mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-11 05:31:46 +02:00
## Thinking Path > - Paperclip is the open source control plane people use to coordinate AI-agent work > - Opening an issue fans out into several authenticated issue-detail reads, so repeated work on that path directly affects perceived latency > - Those reads repeated issue and authorization lookups, returned full private JSON even when unchanged, and performed non-critical bookkeeping writes on the request path > - Interaction reads also performed lifecycle writes even though `GET` must be read-only > - This pull request adds request-scoped reuse, private conditional responses, read-only interaction access, and bounded write debouncing without crossing actor, request, or company boundaries > - The result is less database, serialization, logging, and response-body work while preserving authorization and interaction lifecycle invariants ## Linked Issues or Issue Description This is the server-only latency phase. Related work is tracked separately in #10415 (aggregate view), #10416 (warm navigation, merged into the base), and #10463 (bundle split). This pull request intentionally excludes those scopes. **What happened?** Opening an issue detail view caused avoidable server costs: repeated issue and authorization reads within one request, full private JSON responses when a representation was unchanged, writes during interaction-list reads, production debug transport setup, and immediate bookkeeping writes for cloud tenant activity and board-key usage. **Expected behavior** All successful JSON `GET /api/issues/:id/*` responses should support strong private ETags and `304 Not Modified`. Repeated work may be reused only within the current request. `GET /interactions` must not modify stored interactions. Non-critical activity timestamps may be debounced without weakening authentication or stale instance-admin cleanup. **Steps to reproduce** 1. Start Paperclip in local development or self-hosted server mode. 2. Open one issue and request its detail subresources with the same authenticated actor. 3. Repeat a successful JSON request with its `ETag` in `If-None-Match`. 4. Observe `304 Not Modified`, no interaction writes from `GET /interactions`, and unchanged authorization boundaries. **Deployment mode / installation** - Local development or self-hosted server - Built from source - Core server behavior; not adapter-specific ## What Changed - Added strong ETags and `Cache-Control: private, must-revalidate` to successful JSON reads under `/api/issues/:id/*`, including standards-compliant `If-None-Match` handling. - Added request-scoped promise memoization for issue and authorization lookups; no authorization result survives the request. - Made `GET /interactions` read-only, moved supersession and terminal-state handling to mutation paths, and prevented plugin callers from accepting or rejecting interactions after an issue closes. - Removed the production debug-file logger transport while preserving development formatting. - Debounced cloud-tenant activity and board-key `lastUsedAt` persistence, while keeping stale instance-admin deletion unconditional and authentication checks per request. - Added focused tests for ETags, request isolation, authorization lifecycle behavior, interaction invariants, logger configuration, and retry-safe debounce