feat(database): init database folder frontend and permission

This commit is contained in:
ymy
2026-07-23 23:41:11 +08:00
parent 5df1900ca8
commit 4021e58d5d
67 changed files with 9436 additions and 150 deletions
@@ -0,0 +1,10 @@
{
"sessionID": "ses_0705f8afbffePWIq7GrFfwfFwV",
"updatedAt": "2026-07-23T15:40:15.630Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-23T15:40:15.630Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07252990dffeRFmXnvdyynty2z",
"updatedAt": "2026-07-23T06:33:33.086Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-23T06:33:33.086Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_075d214a0ffe6mU8VNgukUfH5L",
"updatedAt": "2026-07-22T14:15:01.741Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-22T14:15:01.741Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_075d3282bffejz0HFE00taOaGM",
"updatedAt": "2026-07-22T14:13:54.785Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-22T14:13:54.785Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_0781484caffeKJHXVKiD4BqEJw",
"updatedAt": "2026-07-22T06:17:18.238Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-22T06:17:18.238Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b163c13ffeudULxSfIfK986T",
"updatedAt": "2026-07-21T13:55:58.878Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T13:55:58.878Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b1e6c8effeq7bdmj6NgO0LqC",
"updatedAt": "2026-07-21T13:38:01.132Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T13:38:01.132Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b932dddffecSipFLwlJOvoJ9",
"updatedAt": "2026-07-21T11:27:10.420Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T11:27:10.420Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b9c4268ffeic4mMXCPUt225j",
"updatedAt": "2026-07-21T11:18:53.449Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T11:18:53.449Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b9c4346ffeVBdV5pf4h6s9PW",
"updatedAt": "2026-07-21T11:18:29.979Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T11:18:29.979Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07b9c9a75ffeOyJ4ewp3DBvXhz",
"updatedAt": "2026-07-21T11:21:09.776Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-21T11:21:09.776Z"
}
}
}
@@ -0,0 +1,10 @@
{
"sessionID": "ses_07cdbac0effeiBrdcHLUUUfwuF",
"updatedAt": "2026-07-23T15:37:59.918Z",
"sources": {
"background-task": {
"state": "idle",
"updatedAt": "2026-07-23T15:37:59.918Z"
}
}
}
+114
View File
@@ -0,0 +1,114 @@
# 文件库 · 开工计划(v1.0
> 配套文档:《文件库-接口契约.md》(v0.1,仓库根目录)。本计划已吸收规划顾问评审意见,包含开工前必须先冻结的**架构收口决策 D11–D19**(回写契约 v0.2 时并入)。
> 工期按 1 人全栈估算;前端从 Phase 2 后可并行。
## 开工判定
**可以开工。** 四个外部依赖(版本包 / Group / 审计 / 平台身份)全部有契约可依、可 mock 并行开发;无阻塞项。唯一前置:本文件的 D11–D19 决策在写第一行 schema 前过一遍(半天,自查即可,有异议再升级)。
## 架构收口决策(新增,先冻结再动工)
| 编号 | 决策 | 理由 |
|---|---|---|
| D11 | `creator` 是 Node 的**不可变列**,创建时同时落一条 Manage grant;独立权限开关关闭时,**creator 的 Manage 仍生效**,其余项目级 grant 冻结不参与计算 | 否则 creator 可能被自己关掉的开关锁死 |
| D12 | 移动节点授权 = **本节点 Manage + 目标父 Edit+**;移动在事务 + Postgres 咨询锁内完成,防并发成环 | 预检环检测在并发下不安全 |
| D13 | Group resolve 失败返回 **503**(不伪装 404/403);每次 HTTP 请求 fresh resolve,不跨请求缓存;单请求内多次校验合并为一次调用(此点与 Group 团队确认,OPEN-9) | 依赖故障 ≠ 无权限;契约 G4 要求实时 |
| D14 | 命名规则:NFC 归一化、trim、≤128 字符、禁 `/` 与控制字符;**活跃兄弟节点大小写不敏感唯一**;根节点全局唯一 | 缺命名规则必有脏数据 |
| D15 | 删除 = 只给被删节点打标,后代**不递归打标**,靠"任一祖先已删"过滤;所有查询链路强制此过滤(含递归 SQL,不只靠 Prisma middleware) | 递归打标的写放大与恢复复杂度不可控 |
| D16 | `baseVersion` 为**文件级版本**GET file 返回的 version);无关文件的提交不产生冲突 | 与 C1 `head(dir, filePath)` 语义一致 |
| D17 | breadcrumb 只暴露用户有 View 的祖先名称;无权限祖先显示占位符 `…`,不暴露名字 | 404 不泄露语义(D8)延伸到面包屑 |
| D18 | v1 **单副本部署**(git 仓库在本地磁盘);多副本需共享存储或分片,后置 | 不解决不存在的扩展问题 |
| D19 | 网站管理员**不隐式读内容**force_adjust 凭 node id 操作(id 从审计或用户上报获得) | C4 已定的最小权限原则 |
## 阶段计划
### Phase 0 · 骨架与身份先行(1–2 天)
- [ ] 过 D11D19,回写契约 v0.2
