Some checks failed
CI / Build & Test (push) Failing after 1m31s
- Add user management endpoints (list/create/get/update/delete) with pagination and search - Add dashboard stats endpoint with tenant/user/online counts and growth metrics - Add tenant resolver middleware for multi-tenant request scoping - Add i18n kernel with zh/en message files and AcceptLanguage middleware - Add WebSocket hub/handler for real-time communication - Add job scheduler kernel with cron support - Add plugin sandbox for isolated execution - Add storage kernel (local filesystem) - Add event bus kernel for pub/sub - Add cache kernel abstraction - Add database migration runner and version upgrade checker - Add rate limiting middleware with Redis backend - Add SQL migrations for rbac, audit_logs, settings, notifications, examples - Extend user repository with list/delete/count operations - Register all module routes with tenant resolver
54 lines
1.9 KiB
Markdown
54 lines
1.9 KiB
Markdown
# RBAC 模块规范
|
||
|
||
## 模块边界
|
||
|
||
rbac 模块负责权限控制:角色管理、权限点定义、用户-角色关联、接口级鉴权。
|
||
|
||
**属于本模块:** 角色、权限点、用户角色关联、权限中间件
|
||
**不属于本模块:** 用户实体(→ auth)、组织部门(→ org)
|
||
|
||
## 文件职责
|
||
|
||
| 文件 | 层 | 职责 |
|
||
|------|---|------|
|
||
| `domain/role.go` | 领域 | Role 实体 |
|
||
| `domain/permission.go` | 领域 | Permission 实体 |
|
||
| `domain/repository.go` | 领域 | RoleRepository/PermissionRepository 接口 |
|
||
| `application/service.go` | 应用 | 角色/权限 CRUD 编排 |
|
||
| `infrastructure/role_repo.go` | 基础设施 | Role GORM 实现 |
|
||
| `infrastructure/permission_repo.go` | 基础设施 | Permission GORM 实现 |
|
||
| `infrastructure/user_role_repo.go` | 基础设施 | 用户-角色关联实现 |
|
||
| `infrastructure/seed.go` | 基础设施 | 默认角色/权限种子数据 |
|
||
| `middleware/permission.go` | 中间件 | 接口级权限校验 |
|
||
|
||
## 权限模型
|
||
|
||
```
|
||
User ←(N:M)→ Role ←(N:M)→ Permission
|
||
├── 菜单权限(menu:xxx)
|
||
└── 操作权限(action:xxx)
|
||
```
|
||
|
||
## 接口约定
|
||
|
||
```
|
||
GET /api/v1/roles → 角色列表
|
||
POST /api/v1/roles → 创建角色
|
||
PUT /api/v1/roles/:id → 更新角色
|
||
DELETE /api/v1/roles/:id → 删除角色
|
||
POST /api/v1/roles/:id/permissions → 分配权限
|
||
GET /api/v1/permissions → 权限点列表
|
||
POST /api/v1/users/:id/roles → 分配角色
|
||
```
|
||
|
||
## 数据权限(预留)
|
||
|
||
五级数据权限范围:全部数据 / 本部门 / 本部门及下属 / 仅本人 / 自定义
|
||
当前仅实现接口级鉴权,数据权限待业务模块按需扩展。
|
||
|
||
## 禁止
|
||
|
||
- 禁止在 domain 层 import gorm
|
||
- 禁止绕过权限中间件直接访问受保护资源
|
||
- 禁止硬编码角色名(角色通过 seed 初始化,可被修改)
|