fix(access): 统一 API Key 模型权限与列表契约
将全局启用、用户组基线、API Key 专属或排除规则及 scope 按固定顺序求值,避免 Key 越过所属用户组权限,并让运行时候选与模型列表共用同一权限链。 新增 Key 级可分配模型与失效规则诊断接口、OpenAI 兼容 /v1/models 及 rich 列表迁移路径;前端权限弹窗改为按当前 Key 实时加载并支持清理失效规则。 验证:Go 全量测试与 go vet 通过;Web 22 个测试文件共 142 项通过;pnpm lint、pnpm openapi、pnpm build、Compose 配置、gofmt、ShellCheck 和 git diff --check 通过;独立 PostgreSQL 真实配置验收通过。
This commit is contained in:
@@ -530,6 +530,23 @@ export interface GatewayAccessRuleBatchRequest {
|
||||
deleteResources?: GatewayAccessRuleResourceRequest[];
|
||||
}
|
||||
|
||||
export type GatewayAPIKeyRuleDiagnosticReason = 'resource_unavailable' | 'owner_access_revoked' | 'scope_not_allowed';
|
||||
|
||||
export interface GatewayAPIKeyAccessRuleDiagnostic {
|
||||
ruleId: string;
|
||||
resourceType: GatewayAccessResourceType | string;
|
||||
resourceId: string;
|
||||
resourceName?: string;
|
||||
effect: GatewayAccessEffect | string;
|
||||
effective: boolean;
|
||||
reason?: GatewayAPIKeyRuleDiagnosticReason | string;
|
||||
}
|
||||
|
||||
export interface GatewayAPIKeyAssignableModelsResponse {
|
||||
items: PlatformModel[];
|
||||
ruleDiagnostics: GatewayAPIKeyAccessRuleDiagnostic[];
|
||||
}
|
||||
|
||||
export interface GatewayApiKey {
|
||||
id: string;
|
||||
gatewayTenantId?: string;
|
||||
|
||||
Reference in New Issue
Block a user