- [ ] repo 骨架 `server/` + `web/`Postgres docker-composeCIlint / typecheck / vitest / 集成测试用真实 Postgres service container
- [ ] **JWT 中间件 + 本地 JWKS 测试服务 + 签名 token fixtures**(有效/过期/错 issuer/错 audience/错算法/未知 kid/轮换)——身份先行,不做"宽松 mock 身份"
- [ ] 4 个 port 接口定义 + mock`VersionStore``GroupResolver``AuditSink`(直写 outbox 表的实现就是真的,mock 的是对端服务)、`ExportAdapter`
- [ ] fastify-swagger 接入,OpenAPI 骨架——**OpenAPI 随每个端点同步产出,不留到最后**
- **验收**:骨架可 `pnpm dev` 起服务;本地 JWKS 六类 token fixture(有效/过期/错 issuer/错 audience/错算法/未知 kid)中间件行为全对;CI 流水线绿
### Phase 1 · 数据模型与权限引擎(2–3 天)⚑ 心脏
- [ ] Prisma schema`Node`parentId **权威** + id 编码的 materialized path 派生列,name 不入 path)、`Grant``ProjectIndependentSettings``OutboxEvent`(含 attempts/nextAttemptAt/lease/lastErrorrelay 字段一次到位)、`ExportJob`
- [ ] 数据库约束:kind 枚举、项目无子节点、活跃兄弟名唯一(部分唯一索引,root 的 NULL parent 特殊处理)、活跃 grant 按 (nodeId, principalType, principalId) 唯一、独立设置仅项目
- [ ] **纯权限 reducer**:输入已解析的 grants + 祖先链 + 用户组集合,输出 role|null;不碰 DB/网络。fast-check 属性测试:max 单调、加 grant 只升不降、祖先继承、toggle 行为、顺序无关、软删过滤
- [ ] 数据获取层 + `effective(user, node)` 组装
- [ ] 树操作服务:createcreator 自动 Manage、root 仅管理员且必带 ≥1 Manage)、rename、moveD12 事务+咨询锁)、soft deleteD15)、breadcrumbD17
- **验收**:并发对移(A→B 与 B→A)、移动+并发建子、property tests、删除祖先过滤,真实 Postgres 全绿
### Phase 2 · 树与授权 API12 天)
- [ ] nodes 端点组 + grants 端点组 + independent-permission 开关 + effective-permission 自查
- [ ] 授权矩阵校验(契约 8.1creator-only 授 Manage、Manage 不可动 creator、force_adjust 独立通道)
- [ ] 全部写操作落 outbox 事件(C3 词汇表)
- **验收**:契约 8.1 矩阵逐格 API 测试;D8 的 404/403/503 三分语义测试
### Phase 3 · 仓库生命周期与文件 API(2 天)
- [ ] 项目 provisioning 状态机 `PROVISIONING → READY | FAILED`:先建 DB 行(PROVISIONING)→ 调 `VersionStore.init`(幂等)→ 置 READY;失败可重试;孤儿仓库对账 job
- [ ] 每项目写锁(Postgres 咨询锁,跨进程安全)——不假设版本包能跨进程串行
- [ ] 路径安全:canonical 后必须落在项目根内、拒绝 `.git`、禁 symlink 逃逸、路径长度上限
- [ ] 上传限额(单文件 10MB / 单项目配额,数值 OPEN-5)+ 流式接收
- [ ] files 端点组全量(list/read/upload/commits→409/diff/history/delete+ 双客户端冲突 e2e
- **验收**DB/git 故障注入(init 失败、提交后崩溃)→ 对账能收敛;路径穿越语料库测试全拒
### Phase 4 · 外部集成(12 天)
- [ ] `GroupResolver` HTTP client:超时/5xx/429/畸形 JSON/万级 group 的故障注入测试;失败 → 503(D13)
- [ ] Audit relay worker:租约领取、指数退避、eventId 幂等、重启恢复、积压告警
- [ ] 导出 job:状态机 + 轮询 + 下载权限校验;`ExportAdapter` 桩(参数 OPEN-6 未定前**不计入完成标准**)
- **验收**:relay 重启不丢不重(对端幂等);group 故障时写操作 503、读操作按 D13
### Phase 5 · 前端(35 天,Phase 2 后并行启动)
- [ ] 登录(平台 SSO 占位 + 本地 JWKS 直通开关)
- [ ] 树浏览(懒加载 + 分页)、breadcrumb(D17 占位符)、创建对话框(类型 + 批量授权选择器,Group search 接 C2
- [ ] 权限管理面板(按 8.1 矩阵控制可选项,creator 标识)
- [ ] 文件页:查看/上传/下载/历史列表(编辑 UI 不归我方,留对接位)
- [ ] 导出按钮 + job 轮询
- **验收**:无权限节点全链路不可见;授权面板不会送出矩阵禁止的组合
### Phase 6 · 硬化与交付(12 天)
- [ ] 404/403/503 全端点核对;并发与重试幂等抽查
- [ ] 备份脚本(DB + git 仓库一致性快照)、健康检查(DB/JWKS/磁盘/Group)、磁盘水位告警
- [ ] OpenAPI 终稿 + 部署脚本 + 一页运维手册
## 里程碑
| 里程碑 | 内容 | 累计工期 |
|---|---|---|
| M1 | Phase 0–1:骨架 + 权限引擎 + 树操作可跑 | ~4 天 |
| M2 | Phase 2–3:后端 API 全量(含文件冲突流) | ~7 天 |
| M3 | Phase 4:外部集成(导出不计) | ~9 天 |
| M4 | Phase 56:前端 + 硬化,可交付 | ~14–18 天 |
## Mock 保真红线(mock 可以顶,但不许骗)
| Mock | 不许掩盖的事 | 真身到位后的契约测试 |
|---|---|---|
| VersionStore | 磁盘延迟、半初始化、锁残留、跨进程并发 | 真包跑临时仓库:并发 commit/init 重试/遍历与 symlink 语料 |
| GroupResolver | 超时、5xx、畸形响应、大规模组集 | 故障注入 HTTP 桩全过;我方绝不自己推祖先 |
| GroupSearch(前端选择器) | 与 resolve 是**两个独立端点**,不可用 resolve mock 顶替 | C2 `/groups/search` 真身到位后跑分页/空结果/超时 |
| Audit 对端 | 重复投递、乱序、长时间不可用 | relay 重启恢复 + 对端幂等 |
| JWT | issuer/audience/算法/轮换 | 本地 JWKS 全用例 |
| ExportAdapter | 参数、幂等、耗时 | 参数定了再写,之前不算完成 |
## Top 5 风险
1. **DB/git 分裂**(崩溃导致元数据、仓库、审计三边不一致)→ provisioning 状态机 + 对账 jobPhase 3 前置
2. **移动子树改变整树权限** → D12 事务+锁+源目标双授权,并发测试
3. **creator/独立权限开关交互** → D11 先冻结
4. **外部契约缺口**(导出参数、请求内 resolve 合并)→ OPEN 清单跟踪,mock 保真红线不许掩盖
5. **存储滥用/路径逃逸** → 路径安全 + 配额进 Phase 3 验收,不拖到硬化
## OPEN 清单(在契约文档基础上增补)
- OPEN-9:单请求内合并多次 resolve 是否符合 G4"实时"语义(找 Group 团队确认)
- OPEN-10:恶意软件扫描归属(我方/平台/不做)
- 其余 OPEN-1~8 见《文件库-接口契约.md》第 10 节
+12
View File
