chore(contracts): 同步后端 schema 漂移(tenantId / device-identity / policy)+ 修消费方 - #70
Merged
Merged
Conversation
跑 pnpm codegen 一次性吸收 ../gocell develop 的 schema 漂移:
- auth/refresh/v1/request: refreshToken 必填 → 可选
- auth/role/{assign,revoke}/v1/request: 新增必填 tenantId(多租户 epic #1337)
- audit/list/v1/response: data 项新增 tenantId?/scope? + 列掩码文案
- 新落地类型(无 UI 消费,仅契约):admin/health/cells、audit/get、
devicecompliance、deviceidentity/{enroll,renew,revoke,status}、devicestate、
policy/{create,get,list,update,shared}、shared/deviceidentity/certificate-identity
消费方修复(role assign/revoke 必填 tenantId、audit 字段呈现)随后续 commit。
Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
后端 role/assign·revoke 新增必填 tenantId(多租户 epic #1337),消费方同步: - useAuthStore 加 tenantId: string|null(会话身份归属地)。session 契约尚未 暴露租户(BR-009),故恒为 null,待 setSession 后续填充。 - usePoliciesStore.assign/revoke 调 API 前读 auth.tenantId:为 null 抛 TenantUnavailableError(不发请求、不塞假值),否则带上 tenantId。 - PoliciesView catch 将该错误映射到 access.policies.errors.tenantUnavailable inline 文案(zh-CN + en-US)。 - 测试覆盖:有租户→payload 含 tenantId;无租户→抛错且不调 API。 Refs: #66 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
audit/list/v1/response 新增可选 tenantId / scope(多租户列掩码语义,
epic #1337 PR-12)。AuditView 详情面板按现有 correlationId 条件行模式
新增两行:tenantId(mono)与 scope(行分类 tenant/system),仅在字段
非空时渲染——空串(系统行 / 历史行)不显示。i18n 两 locale 补
audit.log.detail.{tenantId,scope}。测试覆盖有值渲染 / 无值省略。
Refs: #66
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
后端 role/assign·revoke 必填 tenantId 但无会话响应透出,前端无来源。 BR-009 请求 login/refresh 响应 data 暴露 tenantId(uuid),后端交付后 前端 setSession 填充 auth.tenantId 即接通角色变更,守门逻辑无需改动。 README 索引同步。 Refs: #66 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
六维度 review Cx1 findings: - useAuthStore.spec:补 tenantId 初始 null + clearSession 重置 null。 - PoliciesView.spec:补 onAssign/onRevoke 将 TenantUnavailableError 映射到 access.policies.errors.tenantUnavailable 的视图级覆盖。 - AuditView:scope 的 dd 加 v1-mono,与 KV 表其余字段视觉一致。 未采纳:setSession 预读 payload.tenantId(需 cast 读契约尚无字段,违反 契约类型纪律;#68 已跟踪该补丁);错误文案改写 / 导出 TenantUnavailableError (YAGNI,当前仅包内消费)。 Refs: #66 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
4 tasks done
This was referenced Jun 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
一次性吸收
../gocelldevelop 的后端 schema 漂移(远超 #27 范围,#27 用未类型化请求体规避),并修复因role/assign·role/revoke新增必填tenantId而会 typecheck 红的消费方,恢复codegen-diff守门 +pnpm -w typecheck一致。真正的多租户角色 UX 是更大的 epic(#68),本 PR 只留集成缝 + 起 BR-009,不建租户上下文。
改动
packages/contracts/src/,全生成物,未手改)auth/refresh/v1/request:refreshToken必填 → 可选(消费方中立)auth/role/{assign,revoke}/v1/request:新增必填tenantIdaudit/list/v1/response:data 项新增tenantId?/scope?+ 列掩码文案admin/health/cells、audit/get、devicecompliance、deviceidentity/{enroll,renew,revoke,status}、devicestate、policy/{create,get,list,update,shared}、shared/deviceidentity/certificate-identityfix):useAuthStore.tenantId: string\|null(恒 null,待 BR-009);usePoliciesStore.assign/revoke守门,无租户抛TenantUnavailableError(不发请求/不塞假值),有则带tenantId;PoliciesView映射到access.policies.errors.tenantUnavailable。feat):AuditView详情区按correlationId模式新增tenantId/scope条件行(仅非空渲染)+ i18n 两 locale。docs):请求后端login/refresh响应暴露tenantId;README 索引同步。涉及包
@gocell/contracts(生成)、@gocell/access、@gocell/audit、@gocell/core(i18n)、docs/backend-requirements。触及
packages/contracts/✅ 因后端 schema 演进(多租户 epic #1337 / 审计列掩码 / device-identity·policy·compliance 新 cell)。全部由
pnpm codegen派生、未手改;codegen-diff守门已本地转绿(产物字节级匹配 raw codegen)。后端漂移已全部落在ghbvf/gocell默认分支develop(CI checkout 的 ref),故 CI 可复现。Test plan
pnpm codegen && git diff --exit-code packages/contracts/src/— cleanpnpm -w typecheck— pass(消费方未漂)pnpm -w lint— 0 issuespnpm -w test --run— 1757 passed (118 files)关联
Closes #66
Refs BR-009 → gocell #2324(后端透出 tenantId)、#68(前端多租户角色 UX epic)、#69(health/cells 迁移 follow-up)
🤖 Generated with Claude Code