fix(access): 统一 API Key 模型权限与列表契约

将全局启用、用户组基线、API Key 专属或排除规则及 scope 按固定顺序求值,避免 Key 越过所属用户组权限,并让运行时候选与模型列表共用同一权限链。

新增 Key 级可分配模型与失效规则诊断接口、OpenAI 兼容 /v1/models 及 rich 列表迁移路径;前端权限弹窗改为按当前 Key 实时加载并支持清理失效规则。

验证:Go 全量测试与 go vet 通过;Web 22 个测试文件共 142 项通过;pnpm lint、pnpm openapi、pnpm build、Compose 配置、gofmt、ShellCheck 和 git diff --check 通过;独立 PostgreSQL 真实配置验收通过。
This commit is contained in:
2026-08-03 09:17:15 +08:00
parent c28bf74230
commit cc97e6649c
26 changed files with 2249 additions and 220 deletions
+4 -3
View File
@@ -18,6 +18,7 @@ import type {
GatewayAccessRuleBatchRequest,
GatewayAccessRule,
GatewayAccessRuleUpsertRequest,
GatewayAPIKeyAssignableModelsResponse,
GatewayApiKey,
GatewayApiKeyScopeUpdateRequest,
GatewayAuditLog,
@@ -159,7 +160,7 @@ export async function listModels(token: string): Promise<ListResponse<PlatformMo
}
export async function listPlayableModels(token: string): Promise<ListResponse<PlatformModel>> {
return request<ListResponse<PlatformModel>>('/api/v1/models', { token });
return request<ListResponse<PlatformModel>>('/api/v1/platform-models', { token });
}
export async function listModelCatalog(token: string): Promise<ModelCatalogResponse> {
@@ -461,8 +462,8 @@ export async function listApiKeyAccessRules(token: string): Promise<ListResponse
return request<ListResponse<GatewayAccessRule>>('/api/v1/api-keys/access-rules', { token });
}
export async function listApiKeyAssignableModels(token: string): Promise<ListResponse<PlatformModel>> {
return request<ListResponse<PlatformModel>>('/api/v1/api-keys/assignable-models', { token });
export async function listApiKeyAssignableModels(token: string, apiKeyId: string): Promise<GatewayAPIKeyAssignableModelsResponse> {
return request<GatewayAPIKeyAssignableModelsResponse>(`/api/v1/api-keys/${apiKeyId}/assignable-models`, { token });
}
export async function createAccessRule(token: string, input: GatewayAccessRuleUpsertRequest): Promise<GatewayAccessRule> {