@@ -0,0 +1,12 @@
<!doctype html>
<html lang="zh-CN">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>文件库</title>
</head>
<body>
<div id="app"></div>
<script type="module" src="/src/main.ts"></script>
</body>
</html>
+1621
View File
File diff suppressed because it is too large Load Diff
+21
View File
@@ -0,0 +1,21 @@
{
"name": "filelib-web",
"private": true,
"version": "0.1.0",
"type": "module",
"scripts": {
"dev": "vite",
"build": "vite build",
"preview": "vite preview",
"check": "svelte-check --tsconfig ./tsconfig.json"
},
"devDependencies": {
"@sveltejs/vite-plugin-svelte": "^7.1.2",
"@tailwindcss/vite": "^4.3.2",
"svelte": "^5.56.1",
"svelte-check": "^4.6.0",
"tailwindcss": "^4.3.2",
"typescript": "^5.7.0",
"vite": "^8.0.16"
}
}
+30
View File
@@ -0,0 +1,30 @@
<script lang="ts">
import { onMount } from "svelte";
import { api, UnauthenticatedError } from "./lib/api.js";
import { me, authChecked } from "./lib/stores.js";
import type { MeResponse } from "./lib/types.js";
import LoginView from "./lib/LoginView.svelte";
import BrowserShell from "./lib/BrowserShell.svelte";
import Toasts from "./lib/Toasts.svelte";
onMount(async () => {
try {
me.set(await api<MeResponse>("/database/api/me"));
} catch (e) {
if (!(e instanceof UnauthenticatedError)) console.error(e);
me.set(null);
} finally {
authChecked.set(true);
}
});
</script>
{#if !$authChecked}
<div class="flex h-full items-center justify-center text-ink-3">加载中…</div>
{:else if $me}
<BrowserShell />
{:else}
<LoginView />
{/if}
<Toasts />
+66
View File
@@ -0,0 +1,66 @@
@import "tailwindcss";
/* 全局 UI 主题令牌(与 hub 端 uiTheme.ts 同源) */
@theme {
--color-bg: #fcfcfb;
--color-panel: #ffffff;
--color-sidebar: #f7f7f5;
--color-ink: #1a1a18;
--color-ink-2: #6b6a66;
--color-ink-3: #9c9b96;
--color-line: #ecece8;
--color-line-soft: #f1f1ee;
--color-hover: #f4f4f1;
--color-selected: #ebebe7;
--color-accent: #1a1a18;
--color-accent-hover: #333330;
--color-danger: #a13a33;
--color-guide: #e9e9e5;
--color-diff-add-bg: #f3f6f2;
--color-diff-add-text: #4a6741;
--color-diff-del-bg: #f8f2f1;
--color-diff-del-text: #a13a33;
}
html,
body,
#app {
height: 100%;
}
body {
background: var(--color-bg);
color: var(--color-ink);
font-family:
"Inter",
-apple-system,
"Segoe UI",
"PingFang SC",
"Microsoft YaHei",
sans-serif;
font-size: 14px;
line-height: 1.65;
-webkit-font-smoothing: antialiased;
}
.font-mono {
font-family: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
}
/* diff 渲染 */
pre.diff {
white-space: pre-wrap;
font-family: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
font-size: 12.5px;
line-height: 1.75;
}
pre.diff .add {
display: block;
color: var(--color-diff-add-text);
background: var(--color-diff-add-bg);
}
pre.diff .del {
display: block;
color: var(--color-diff-del-text);
background: var(--color-diff-del-bg);
}
+141
View File
@@ -0,0 +1,141 @@
<script lang="ts">
import { onMount } from "svelte";
import { api } from "./api.js";
import { me, toastErr, toastOk } from "./stores.js";
import { treeVersion, bumpTree, currentNode, selectedFilePath, clearSelectedFile, bumpFiles } from "./browser.js";
import type { NodeChild } from "./types.js";
import TreeNode from "./TreeNode.svelte";
import NodeDetailPanel from "./NodeDetailPanel.svelte";
import FileEditor from "./FileEditor.svelte";
import Modal from "./Modal.svelte";
let roots = $state<NodeChild[] | null>(null);
let treeError = $state<string | null>(null);
let showCreateRoot = $state(false);
let newName = $state("");
let newKind = $state<"FOLDER" | "PROJECT">("FOLDER");
let newDesc = $state("");
async function loadRoots(): Promise<void> {
try {
const r = await api<{ nodes: NodeChild[] }>("/database/api/nodes");
roots = r.nodes;
treeError = null;
} catch (e) {
treeError = e instanceof Error ? e.message : String(e);
}
}
onMount(loadRoots);
