use actix_web::{HttpResponse, web}; use serde::Deserialize; use utoipa::{IntoParams, ToSchema}; use crate::api::response::{ApiErrorResponse, ApiResponse}; use crate::error::AppError; use crate::service::AppService; use crate::session::Session; #[derive(Debug, Deserialize, IntoParams)] pub struct PathParams { /// Workspace name (unique identifier) pub workspace_name: String, /// Repository name (unique within the workspace) pub repo_name: String, /// Branch ID (UUID) pub branch_id: uuid::Uuid, } #[derive(Debug, Deserialize, ToSchema)] pub struct SetBranchProtectionParams { /// Whether to enable branch protection pub protected: bool, } /// Set branch protection /// /// Enables or disables protection for a specific branch. /// Requires Admin role or higher in the repository. /// /// Effects: /// - When enabled: prevents force pushes and branch deletion /// - When disabled: allows force pushes and branch deletion /// /// Returns success message on completion. #[utoipa::path( put, path = "/api/v1/workspaces/{workspace_name}/repos/{repo_name}/branches/{branch_id}/protection", tag = "Repos", operation_id = "repoSetBranchProtection", params(PathParams), request_body( content = SetBranchProtectionParams, description = "Branch protection parameters", content_type = "application/json" ), responses( (status = 200, description = "Branch protection rules set successfully.", body = ApiResponse), (status = 400, description = "Invalid parameters: negative approvals count or conflicting protection settings", body = ApiErrorResponse), (status = 401, description = "Authentication required or session expired", body = ApiErrorResponse), (status = 403, description = "Insufficient permissions (requires Admin role or higher)", body = ApiErrorResponse), (status = 404, description = "Repository, workspace, or branch not found", body = ApiErrorResponse), (status = 500, description = "Internal server error", body = ApiErrorResponse), ), security( ("session_cookie" = []) ) )] pub async fn set_branch_protection( service: web::Data, session: Session, path: web::Path, params: web::Json, ) -> Result { service .repo .repo_set_branch_protection( &session, &path.workspace_name, &path.repo_name, path.branch_id, params.protected, ) .await?; Ok(HttpResponse::Ok().json(ApiResponse::new( "Branch protection rules set successfully".to_string(), ))) }