| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152 |
- syntax = "proto3";
- package smartbotic.proto;
- option cc_enable_arenas = true;
- // Credential service for runners to fetch authentication headers
- service CredentialService {
- // Get HTTP authentication header for a credential
- rpc GetCredentialAuth(GetCredentialAuthRequest) returns (GetCredentialAuthResponse);
- // Get IMAP credentials for a credential
- rpc GetImapCredentials(GetImapCredentialsRequest) returns (GetImapCredentialsResponse);
- // Get the client certificate a workflow presents when a server asks for
- // one. Mediated like every other secret here: the private key never
- // reaches the runner except in answer to a request the webserver has
- // checked.
- rpc GetClientCertificate(GetClientCertificateRequest) returns (GetClientCertificateResponse);
- // Get SMTP credentials for a credential
- rpc GetSmtpCredentials(GetSmtpCredentialsRequest) returns (GetSmtpCredentialsResponse);
- // Get MySQL credentials for a credential
- rpc GetMysqlCredentials(GetMysqlCredentialsRequest) returns (GetMysqlCredentialsResponse);
- // Get PostgreSQL credentials for a credential
- rpc GetPostgresqlCredentials(GetPostgresqlCredentialsRequest) returns (GetPostgresqlCredentialsResponse);
- // List available credentials (metadata only)
- rpc ListCredentials(ListCredentialsRequest) returns (ListCredentialsResponse);
- }
- // Request to get credential auth header
- message GetCredentialAuthRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with auth header
- message GetCredentialAuthResponse {
- bool success = 1;
- string header_name = 2; // e.g., "Authorization"
- string header_value = 3; // e.g., "Bearer token123"
- string error = 4; // Error message if success is false
- }
- // Credential info (metadata only, no secrets)
- message CredentialInfo {
- string id = 1;
- string name = 2;
- string type = 3; // "basic", "bearer", "api_key", "oauth2", "imap", "smtp", "mysql", "postgresql", "client_certificate"
- string description = 4;
- }
- // Request to get a client certificate (mTLS identity)
- message GetClientCertificateRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with the certificate and its key. Both are PEM.
- message GetClientCertificateResponse {
- bool success = 1;
- string certificate_pem = 2;
- string private_key_pem = 3;
- string passphrase = 4; // Empty when the key is not encrypted
- string error = 5; // Error message if success is false
- }
- // Request to get IMAP credentials
- message GetImapCredentialsRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with IMAP credentials
- message GetImapCredentialsResponse {
- bool success = 1;
- string host = 2;
- int32 port = 3;
- string username = 4;
- string password = 5;
- bool use_ssl = 6;
- string error = 7; // Error message if success is false
- }
- // Request to get SMTP credentials
- message GetSmtpCredentialsRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with SMTP credentials. An imap credential answers here too, so an
- // account stored for reading mail can also be used to send it.
- message GetSmtpCredentialsResponse {
- bool success = 1;
- string host = 2;
- int32 port = 3;
- string username = 4;
- string password = 5;
- string security = 6; // "starttls", "ssl" or "none"
- string from_address = 7;
- string from_name = 8;
- string error = 9;
- }
- // Request to get MySQL credentials
- message GetMysqlCredentialsRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with MySQL credentials
- message GetMysqlCredentialsResponse {
- bool success = 1;
- string host = 2;
- int32 port = 3;
- string username = 4;
- string password = 5;
- string database = 6;
- bool use_ssl = 7;
- string error = 8; // Error message if success is false
- }
- // Request to get PostgreSQL credentials
- message GetPostgresqlCredentialsRequest {
- string credential_id = 1;
- string workflow_id = 2; // For access control verification
- }
- // Response with PostgreSQL credentials
- message GetPostgresqlCredentialsResponse {
- bool success = 1;
- string host = 2;
- int32 port = 3;
- string username = 4;
- string password = 5;
- string database = 6;
- bool use_ssl = 7;
- string error = 8; // Error message if success is false
- }
- // Request to list credentials
- message ListCredentialsRequest {
- string workflow_id = 1; // Optional: filter by workflow access
- }
- // Response with credential list
- message ListCredentialsResponse {
- repeated CredentialInfo credentials = 1;
- }
|