behavior. ## Verification - `pnpm exec vitest run server/src/__tests__/private-json-etag.test.ts server/src/__tests__/issue-thread-interaction-routes.test.ts` — 2 files, 23 tests passed. - Focused Vitest run covering request memoization, authorization, interactions, plugin orchestration, logger, cloud tenant, board auth, and issue services — 9 files, 264 tests passed. - `pnpm --filter @paperclipai/server typecheck` — passed. - `git diff --check origin/master...HEAD` — passed. - Scope guardrails: 21 changed files under `server/src`; no lockfile, workflow, migration, UI, aggregate-view, or bundle-split changes. ## Risks - Strong ETags hash each successful serialized JSON response. This adds a small CPU cost but avoids transferring unchanged bodies. - Debounced bookkeeping timestamps can lag by the bounded debounce interval. They are non-critical usage metadata; authentication still runs per request, and stale instance-admin deletion remains unconditional. - Legacy pending interactions on terminal issues are projected as expired by reads and are finalized only by mutation paths. The stored record remains unchanged on `GET` by design. - No database schema or migration changes are included. > This is a focused performance correction and does not duplicate a planned core feature in `ROADMAP.md`. ## Model Used OpenAI Codex using `gpt-5.3-codex` for the initial implementation and `gpt-5.6-sol` for isolation, verification, and PR preparation, with reasoning, repository tool use, code execution, and GitHub CLI access. The runtimes did not expose authoritative context-window sizes. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Dev Agent <dev@paperclip.ing>
473 lines
15 KiB
TypeScript
473 lines
15 KiB
TypeScript
import { createHash, randomBytes, timingSafeEqual } from "node:crypto";
|
|
import { and, eq, gt, isNull, or, sql } from "drizzle-orm";
|
|
import type { Db } from "@paperclipai/db";
|
|
import {
|
|
authUsers,
|
|
boardApiKeys,
|
|
cliAuthChallenges,
|
|
companies,
|
|
companyMemberships,
|
|
instanceUserRoles,
|
|
} from "@paperclipai/db";
|
|
import { conflict, forbidden, notFound } from "../errors.js";
|
|
|
|
export const BOARD_API_KEY_TTL_MS = 30 * 24 * 60 * 60 * 1000;
|
|
export const CLI_AUTH_CHALLENGE_TTL_MS = 10 * 60 * 1000;
|
|
const BOARD_API_KEY_TOUCH_DEBOUNCE_MS = 60_000;
|
|
const BOARD_API_KEY_TOUCH_CACHE_MAX = 1_000;
|
|
|
|
export type CliAuthChallengeStatus = "pending" | "approved" | "cancelled" | "expired";
|
|
|
|
export function hashBearerToken(token: string) {
|
|
return createHash("sha256").update(token).digest("hex");
|
|
}
|
|
|
|
export function tokenHashesMatch(left: string, right: string) {
|
|
const leftBytes = Buffer.from(left, "utf8");
|
|
const rightBytes = Buffer.from(right, "utf8");
|
|
return leftBytes.length === rightBytes.length && timingSafeEqual(leftBytes, rightBytes);
|
|
}
|
|
|
|
export function createBoardApiToken() {
|
|
return `pcp_board_${randomBytes(24).toString("hex")}`;
|
|
}
|
|
|
|
export function createCliAuthSecret() {
|
|
return `pcp_cli_auth_${randomBytes(24).toString("hex")}`;
|
|
}
|
|
|
|
export function boardApiKeyExpiresAt(nowMs: number = Date.now()) {
|
|
return new Date(nowMs + BOARD_API_KEY_TTL_MS);
|
|
}
|
|
|
|
export function cliAuthChallengeExpiresAt(nowMs: number = Date.now()) {
|
|
return new Date(nowMs + CLI_AUTH_CHALLENGE_TTL_MS);
|
|
}
|
|
|
|