$effect(() => {
void $treeVersion;
void loadRoots();
});
async function createRoot(): Promise<void> {
const name = newName.trim();
if (name === "") return;
try {
await api("/database/api/nodes", {
method: "POST",
body: {
parentId: null,
kind: newKind,
name,
...(newDesc.trim() !== "" ? { description: newDesc.trim() } : {}),
},
});
toastOk("已创建");
showCreateRoot = false;
newName = ""; newKind = "FOLDER"; newDesc = "";
bumpTree();
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function logout(): Promise<void> {
try { await fetch("/auth/logout", { method: "POST", credentials: "same-origin" }); } catch { /* ignore */ }
me.set(null);
}
const initial = $derived(($me?.userId ?? "U").slice(0, 1).toUpperCase());
</script>
<div class="flex h-full">
<!-- 侧栏 -->
<aside class="flex w-[300px] shrink-0 flex-col border-r border-line-soft bg-sidebar">
<div class="flex items-center justify-between border-b border-line-soft px-4 py-3.5">
<span class="text-[15px] font-semibold text-ink">文件库</span>
{#if $me?.isWebsiteAdmin}
<button class="rounded-lg border border-line bg-panel px-2.5 py-1 text-[11.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showCreateRoot = true)}>
+ 根目录
</button>
{/if}
</div>
<div class="flex-1 overflow-y-auto px-2 py-2 text-[13px]">
{#if roots === null}
<div class="px-3 py-6 text-center text-xs text-ink-3">加载中…</div>
{:else if treeError}
<div class="px-3 py-6 text-center text-xs text-danger">{treeError}</div>
{:else if roots.length === 0}
<div class="px-3 py-6 text-center text-xs text-ink-3">
{$me?.isWebsiteAdmin ? "空文件库 · 点上方「+ 根目录」开始" : "文件库为空,请联系管理员创建根目录"}
</div>
{:else}
{#each roots as node (node.id)}
<TreeNode {node} depth={0} />
{/each}
{/if}
</div>
<div class="flex items-center gap-2 border-t border-line-soft px-4 py-3 text-[12.5px]">
<div class="flex h-6 w-6 shrink-0 items-center justify-center rounded-full bg-accent text-[11px] font-semibold text-white">{initial}</div>
<span class="flex-1 truncate text-ink">{$me?.userId ?? ""}</span>
<button class="rounded-lg border border-line-soft px-2.5 py-1 text-[11.5px] text-ink-3 transition hover:bg-hover hover:text-ink" onclick={logout} title="退出登录">退出</button>
</div>
</aside>
<!-- 主区 -->
<main class="flex-1 overflow-y-auto">
<NodeDetailPanel />
</main>
<!-- 右侧:文件预览/编辑栏(选中文件时出现) -->
{#if $selectedFilePath && $currentNode?.kind === "PROJECT"}
<section class="flex w-[46%] min-w-[420px] shrink-0 flex-col overflow-y-auto border-l border-line-soft bg-bg p-4">
<FileEditor
projectId={$currentNode.id}
path={$selectedFilePath}
role={$currentNode.role}
onchanged={bumpFiles}
onclose={clearSelectedFile}
/>
</section>
{/if}
</div>
{#if showCreateRoot}
<Modal title="新建根目录" onclose={() => (showCreateRoot = false)}>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="root-name">名称</label>
<input id="root-name" class="w-full rounded-lg border border-line bg-panel px-3 py-2 text-[13px] outline-none focus:border-accent" bind:value={newName} placeholder="例如:物理教研" />
</div>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="root-kind">类型</label>
<select id="root-kind" class="w-full rounded-lg border border-line bg-panel px-3 py-2 text-[13px] outline-none focus:border-accent" bind:value={newKind}>
<option value="FOLDER">文件夹</option>
<option value="PROJECT">项目(课程资源库)</option>
</select>
</div>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="root-desc">简介(可选)</label>
<textarea id="root-desc" rows="3" class="w-full rounded-lg border border-line bg-panel px-3 py-2 font-mono text-xs outline-none focus:border-accent" bind:value={newDesc} placeholder="简要说明用途…"></textarea>
</div>
<div class="mt-4 flex justify-end gap-2">
<button class="rounded-lg border border-line bg-panel px-3.5 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showCreateRoot = false)}>取消</button>
