | The account this setting belongs to. |
config | AccountSettingConfig | The setting itself. An account holds at most one of each variant. |
secret_fingerprints | repeated AccountSetting.SecretFingerprintsEntry | The fingerprint of each secret the setting carries, by the path of its field
("anonymization_consistency.derivation_key").
A response carries these instead of the secrets, which are absent from it: a
fingerprint answers the only real need — telling whether two deployments share a
secret, or whether the one just written really replaced the one that was there —
while showing the last characters of a secret would only make it easier to guess. |
created_at | google.protobuf.Timestamp | The time this setting was created. |
updated_at | google.protobuf.Timestamp | The last time this setting was updated. |
created_by_user_id | string | The user that created this setting. Empty when a run generated it. |
updated_by_user_id | string | The user that last updated this setting. Empty when a run generated it. |
AccountSetting.SecretFingerprintsEntry
| Name | Type | Description |
|---|
key | string | |
value | string | |
AccountSettingConfig
The setting itself, one variant per kind of setting.
Adding a setting is adding a variant: neither the table, nor the RPCs, nor the access
rules move.
| Name | Type | Description |
|---|
anonymization_consistency | AnonymizationConsistency | What the account's deterministic anonymization derives from. |
oidc_provider | OidcProvider | The identity provider the account's members sign in with. |
AnonymizationConsistency
What an account's deterministic anonymization derives from.
| Name | Type | Description |
|---|
derivation_key | string | The key both engines derive their deterministic outputs from: Athanor for all of its
transformers, Benthos for the permutation of TransformPhoneNumber in preserve_format.
It is generated rather than typed. It is given only for a reason: taking over the key
of a deployment being replaced, or replaying outputs produced elsewhere. Replacing it
changes every output of the account, so the destinations already filled no longer
match what a new run writes. |
GetAccountConsistencyKeyRequest
| Name | Type | Description |
|---|
account_id | string | The account to read the key of. |
generate_if_absent | bool | Whether to generate a key for the account when it has none.
A run asks for one only when nothing else gives it a key: the deployment variable
still wins over an account with no setting, so a deployment that carries one keeps
producing the outputs it produced. Where no variable is set, every account gets its
own key on its first run. |
GetAccountConsistencyKeyResponse
| Name | Type | Description |
|---|
key | optional string | The key, in clear. Absent when the account has none — and, when one was asked for,
when the deployment has no way to keep a secret. |
GetAccountSettingsRequest
| Name | Type | Description |
|---|
account_id | string | The account to read the settings of. |
GetAccountSettingsResponse
OidcProvider
The identity provider an account's members sign in with.
Nothing here names a product. What an account declares is what the standard defines:
an issuer to discover, a public client to authorize as, and the audience its tokens
carry. The issuer must be reached over https, at an address on the internet, unless the
deployment allows otherwise (AUTH_ACCOUNT_ISSUER_ALLOW_PRIVATE).
A provider that needs more than this is a provider Husonym does not claim to support.
| Name | Type | Description |
|---|
issuer | string | The issuer, exactly as its tokens spell it in their iss claim.
It is compared by exact string equality, so it is the issuer and not the URL a human
would type: a discovery document that answers under one name and calls itself another
is rejected by the test below rather than accepted and puzzled over later. |
client_id | string | The client the frontend authorizes as. Public information: the browser carries it in
the authorization URL, and the tenant discovery endpoint serves it unauthenticated. |
SetAccountSettingRequest
| Name | Type | Description |
|---|
account_id | string | The account to write the setting for. |
config | AccountSettingConfig | The setting to write. It replaces the one the account holds of that kind, if any. |
SetAccountSettingResponse
| Name | Type | Description |
|---|
setting | AccountSetting | The setting as it now stands, without its secrets. |
SettingCheck
One finding of a setting test.
A finding, not a sentence: what was checked, how much it weighs, what is missing and
what to do about it. The same shape the connection checks use, for the same reason --
a human fixes a provider from a remedy, never from a stack trace.
| Name | Type | Description |
|---|
check | string | What was checked, as a stable identifier a screen can translate. |
level | SettingCheckLevel | How much the finding weighs. |
detail | string | What was found, in one sentence. |
remedy | string | What to do about it. Empty when there is nothing to do. |
TestAccountSettingRequest
| Name | Type | Description |
|---|
account_id | string | The account the setting would belong to. |
config | AccountSettingConfig | The setting to try. It is not written, whatever the findings say. |
TestAccountSettingResponse
| Name | Type | Description |
|---|
checks | repeated SettingCheck | What the test found, in the order it found it. |
ok | bool | Whether nothing blocking was found. A caller that reads only this is still correct. |
Enums
SettingCheckLevel
How much a finding of a setting test weighs.
| Name | Number | Description |
|---|
SETTING_CHECK_LEVEL_UNSPECIFIED | 0 | |
SETTING_CHECK_LEVEL_BLOCKING | 1 | The setting cannot work. Saving it would lock the account out. |
SETTING_CHECK_LEVEL_WARNING | 2 | The setting works, but not the way its author probably meant. |
SETTING_CHECK_LEVEL_INFO | 3 | Worth knowing, nothing to do. |
Services
AccountSettingService
Holds the settings of an account.
GetAccountSettings
SetAccountSetting
TestAccountSetting
| Method | TestAccountSetting |
|---|
| Request | TestAccountSettingRequest |
|---|
| Response | TestAccountSettingResponse |
|---|
| Description | Tries a setting without writing it, and returns what it found.
For OIDC this is what makes "any compliant provider" true rather than merely claimed:
it performs the discovery, checks that the document calls itself what it was asked
under, and reads the keys -- so a provider is refused with a reason instead of
locking an account out after it is saved. |
|---|
GetAccountConsistencyKey
| Method | GetAccountConsistencyKey |
|---|
| Request | GetAccountConsistencyKeyRequest |
|---|
| Response | GetAccountConsistencyKeyResponse |
|---|
| Description | Retrieves the key an account's deterministic anonymization derives from, in clear, and
generates one when asked and the account has none.
For the worker of a run: it already reads the passwords of the databases it
synchronizes, so the key of the account it runs for adds no surface. |
|---|