mengstack-api/internal/modules/rbac/.spec/module.md
MengStack Dev df809f1045
Some checks failed
CI / Build & Test (push) Failing after 1m31s
feat: user CRUD API + dashboard stats + kernel infrastructure
- Add user management endpoints (list/create/get/update/delete) with pagination and search
- Add dashboard stats endpoint with tenant/user/online counts and growth metrics
- Add tenant resolver middleware for multi-tenant request scoping
- Add i18n kernel with zh/en message files and AcceptLanguage middleware
- Add WebSocket hub/handler for real-time communication
- Add job scheduler kernel with cron support
- Add plugin sandbox for isolated execution
- Add storage kernel (local filesystem)
- Add event bus kernel for pub/sub
- Add cache kernel abstraction
- Add database migration runner and version upgrade checker
- Add rate limiting middleware with Redis backend
- Add SQL migrations for rbac, audit_logs, settings, notifications, examples
- Extend user repository with list/delete/count operations
- Register all module routes with tenant resolver
2026-10-03 03:42:58 +08:00

1.9 KiB
Raw Blame History

RBAC 模块规范

模块边界

rbac 模块负责权限控制:角色管理、权限点定义、用户-角色关联、接口级鉴权。

属于本模块: 角色、权限点、用户角色关联、权限中间件 不属于本模块: 用户实体(→ auth)、组织部门(→ org)

文件职责

文件 层 职责
domain/role.go 领域 Role 实体
domain/permission.go 领域 Permission 实体
domain/repository.go 领域 RoleRepository/PermissionRepository 接口
application/service.go 应用 角色/权限 CRUD 编排
infrastructure/role_repo.go 基础设施 Role GORM 实现
infrastructure/permission_repo.go 基础设施 Permission GORM 实现
infrastructure/user_role_repo.go 基础设施 用户-角色关联实现
infrastructure/seed.go 基础设施 默认角色/权限种子数据
middleware/permission.go 中间件 接口级权限校验

权限模型

User ←(N:M)→ Role ←(N:M)→ Permission
                              ├── 菜单权限(menu:xxx)
                              └── 操作权限(action:xxx)

接口约定

GET    /api/v1/roles              → 角色列表
POST   /api/v1/roles              → 创建角色
PUT    /api/v1/roles/:id          → 更新角色
DELETE /api/v1/roles/:id          → 删除角色
POST   /api/v1/roles/:id/permissions → 分配权限
GET    /api/v1/permissions        → 权限点列表
POST   /api/v1/users/:id/roles    → 分配角色

数据权限(预留)

五级数据权限范围:全部数据 / 本部门 / 本部门及下属 / 仅本人 / 自定义 当前仅实现接口级鉴权,数据权限待业务模块按需扩展。

禁止

  • 禁止在 domain 层 import gorm
  • 禁止绕过权限中间件直接访问受保护资源
  • 禁止硬编码角色名(角色通过 seed 初始化,可被修改)