<button class="rounded-lg bg-accent px-3.5 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={createRoot}>创建</button>
</div>
</Modal>
{/if}
+165
View File
@@ -0,0 +1,165 @@
<script lang="ts">
import { api, ApiError } from "./api.js";
import { toastOk, toastErr, toast } from "./stores.js";
import type { FileContent, VersionInfo, Role } from "./types.js";
import Modal from "./Modal.svelte";
let { projectId, path, role, onchanged, onclose }: { projectId: string; path: string; role: Role; onchanged: () => void; onclose?: () => void } = $props();
let file = $state<FileContent | null>(null);
let draft = $state("");
let loadError = $state<string | null>(null);
let conflict = $state<{ currentVersion: string; diff: string } | null>(null);
let showHistory = $state(false);
let history = $state<VersionInfo[]>([]);
const canEdit = $derived(role !== "VIEW");
async function load(): Promise<void> {
try {
file = await api<FileContent>(`/database/api/projects/${projectId}/file?path=${encodeURIComponent(path)}`);
draft = file.encoding === "utf8" ? file.content : "";
loadError = null;
conflict = null;
} catch (e) {
loadError = e instanceof Error ? e.message : String(e);
}
}
$effect(() => {
void projectId;
void path;
void load();
});
async function save(): Promise<void> {
if (file === null) return;
try {
const r = await api<{ version: string }>(`/database/api/projects/${projectId}/file/commits`, {
method: "POST",
body: { path: file.path, baseVersion: file.version, content: draft },
});
toastOk("已提交 " + r.version);
await load();
onchanged();
} catch (e) {
if (e instanceof ApiError && e.status === 409 && typeof e.details?.["currentVersion"] === "string") {
await showConflict(e.details["currentVersion"]);
} else {
toastErr(e instanceof Error ? e.message : String(e));
}
}
}
async function showConflict(currentVersion: string): Promise<void> {
if (file === null) return;
try {
const r = await api<{ diff: string }>(
`/database/api/projects/${projectId}/file/diff?path=${encodeURIComponent(file.path)}&from=${encodeURIComponent(file.version)}&to=${encodeURIComponent(currentVersion)}`,
);
conflict = { currentVersion, diff: r.diff };
file = { ...file, version: currentVersion };
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function acceptLatest(): Promise<void> {
conflict = null;
await load();
toast("已载入最新内容,请在此基础上合并", "info");
}
async function remove(): Promise<void> {
if (file === null || !confirm("删除文件 " + file.path + "?")) return;
try {
await api(`/database/api/projects/${projectId}/file?path=${encodeURIComponent(file.path)}`, {
method: "DELETE",
body: { baseVersion: file.version },
});
toastOk("已删除");
file = null;
onchanged();
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function openHistory(): Promise<void> {
try {
const r = await api<{ history: VersionInfo[] }>(`/database/api/projects/${projectId}/file/history?path=${encodeURIComponent(path)}`);
history = r.history;
showHistory = true;
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
function renderDiff(diff: string): string {
return diff
.replace(/&/g, "&amp;").replace(/</g, "&lt;").replace(/>/g, "&gt;")
.replace(/^\+(.*)$/gm, '<span class="add">+$1</span>')
.replace(/^-(.*)$/gm, '<span class="del">-$1</span>');
}
</script>
{#if loadError}
<div class="rounded-xl border border-line-soft bg-panel p-5 text-xs text-danger">{loadError}</div>
{:else if file}
<div class="rounded-xl border border-line-soft bg-panel p-5">
<div class="mb-2.5 flex items-center justify-between">
<span class="font-mono text-[11px] text-ink-3">{file.path} @ {file.version}</span>
<div class="flex items-center gap-2">
<a class="rounded-lg border border-line bg-panel px-3 py-1 text-[12px] font-medium text-ink transition hover:bg-hover" href="/database/api/projects/{projectId}/file/raw?path={encodeURIComponent(file.path)}" download>下载</a>