function challengeStatusForRow(row: typeof cliAuthChallenges.$inferSelect): CliAuthChallengeStatus {
|
|
if (row.cancelledAt) return "cancelled";
|
|
if (row.expiresAt.getTime() <= Date.now()) return "expired";
|
|
if (row.approvedAt && row.boardApiKeyId) return "approved";
|
|
return "pending";
|
|
}
|
|
|
|
export function boardAuthService(db: Db) {
|
|
const touchedBoardApiKeys = new Map<string, { completedAt: number | null; inFlight: Promise<void> | null }>();
|
|
|
|
function pruneTouchedBoardApiKeys(nowMs: number) {
|
|
for (const [id, entry] of touchedBoardApiKeys) {
|
|
if (!entry.inFlight && entry.completedAt !== null && entry.completedAt <= nowMs - BOARD_API_KEY_TOUCH_DEBOUNCE_MS) {
|
|
touchedBoardApiKeys.delete(id);
|
|
}
|
|
}
|
|
while (touchedBoardApiKeys.size > BOARD_API_KEY_TOUCH_CACHE_MAX) {
|
|
const oldestId = touchedBoardApiKeys.keys().next().value;
|
|
if (!oldestId) break;
|
|
touchedBoardApiKeys.delete(oldestId);
|
|
}
|
|
}
|
|
async function resolveBoardAccess(userId: string) {
|
|
const [user, memberships, adminRole] = await Promise.all([
|
|
db
|
|
.select({
|
|
id: authUsers.id,
|
|
name: authUsers.name,
|
|
email: authUsers.email,
|
|
})
|
|
.from(authUsers)
|
|
.where(eq(authUsers.id, userId))
|
|
.then((rows) => rows[0] ?? null),
|
|
db
|
|
.select({
|
|
companyId: companyMemberships.companyId,
|
|
membershipRole: companyMemberships.membershipRole,
|
|
status: companyMemberships.status,
|
|
})
|
|
.from(companyMemberships)
|
|
.where(
|
|
and(
|
|
eq(companyMemberships.principalType, "user"),
|
|
eq(companyMemberships.principalId, userId),
|
|
eq(companyMemberships.status, "active"),
|
|
),
|
|
)
|
|
.then((rows) => rows),
|
|
db
|
|
.select({ id: instanceUserRoles.id })
|
|
.from(instanceUserRoles)
|
|
.where(and(eq(instanceUserRoles.userId, userId), eq(instanceUserRoles.role, "instance_admin")))
|
|
.then((rows) => rows[0] ?? null),
|
|
]);
|
|
|
|
return {
|
|
user,
|
|
companyIds: memberships.map((row) => row.companyId),
|
|
memberships,
|
|
isInstanceAdmin: Boolean(adminRole),
|
|
};
|
|
}
|
|
|
|
async function resolveBoardActivityCompanyIds(input: {
|
|
userId: string;
|
|
requestedCompanyId?: string | null;
|
|
boardApiKeyId?: string | null;
|
|
}) {
|
|
const access = await resolveBoardAccess(input.userId);
|
|
const companyIds = new Set(access.companyIds);
|
|
|
|
if (companyIds.size === 0 && input.requestedCompanyId?.trim()) {
|
|
companyIds.add(input.requestedCompanyId.trim());
|
|
}
|
|
|
|
if (companyIds.size === 0 && input.boardApiKeyId?.trim()) {
|
|
const challengeCompanyIds = await db
|
|
.select({ requestedCompanyId: cliAuthChallenges.requestedCompanyId })
|
|
.from(cliAuthChallenges)
|
|
.where(eq(cliAuthChallenges.boardApiKeyId, input.boardApiKeyId.trim()))
|
|
.then((rows) =>
|
|
rows
|
|
.map((row) => row.requestedCompanyId?.trim() ?? null)
|
|
.filter((value): value is string => Boolean(value)),
|
|
);
|
|
for (const companyId of challengeCompanyIds) {
|
|
companyIds.add(companyId);
|
|
}
|
|
}
|
|
|
|
if (companyIds.size === 0 && access.isInstanceAdmin) {
|
|
const allCompanyIds = await db
|
|
.select({ id: companies.id })
|
|
.from(companies)
|
|
.then((rows) => rows.map((row) => row.id));
|
|
for (const companyId of allCompanyIds) {
|
|
companyIds.add(companyId);
|
|
}
|
|
}
|
|
|
|
return Array.from(companyIds);
|
|
}
|
|
|
|
async function findBoardApiKeyByToken(token: string) {
