credentials.proto 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152
  1. syntax = "proto3";
  2. package smartbotic.proto;
  3. option cc_enable_arenas = true;
  4. // Credential service for runners to fetch authentication headers
  5. service CredentialService {
  6. // Get HTTP authentication header for a credential
  7. rpc GetCredentialAuth(GetCredentialAuthRequest) returns (GetCredentialAuthResponse);
  8. // Get IMAP credentials for a credential
  9. rpc GetImapCredentials(GetImapCredentialsRequest) returns (GetImapCredentialsResponse);
  10. // Get the client certificate a workflow presents when a server asks for
  11. // one. Mediated like every other secret here: the private key never
  12. // reaches the runner except in answer to a request the webserver has
  13. // checked.
  14. rpc GetClientCertificate(GetClientCertificateRequest) returns (GetClientCertificateResponse);
  15. // Get SMTP credentials for a credential
  16. rpc GetSmtpCredentials(GetSmtpCredentialsRequest) returns (GetSmtpCredentialsResponse);
  17. // Get MySQL credentials for a credential
  18. rpc GetMysqlCredentials(GetMysqlCredentialsRequest) returns (GetMysqlCredentialsResponse);
  19. // Get PostgreSQL credentials for a credential
  20. rpc GetPostgresqlCredentials(GetPostgresqlCredentialsRequest) returns (GetPostgresqlCredentialsResponse);
  21. // List available credentials (metadata only)
  22. rpc ListCredentials(ListCredentialsRequest) returns (ListCredentialsResponse);
  23. }
  24. // Request to get credential auth header
  25. message GetCredentialAuthRequest {
  26. string credential_id = 1;
  27. string workflow_id = 2; // For access control verification
  28. }
  29. // Response with auth header
  30. message GetCredentialAuthResponse {
  31. bool success = 1;
  32. string header_name = 2; // e.g., "Authorization"
  33. string header_value = 3; // e.g., "Bearer token123"
  34. string error = 4; // Error message if success is false
  35. }
  36. // Credential info (metadata only, no secrets)
  37. message CredentialInfo {
  38. string id = 1;
  39. string name = 2;
  40. string type = 3; // "basic", "bearer", "api_key", "oauth2", "imap", "smtp", "mysql", "postgresql", "client_certificate"
  41. string description = 4;
  42. }
  43. // Request to get a client certificate (mTLS identity)
  44. message GetClientCertificateRequest {
  45. string credential_id = 1;
  46. string workflow_id = 2; // For access control verification
  47. }
  48. // Response with the certificate and its key. Both are PEM.
  49. message GetClientCertificateResponse {
  50. bool success = 1;
  51. string certificate_pem = 2;
  52. string private_key_pem = 3;
  53. string passphrase = 4; // Empty when the key is not encrypted
  54. string error = 5; // Error message if success is false
  55. }
  56. // Request to get IMAP credentials
  57. message GetImapCredentialsRequest {
  58. string credential_id = 1;
  59. string workflow_id = 2; // For access control verification
  60. }
  61. // Response with IMAP credentials
  62. message GetImapCredentialsResponse {
  63. bool success = 1;
  64. string host = 2;
  65. int32 port = 3;
  66. string username = 4;
  67. string password = 5;
  68. bool use_ssl = 6;
  69. string error = 7; // Error message if success is false
  70. }
  71. // Request to get SMTP credentials
  72. message GetSmtpCredentialsRequest {
  73. string credential_id = 1;
  74. string workflow_id = 2; // For access control verification
  75. }
  76. // Response with SMTP credentials. An imap credential answers here too, so an
  77. // account stored for reading mail can also be used to send it.
  78. message GetSmtpCredentialsResponse {
  79. bool success = 1;
  80. string host = 2;
  81. int32 port = 3;
  82. string username = 4;
  83. string password = 5;
  84. string security = 6; // "starttls", "ssl" or "none"
  85. string from_address = 7;
  86. string from_name = 8;
  87. string error = 9;
  88. }
  89. // Request to get MySQL credentials
  90. message GetMysqlCredentialsRequest {
  91. string credential_id = 1;
  92. string workflow_id = 2; // For access control verification
  93. }
  94. // Response with MySQL credentials
  95. message GetMysqlCredentialsResponse {
  96. bool success = 1;
  97. string host = 2;
  98. int32 port = 3;
  99. string username = 4;
  100. string password = 5;
  101. string database = 6;
  102. bool use_ssl = 7;
  103. string error = 8; // Error message if success is false
  104. }
  105. // Request to get PostgreSQL credentials
  106. message GetPostgresqlCredentialsRequest {
  107. string credential_id = 1;
  108. string workflow_id = 2; // For access control verification
  109. }
  110. // Response with PostgreSQL credentials
  111. message GetPostgresqlCredentialsResponse {
  112. bool success = 1;
  113. string host = 2;
  114. int32 port = 3;
  115. string username = 4;
  116. string password = 5;
  117. string database = 6;
  118. bool use_ssl = 7;
  119. string error = 8; // Error message if success is false
  120. }
  121. // Request to list credentials
  122. message ListCredentialsRequest {
  123. string workflow_id = 1; // Optional: filter by workflow access
  124. }
  125. // Response with credential list
  126. message ListCredentialsResponse {
  127. repeated CredentialInfo credentials = 1;
  128. }