<button class="rounded-lg border border-line bg-panel px-3 py-1 text-[12px] font-medium text-ink transition hover:bg-hover" onclick={openHistory}>历史</button>
{#if canEdit}
<button class="rounded-lg border border-transparent px-3 py-1 text-[12px] font-medium text-danger transition hover:bg-[#A13A3312]" onclick={remove}>删除文件</button>
{/if}
{#if onclose}
<button class="rounded-lg border border-line bg-panel px-2.5 py-1 text-[12px] font-medium text-ink-3 transition hover:bg-hover hover:text-ink" onclick={onclose} title="关闭预览"></button>
{/if}
</div>
</div>
{#if file.encoding === "base64"}
<div class="text-xs text-ink-3">二进制文件({file.size} B),不支持在线编辑</div>
{:else}
<textarea rows="14" class="w-full rounded-lg border border-line bg-panel px-3 py-2 font-mono text-xs leading-7 outline-none focus:border-accent" bind:value={draft} readonly={!canEdit}></textarea>
{/if}
{#if canEdit && file.encoding !== "base64"}
<div class="mt-3 flex justify-end">
<button class="rounded-lg bg-accent px-3.5 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={save}>提交修改</button>
</div>
{/if}
{#if conflict}
<div class="mt-3.5 rounded-xl border border-[#E8E2C8] bg-[#FCFBF4] p-4">
<div class="mb-2 text-[13px] font-semibold text-[#6E6329]">冲突:他人已提交 {conflict.currentVersion},差异如下(你的基版 → 最新版)</div>
<pre class="diff rounded-lg border border-line-soft bg-panel p-3">{@html renderDiff(conflict.diff)}</pre>
<div class="mt-2 text-[11.5px] text-[#8A8059]">请人工合并后,以最新内容为全文重新提交(基版将更新为 {conflict.currentVersion})</div>
<div class="mt-2 flex justify-end">
<button class="rounded-lg border border-line bg-panel px-3 py-1 text-[12px] font-medium text-ink transition hover:bg-hover" onclick={acceptLatest}>载入最新内容</button>
</div>
</div>
{/if}
</div>
{:else}
<div class="rounded-xl border border-line-soft bg-panel p-5 text-xs text-ink-3">加载中…</div>
{/if}
{#if showHistory}
<Modal title="版本历史" onclose={() => (showHistory = false)}>
<div class="max-h-80 overflow-y-auto">
{#each history as v (v.version)}
<div class="border-t border-line-soft py-2 text-xs first:border-t-0">
<span class="font-mono text-accent">{v.version}</span> {v.message}
<div class="text-ink-3">{new Date(v.committedAt).toLocaleString("zh-CN")}{v.author ? " · " + v.author : ""}</div>
</div>
{/each}
</div>
<div class="mt-3 flex justify-end">
<button class="rounded-lg border border-line bg-panel px-3 py-1 text-[12px] font-medium text-ink transition hover:bg-hover" onclick={() => (showHistory = false)}>关闭</button>
</div>
</Modal>
{/if}
+137
View File
@@ -0,0 +1,137 @@
<script lang="ts">
import { api } from "./api.js";
import { toastOk, toastErr } from "./stores.js";
import { selectedFilePath, filesVersion } from "./browser.js";
import type { FileEntry, NodeDetail } from "./types.js";
import Modal from "./Modal.svelte";
let { node }: { node: NodeDetail } = $props();
let files = $state<FileEntry[] | null>(null);
let loadError = $state<string | null>(null);
let showNewFile = $state(false);
let newPath = $state("");
let newContent = $state("");
let uploadInput: HTMLInputElement;
const canEdit = $derived(node.role !== "VIEW");
async function loadFiles(): Promise<void> {
try {
const r = await api<{ files: FileEntry[] }>(`/database/api/projects/${node.id}/files`);
files = r.files;
loadError = null;
} catch (e) {
loadError = e instanceof Error ? e.message : String(e);
}
}
$effect(() => {
void node.id;
void $filesVersion;
void loadFiles();
});
async function submitNewFile(): Promise<void> {
const path = newPath.trim();
if (path === "") return;
try {
await api(`/database/api/projects/${node.id}/file`, {
method: "PUT",
body: { path, content: newContent },
});
toastOk("已创建");
showNewFile = false;
newPath = ""; newContent = "";
await loadFiles();
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
