Skip to content

chore(contracts): 同步后端 schema 漂移(tenantId / device-identity / policy)+ 修消费方 - #70

Merged
ghbvf merged 5 commits into
developfrom
201-contracts-tenant-drift
Jun 17, 2026
Merged

ghbvf merged 5 commits into
developfrom
201-contracts-tenant-drift

Conversation

@ghbvf

@ghbvf ghbvf commented Jun 17, 2026

Copy link
Copy Markdown
Owner

Summary

一次性吸收 ../gocell develop 的后端 schema 漂移(远超 #27 范围,#27 用未类型化请求体规避),并修复因 role/assign·role/revoke 新增必填 tenantId 而会 typecheck 红的消费方,恢复 codegen-diff 守门 + pnpm -w typecheck 一致。

真正的多租户角色 UX 是更大的 epic(#68),本 PR 只留集成缝 + 起 BR-009,不建租户上下文。

改动

  1. codegen 吸收漂移(packages/contracts/src/,全生成物,未手改)
    • auth/refresh/v1/request:refreshToken 必填 → 可选(消费方中立)
    • auth/role/{assign,revoke}/v1/request:新增必填 tenantId
    • audit/list/v1/response:data 项新增 tenantId?/scope? + 列掩码文案
    • 新落地类型(仅契约,无 UI 消费):admin/health/cells、audit/get、devicecompliance、deviceidentity/{enroll,renew,revoke,status}、devicestate、policy/{create,get,list,update,shared}、shared/deviceidentity/certificate-identity
  2. access tenantId 消费方(fix):useAuthStore.tenantId: string\|null(恒 null,待 BR-009);usePoliciesStore.assign/revoke 守门,无租户抛 TenantUnavailableError(不发请求/不塞假值),有则带 tenantId;PoliciesView 映射到 access.policies.errors.tenantUnavailable。
  3. audit 详情面板(feat):AuditView 详情区按 correlationId 模式新增 tenantId/scope 条件行(仅非空渲染)+ i18n 两 locale。
  4. BR-009(docs):请求后端 login/refresh 响应暴露 tenantId;README 索引同步。

涉及包

@gocell/contracts(生成)、@gocell/access、@gocell/audit、@gocell/core(i18n)、docs/backend-requirements。

触及 packages/contracts/

✅ 因后端 schema 演进(多租户 epic #1337 / 审计列掩码 / device-identity·policy·compliance 新 cell)。全部由 pnpm codegen 派生、未手改;codegen-diff 守门已本地转绿(产物字节级匹配 raw codegen)。后端漂移已全部落在 ghbvf/gocell 默认分支 develop(CI checkout 的 ref),故 CI 可复现。

Test plan

  • pnpm codegen && git diff --exit-code packages/contracts/src/ — clean
  • pnpm -w typecheck — pass(消费方未漂)
  • pnpm -w lint — 0 issues
  • pnpm -w test --run — 1757 passed (118 files)
  • access:有租户→payload 含 tenantId;无租户→抛错且不调 API
  • audit:详情面板对含 tenantId/scope 条目渲染新行、为空省略

关联

Closes #66
Refs BR-009 → gocell #2324(后端透出 tenantId)、#68(前端多租户角色 UX epic)、#69(health/cells 迁移 follow-up)

🤖 Generated with Claude Code

ghbvf and others added 5 commits June 18, 2026 00:27
跑 pnpm codegen 一次性吸收 ../gocell develop 的 schema 漂移:
- auth/refresh/v1/request: refreshToken 必填 → 可选
- auth/role/{assign,revoke}/v1/request: 新增必填 tenantId(多租户 epic #1337)
- audit/list/v1/response: data 项新增 tenantId?/scope? + 列掩码文案
- 新落地类型(无 UI 消费,仅契约):admin/health/cells、audit/get、
  devicecompliance、deviceidentity/{enroll,renew,revoke,status}、devicestate、
  policy/{create,get,list,update,shared}、shared/deviceidentity/certificate-identity

消费方修复(role assign/revoke 必填 tenantId、audit 字段呈现)随后续 commit。

Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
后端 role/assign·revoke 新增必填 tenantId(多租户 epic #1337),消费方同步:
- useAuthStore 加 tenantId: string|null(会话身份归属地)。session 契约尚未
  暴露租户(BR-009),故恒为 null,待 setSession 后续填充。
- usePoliciesStore.assign/revoke 调 API 前读 auth.tenantId:为 null 抛
  TenantUnavailableError(不发请求、不塞假值),否则带上 tenantId。
- PoliciesView catch 将该错误映射到 access.policies.errors.tenantUnavailable
  inline 文案(zh-CN + en-US)。
- 测试覆盖:有租户→payload 含 tenantId;无租户→抛错且不调 API。

Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
audit/list/v1/response 新增可选 tenantId / scope(多租户列掩码语义,
epic #1337 PR-12)。AuditView 详情面板按现有 correlationId 条件行模式
新增两行:tenantId(mono)与 scope(行分类 tenant/system),仅在字段
非空时渲染——空串(系统行 / 历史行)不显示。i18n 两 locale 补
audit.log.detail.{tenantId,scope}。测试覆盖有值渲染 / 无值省略。

Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
后端 role/assign·revoke 必填 tenantId 但无会话响应透出,前端无来源。
BR-009 请求 login/refresh 响应 data 暴露 tenantId(uuid),后端交付后
前端 setSession 填充 auth.tenantId 即接通角色变更,守门逻辑无需改动。
README 索引同步。

Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
六维度 review Cx1 findings:
- useAuthStore.spec:补 tenantId 初始 null + clearSession 重置 null。
- PoliciesView.spec:补 onAssign/onRevoke 将 TenantUnavailableError 映射到
  access.policies.errors.tenantUnavailable 的视图级覆盖。
- AuditView:scope 的 dd 加 v1-mono,与 KV 表其余字段视觉一致。

未采纳:setSession 预读 payload.tenantId(需 cast 读契约尚无字段,违反
契约类型纪律;#68 已跟踪该补丁);错误文案改写 / 导出 TenantUnavailableError
(YAGNI,当前仅包内消费)。

Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(contracts): 同步后端 schema 漂移(多租户 tenantId / device-identity / policy 导出)+ 修消费方

1 participant