|
|
const tokenHash = hashBearerToken(token);
|
|
const now = new Date();
|
|
return db
|
|
.select()
|
|
.from(boardApiKeys)
|
|
.where(
|
|
and(
|
|
eq(boardApiKeys.keyHash, tokenHash),
|
|
isNull(boardApiKeys.revokedAt),
|
|
),
|
|
)
|
|
.then((rows) => rows.find((row) => !row.expiresAt || row.expiresAt.getTime() > now.getTime()) ?? null);
|
|
}
|
|
|
|
async function touchBoardApiKey(id: string) {
|
|
const nowMs = Date.now();
|
|
pruneTouchedBoardApiKeys(nowMs);
|
|
const cached = touchedBoardApiKeys.get(id);
|
|
if (cached?.inFlight) return cached.inFlight;
|
|
if (cached?.completedAt !== null && cached?.completedAt !== undefined
|
|
&& cached.completedAt > nowMs - BOARD_API_KEY_TOUCH_DEBOUNCE_MS) return;
|
|
|
|
const inFlight = db
|
|
.update(boardApiKeys)
|
|
.set({ lastUsedAt: new Date() })
|
|
.where(eq(boardApiKeys.id, id))
|
|
.then(() => {
|
|
touchedBoardApiKeys.delete(id);
|
|
touchedBoardApiKeys.set(id, { completedAt: Date.now(), inFlight: null });
|
|
pruneTouchedBoardApiKeys(Date.now());
|
|
})
|
|
.catch((error) => {
|
|
if (touchedBoardApiKeys.get(id)?.inFlight === inFlight) touchedBoardApiKeys.delete(id);
|
|
throw error;
|
|
});
|
|
touchedBoardApiKeys.set(id, { completedAt: null, inFlight });
|
|
return inFlight;
|
|
}
|
|
|
|
async function revokeBoardApiKey(id: string) {
|
|
const now = new Date();
|
|
return db
|
|
.update(boardApiKeys)
|
|
.set({ revokedAt: now, lastUsedAt: now })
|
|
.where(and(eq(boardApiKeys.id, id), isNull(boardApiKeys.revokedAt)))
|
|
.returning()
|
|
.then((rows) => rows[0] ?? null);
|
|
}
|
|
|
|
async function createNamedBoardApiKey(input: {
|
|
userId: string;
|
|
name: string;
|
|
expiresAt?: Date | null;
|
|
}) {
|
|
const token = createBoardApiToken();
|
|
const created = await db
|
|
.insert(boardApiKeys)
|
|
.values({
|
|
userId: input.userId,
|
|
name: input.name.trim(),
|
|
keyHash: hashBearerToken(token),
|
|
expiresAt: input.expiresAt === undefined ? boardApiKeyExpiresAt() : input.expiresAt,
|
|
})
|
|
.returning()
|
|
.then((rows) => rows[0]);
|
|
|
|
return {
|
|
id: created.id,
|
|
name: created.name,
|
|
token,
|
|
createdAt: created.createdAt,
|
|
lastUsedAt: created.lastUsedAt,
|
|
revokedAt: created.revokedAt,
|
|
expiresAt: created.expiresAt,
|
|
};
|
|
}
|
|
|
|
async function listBoardApiKeys(
|
|
userId: string,
|
|
opts: { includeInactive?: boolean } = {},
|
|
) {
|
|
const conditions = [eq(boardApiKeys.userId, userId)];
|
|
if (!opts.includeInactive) {
|
|
const activeExpirationCondition = or(
|
|
isNull(boardApiKeys.expiresAt),
|
|
gt(boardApiKeys.expiresAt, new Date()),
|
|
);
|
|
conditions.push(
|
|
isNull(boardApiKeys.revokedAt),
|
|
);
|
|
if (activeExpirationCondition) conditions.push(activeExpirationCondition);
|
|
}
|
|
return db
|
|
.select({
|
|
id: boardApiKeys.id,
|
|
name: boardApiKeys.name,
|
|
createdAt: boardApiKeys.createdAt,
|
|
lastUsedAt: boardApiKeys.lastUsedAt,
|
|
revokedAt: boardApiKeys.revokedAt,
|
|
expiresAt: boardApiKeys.expiresAt,
|
|
})
|
|
.from(boardApiKeys)
|
|
.where(and(...conditions))
|
|
.orderBy(sql`${boardApiKeys.createdAt} desc`);
|
|
}
|
|
|
|
async function getBoardApiKeyForUser(keyId: string, userId: string) {
|
|
return db
|
|
.select({
|
|
id: boardApiKeys.id,
|
|
userId: boardApiKeys.userId,
|
|
name: boardApiKeys.name,
|
|
createdAt: boardApiKeys.createdAt,
|
|