function u8ToBase64(bytes: Uint8Array): string {
let bin = "";
const CHUNK = 0x8000;
for (let i = 0; i < bytes.length; i += CHUNK) {
bin += String.fromCharCode.apply(null, Array.from(bytes.subarray(i, i + CHUNK)) as unknown as number[]);
}
return btoa(bin);
}
async function doUpload(e: Event): Promise<void> {
const input = e.target as HTMLInputElement;
const file = input.files?.[0];
input.value = "";
if (!file) return;
if (file.size > 10 * 1024 * 1024) {
toastErr("文件超过 10MB 上限");
return;
}
const targetPath = prompt("保存到路径(可含目录):", "材料/" + file.name);
if (!targetPath) return;
const bytes = new Uint8Array(await file.arrayBuffer());
const isBinary = bytes.includes(0);
const body = isBinary
? { path: targetPath, content: u8ToBase64(bytes), encoding: "base64" }
: { path: targetPath, content: new TextDecoder("utf-8").decode(bytes), encoding: "utf8" };
try {
await api(`/database/api/projects/${node.id}/file`, { method: "PUT", body });
toastOk("已上传 " + file.name);
await loadFiles();
} catch (err) {
toastErr(err instanceof Error ? err.message : String(err));
}
}
</script>
<div class="rounded-xl border border-line-soft bg-panel p-5">
<div class="mb-2 flex items-center justify-between">
<div class="text-[13px] font-semibold">项目文件({files?.length ?? 0})</div>
{#if canEdit}
<div class="flex gap-2">
<button class="rounded-lg border border-line bg-panel px-3 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showNewFile = true)}>+ 新建文件</button>
<button class="rounded-lg bg-accent px-3 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={() => uploadInput.click()}>上传文件</button>
<input bind:this={uploadInput} type="file" class="hidden" onchange={doUpload} />
</div>
{/if}
</div>
{#if files === null && loadError === null}
<div class="py-5 text-center text-xs text-ink-3">加载中…</div>
{:else if loadError}
<div class="py-5 text-center text-xs text-danger">{loadError}</div>
{:else if files && files.length === 0}
<div class="py-5 text-center text-xs text-ink-3">空仓库 · 可新建或上传文件</div>
{:else if files}
<table class="w-full border-collapse text-[13px]">
<tbody>
{#each files as f (f.path)}
<tr
class="cursor-pointer border-t border-line-soft first:border-t-0 {$selectedFilePath === f.path ? 'bg-selected' : 'hover:bg-hover'}"
onclick={() => selectedFilePath.set(f.path)}
>
<td class="py-2 font-mono text-[12.5px] text-ink">{f.path}</td>
<td class="py-2 text-right font-mono text-[11px] text-ink-3">{f.size} B</td>
</tr>
{/each}
</tbody>
</table>
{/if}
</div>
{#if showNewFile}
<Modal title="新建文件" onclose={() => (showNewFile = false)}>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="nf-path">路径</label>
<input id="nf-path" class="w-full rounded-lg border border-line bg-panel px-3 py-2 font-mono text-[13px] outline-none focus:border-accent" bind:value={newPath} placeholder="docs/intro.md" />
</div>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="nf-content">内容</label>
<textarea id="nf-content" rows="8" class="w-full rounded-lg border border-line bg-panel px-3 py-2 font-mono text-xs outline-none focus:border-accent" bind:value={newContent} placeholder="内容…"></textarea>
</div>
<div class="mt-4 flex justify-end gap-2">
<button class="rounded-lg border border-line bg-panel px-3.5 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showNewFile = false)}>取消</button>
<button class="rounded-lg bg-accent px-3.5 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={submitNewFile}>创建</button>
</div>
</Modal>
{/if}
+47
View File
@@ -0,0 +1,47 @@
<script lang="ts">
import { onMount } from "svelte";
import { api } from "./api.js";
interface LoginInfo {
orgSlug: string;
devLoginEnabled: boolean;
}
let info = $state<LoginInfo | null>(null);
let loadFailed = $state(false);
onMount(async () => {
try {
info = await api<LoginInfo>("/database/api/login-info");
