mengstack-api/internal/modules/rbac/.spec/module.md
MengStack Dev df809f1045
Some checks failed
CI / Build & Test (push) Failing after 1m31s
feat: user CRUD API + dashboard stats + kernel infrastructure
- Add user management endpoints (list/create/get/update/delete) with pagination and search
- Add dashboard stats endpoint with tenant/user/online counts and growth metrics
- Add tenant resolver middleware for multi-tenant request scoping
- Add i18n kernel with zh/en message files and AcceptLanguage middleware
- Add WebSocket hub/handler for real-time communication
- Add job scheduler kernel with cron support
- Add plugin sandbox for isolated execution
- Add storage kernel (local filesystem)
- Add event bus kernel for pub/sub
- Add cache kernel abstraction
- Add database migration runner and version upgrade checker
- Add rate limiting middleware with Redis backend
- Add SQL migrations for rbac, audit_logs, settings, notifications, examples
- Extend user repository with list/delete/count operations
- Register all module routes with tenant resolver
2026-10-03 03:42:58 +08:00

54 lines
1.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# RBAC 模块规范
## 模块边界
rbac 模块负责权限控制:角色管理、权限点定义、用户-角色关联、接口级鉴权。
**属于本模块:** 角色、权限点、用户角色关联、权限中间件
**不属于本模块:** 用户实体(→ auth)、组织部门(→ org)
## 文件职责
| 文件 | 层 | 职责 |
|------|---|------|
| `domain/role.go` | 领域 | Role 实体 |
| `domain/permission.go` | 领域 | Permission 实体 |
| `domain/repository.go` | 领域 | RoleRepository/PermissionRepository 接口 |
| `application/service.go` | 应用 | 角色/权限 CRUD 编排 |
| `infrastructure/role_repo.go` | 基础设施 | Role GORM 实现 |
| `infrastructure/permission_repo.go` | 基础设施 | Permission GORM 实现 |
| `infrastructure/user_role_repo.go` | 基础设施 | 用户-角色关联实现 |
| `infrastructure/seed.go` | 基础设施 | 默认角色/权限种子数据 |
| `middleware/permission.go` | 中间件 | 接口级权限校验 |
## 权限模型
```
User ←(N:M)→ Role ←(N:M)→ Permission
├── 菜单权限(menu:xxx)
└── 操作权限(action:xxx)
```
## 接口约定
```
GET /api/v1/roles → 角色列表
POST /api/v1/roles → 创建角色
PUT /api/v1/roles/:id → 更新角色
DELETE /api/v1/roles/:id → 删除角色
POST /api/v1/roles/:id/permissions → 分配权限
GET /api/v1/permissions → 权限点列表
POST /api/v1/users/:id/roles → 分配角色
```
## 数据权限(预留)
五级数据权限范围:全部数据 / 本部门 / 本部门及下属 / 仅本人 / 自定义
当前仅实现接口级鉴权,数据权限待业务模块按需扩展。
## 禁止
- 禁止在 domain 层 import gorm
- 禁止绕过权限中间件直接访问受保护资源
- 禁止硬编码角色名(角色通过 seed 初始化,可被修改)