lastUsedAt: boardApiKeys.lastUsedAt,
|
|
revokedAt: boardApiKeys.revokedAt,
|
|
expiresAt: boardApiKeys.expiresAt,
|
|
})
|
|
.from(boardApiKeys)
|
|
.where(and(eq(boardApiKeys.id, keyId), eq(boardApiKeys.userId, userId)))
|
|
.then((rows) => rows[0] ?? null);
|
|
}
|
|
|
|
async function createCliAuthChallenge(input: {
|
|
command: string;
|
|
clientName?: string | null;
|
|
requestedAccess: "board" | "instance_admin_required";
|
|
requestedCompanyId?: string | null;
|
|
}) {
|
|
const challengeSecret = createCliAuthSecret();
|
|
const pendingBoardToken = createBoardApiToken();
|
|
const expiresAt = cliAuthChallengeExpiresAt();
|
|
const labelBase = input.clientName?.trim() || "paperclipai cli";
|
|
const pendingKeyName =
|
|
input.requestedAccess === "instance_admin_required"
|
|
? `${labelBase} (instance admin)`
|
|
: `${labelBase} (board)`;
|
|
|
|
const created = await db
|
|
.insert(cliAuthChallenges)
|
|
.values({
|
|
secretHash: hashBearerToken(challengeSecret),
|
|
command: input.command.trim(),
|
|
clientName: input.clientName?.trim() || null,
|
|
requestedAccess: input.requestedAccess,
|
|
requestedCompanyId: input.requestedCompanyId?.trim() || null,
|
|
pendingKeyHash: hashBearerToken(pendingBoardToken),
|
|
pendingKeyName,
|
|
expiresAt,
|
|
})
|
|
.returning()
|
|
.then((rows) => rows[0]);
|
|
|
|
return {
|
|
challenge: created,
|
|
challengeSecret,
|
|
pendingBoardToken,
|
|
};
|
|
}
|
|
|
|
async function getCliAuthChallenge(id: string) {
|
|
return db
|
|
.select()
|
|
.from(cliAuthChallenges)
|
|
.where(eq(cliAuthChallenges.id, id))
|
|
.then((rows) => rows[0] ?? null);
|
|
}
|
|
|
|
async function getCliAuthChallengeBySecret(id: string, token: string) {
|
|
const challenge = await getCliAuthChallenge(id);
|
|
if (!challenge) return null;
|
|
if (!tokenHashesMatch(challenge.secretHash, hashBearerToken(token))) return null;
|
|
return challenge;
|
|
}
|
|
|
|
async function describeCliAuthChallenge(id: string, token: string) {
|
|
const challenge = await getCliAuthChallengeBySecret(id, token);
|
|
if (!challenge) return null;
|
|
|
|
const [company, approvedBy] = await Promise.all([
|
|
challenge.requestedCompanyId
|
|
? db
|
|
.select({ id: companies.id, name: companies.name })
|
|
.from(companies)
|
|
.where(eq(companies.id, challenge.requestedCompanyId))
|
|
.then((rows) => rows[0] ?? null)
|
|
: Promise.resolve(null),
|
|
challenge.approvedByUserId
|
|
? db
|
|
.select({ id: authUsers.id, name: authUsers.name, email: authUsers.email })
|
|
.from(authUsers)
|
|
.where(eq(authUsers.id, challenge.approvedByUserId))
|
|
.then((rows) => rows[0] ?? null)
|
|
: Promise.resolve(null),
|
|
]);
|
|
|
|
return {
|
|
id: challenge.id,
|
|
status: challengeStatusForRow(challenge),
|
|
command: challenge.command,
|
|
clientName: challenge.clientName ?? null,
|
|
requestedAccess: challenge.requestedAccess as "board" | "instance_admin_required",
|
|
requestedCompanyId: challenge.requestedCompanyId ?? null,
|
|
requestedCompanyName: company?.name ?? null,
|
|
approvedAt: challenge.approvedAt?.toISOString() ?? null,
|
|
cancelledAt: challenge.cancelledAt?.toISOString() ?? null,
|
|
expiresAt: challenge.expiresAt.toISOString(),
|
|
approvedByUser: approvedBy
|
|
? {
|
|
id: approvedBy.id,
|
|
name: approvedBy.name,
|
|
email: approvedBy.email,
|
|
}
|
|
: null,
|
|
};
|
|
}
|
|
|
|
