feat(identity): 收敛 AI Gateway 统一认证入口

Web 登录页合并为单一统一认证入口,未指定上下文时由认证中心在登录后决策。继续接受旧客户端显式传入 platform 或 tenant,并保持回调上下文及 tenant_hint 的绑定校验。同步更新 OpenAPI 产物。\n\n验证:Go 全量测试与 go vet 通过;Web lint、141 项 Vitest 和生产构建通过;本地 platform.admin 登录及管理工作台访问通过。
This commit is contained in:
2026-07-31 15:28:12 +08:00
parent c0296dbf06
commit 59f0817938
13 changed files with 186 additions and 69 deletions
+7 -5
View File
@@ -86,14 +86,14 @@ func (c *OIDCPublicClient) AuthorizationURL(
return "", errors.New("state, nonce and PKCE verifier are required")
}
contextType = strings.TrimSpace(contextType)
if contextType != "platform" && contextType != "tenant" {
return "", errors.New("context type must be platform or tenant")
if contextType != "" && contextType != "platform" && contextType != "tenant" {
return "", errors.New("context type must be empty, platform or tenant")
}
if strings.TrimSpace(tenantHint) != "" && uuid.Validate(strings.TrimSpace(tenantHint)) != nil {
return "", errors.New("tenant hint must be a UUID")
}
if contextType == "platform" && strings.TrimSpace(tenantHint) != "" {
return "", errors.New("platform context cannot bind a tenant hint")
if contextType != "tenant" && strings.TrimSpace(tenantHint) != "" {
return "", errors.New("only tenant context can bind a tenant hint")
}
config, _, err := c.configuration(ctx)
if err != nil {
@@ -102,7 +102,9 @@ func (c *OIDCPublicClient) AuthorizationURL(
options := []oauth2.AuthCodeOption{
oidc.Nonce(nonce),
oauth2.S256ChallengeOption(pkceVerifier),
oauth2.SetAuthURLParam("context_type", contextType),
}
if contextType != "" {
options = append(options, oauth2.SetAuthURLParam("context_type", contextType))
}
if strings.TrimSpace(tenantHint) != "" {
options = append(options, oauth2.SetAuthURLParam("tenant_hint", strings.TrimSpace(tenantHint)))