async function approveCliAuthChallenge(id: string, token: string, userId: string) {
|
|
const access = await resolveBoardAccess(userId);
|
|
return db.transaction(async (tx) => {
|
|
await tx.execute(
|
|
sql`select ${cliAuthChallenges.id} from ${cliAuthChallenges} where ${cliAuthChallenges.id} = ${id} for update`,
|
|
);
|
|
|
|
const challenge = await tx
|
|
.select()
|
|
.from(cliAuthChallenges)
|
|
.where(eq(cliAuthChallenges.id, id))
|
|
.then((rows) => rows[0] ?? null);
|
|
if (!challenge || !tokenHashesMatch(challenge.secretHash, hashBearerToken(token))) {
|
|
throw notFound("CLI auth challenge not found");
|
|
}
|
|
|
|
const status = challengeStatusForRow(challenge);
|
|
if (status === "expired") return { status, challenge };
|
|
if (status === "cancelled") return { status, challenge };
|
|
|
|
if (challenge.requestedAccess === "instance_admin_required" && !access.isInstanceAdmin) {
|
|
throw forbidden("Instance admin required");
|
|
}
|
|
|
|
let boardKeyId = challenge.boardApiKeyId;
|
|
if (!boardKeyId) {
|
|
const createdKey = await tx
|
|
.insert(boardApiKeys)
|
|
.values({
|
|
userId,
|
|
name: challenge.pendingKeyName,
|
|
keyHash: challenge.pendingKeyHash,
|
|
expiresAt: boardApiKeyExpiresAt(),
|
|
})
|
|
.returning()
|
|
.then((rows) => rows[0]);
|
|
boardKeyId = createdKey.id;
|
|
}
|
|
|
|
const approvedAt = challenge.approvedAt ?? new Date();
|
|
const updated = await tx
|
|
.update(cliAuthChallenges)
|
|
.set({
|
|
approvedByUserId: userId,
|
|
boardApiKeyId: boardKeyId,
|
|
approvedAt,
|
|
updatedAt: new Date(),
|
|
})
|
|
.where(eq(cliAuthChallenges.id, challenge.id))
|
|
.returning()
|
|
.then((rows) => rows[0] ?? challenge);
|
|
|
|
return { status: "approved" as const, challenge: updated };
|
|
});
|
|
}
|
|
|
|
async function cancelCliAuthChallenge(id: string, token: string) {
|
|
const challenge = await getCliAuthChallengeBySecret(id, token);
|
|
if (!challenge) throw notFound("CLI auth challenge not found");
|
|
|
|
const status = challengeStatusForRow(challenge);
|
|
if (status === "approved") return { status, challenge };
|
|
if (status === "expired") return { status, challenge };
|
|
if (status === "cancelled") return { status, challenge };
|
|
|
|
const updated = await db
|
|
.update(cliAuthChallenges)
|
|
.set({
|
|
cancelledAt: new Date(),
|
|
updatedAt: new Date(),
|
|
})
|
|
.where(eq(cliAuthChallenges.id, challenge.id))
|
|
.returning()
|
|
.then((rows) => rows[0] ?? challenge);
|
|
|
|
return { status: "cancelled" as const, challenge: updated };
|
|
}
|
|
|
|
async function assertCurrentBoardKey(keyId: string | undefined, userId: string | undefined) {
|
|
if (!keyId || !userId) throw conflict("Board API key context is required");
|
|
const key = await db
|
|
.select()
|
|
.from(boardApiKeys)
|
|
.where(and(eq(boardApiKeys.id, keyId), eq(boardApiKeys.userId, userId)))
|
|
.then((rows) => rows[0] ?? null);
|
|
if (!key || key.revokedAt) throw notFound("Board API key not found");
|
|
return key;
|
|
}
|
|
|
|
return {
|
|
resolveBoardAccess,
|
|
findBoardApiKeyByToken,
|
|
touchBoardApiKey,
|
|
revokeBoardApiKey,
|
|
createNamedBoardApiKey,
|
|
listBoardApiKeys,
|
|
getBoardApiKeyForUser,
|
|
createCliAuthChallenge,
|
|
getCliAuthChallengeBySecret,
|
|
describeCliAuthChallenge,
|
|
approveCliAuthChallenge,
|
|
cancelCliAuthChallenge,
|
|
assertCurrentBoardKey,
|
|
resolveBoardActivityCompanyIds,
|
|
};
|
|
}
|