} catch {
loadFailed = true;
}
});
</script>
<div class="flex min-h-full items-center justify-center p-6">
<div class="w-full max-w-[380px] rounded-2xl border border-line-soft bg-panel p-9 shadow-[0_4px_20px_rgba(26,26,24,.07)]">
<div class="text-center text-[26px] font-semibold tracking-wide text-ink">文件库</div>
<p class="mt-2.5 mb-8 text-center text-[13px] text-ink-3">课程资源与教研文件,一处安放,随处可查</p>
{#if info}
<a
href="/auth/feishu/{encodeURIComponent(info.orgSlug)}"
class="flex w-full items-center justify-center rounded-lg bg-accent px-4 py-3 text-sm font-medium text-white transition hover:bg-accent-hover"
>使用飞书登录</a>
{#if info.devLoginEnabled}
<div class="my-5 flex items-center gap-2.5 text-[11px] text-ink-3">
<span class="flex-1 border-t border-line-soft"></span>开发模式
<span class="flex-1 border-t border-line-soft"></span>
</div>
<a href="/app/dev-login-teacher" class="flex w-full items-center justify-center rounded-lg border border-line bg-panel px-4 py-2 text-[12.5px] font-medium text-ink transition hover:bg-hover">⚡ 一键登录(老师)</a>
<p class="mt-2.5 text-center text-[11px] text-ink-3">仅开发环境可见 · 跳过飞书 OAuth</p>
{/if}
{:else if loadFailed}
<p class="text-center text-[12.5px] text-danger">无法加载登录配置,请稍后重试</p>
{:else}
<p class="text-center text-[12.5px] text-ink-3">加载中…</p>
{/if}
</div>
</div>
+16
View File
@@ -0,0 +1,16 @@
<script lang="ts">
import type { Snippet } from "svelte";
let { title, onclose, children }: { title: string; onclose: () => void; children: Snippet } = $props();
</script>
<div
class="fixed inset-0 z-40 flex items-center justify-center bg-black/30 p-4"
role="presentation"
onclick={(e) => { if (e.target === e.currentTarget) onclose(); }}
>
<div class="w-full max-w-[440px] rounded-2xl border border-line-soft bg-panel p-6 shadow-[0_4px_20px_rgba(26,26,24,.07)]">
<div class="mb-4 text-[15px] font-semibold">{title}</div>
{@render children()}
</div>
</div>
@@ -0,0 +1,144 @@
<script lang="ts">
import { api } from "./api.js";
import { currentNode, breadcrumb, bumpTree, clearSelectedFile } from "./browser.js";
import { toastOk, toastErr } from "./stores.js";
import OverviewPanel from "./OverviewPanel.svelte";
import FilesPanel from "./FilesPanel.svelte";
import Modal from "./Modal.svelte";
let tab = $state<"detail" | "files">("detail");
let showCreateChild = $state(false);
let newName = $state("");
let newKind = $state<"FOLDER" | "PROJECT">("FOLDER");
let newDesc = $state("");
const node = $derived($currentNode);
const crumbs = $derived($breadcrumb);
const canManage = $derived(node?.role === "MANAGE");
const canEdit = $derived(canManage || node?.role === "EDIT");
$effect(() => {
void node?.id;
tab = "detail";
clearSelectedFile();
});
async function createChild(): Promise<void> {
const name = newName.trim();
if (name === "" || node === null) return;
try {
await api("/database/api/nodes", {
method: "POST",
body: {
parentId: node.id,
kind: newKind,
name,
...(newDesc.trim() !== "" ? { description: newDesc.trim() } : {}),
},
});
toastOk("已创建");
showCreateChild = false;
newName = ""; newKind = "FOLDER"; newDesc = "";
bumpTree();
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function renameNode(): Promise<void> {
if (node === null) return;
const name = prompt("新名称", node.name);
if (name === null) return;
try {
await api(`/database/api/nodes/${node.id}`, { method: "PATCH", body: { name } });
toastOk("已重命名");
bumpTree();
currentNode.update((n) => (n ? { ...n, name } : n));
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function deleteNode(): Promise<void> {
if (node === null || !confirm(`确认删除「${node.name}」?软删除后不可见。`)) return;
try {
await api(`/database/api/nodes/${node.id}`, { method: "DELETE" });
toastOk("已删除");
currentNode.set(null);
bumpTree();
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
</script>
{#if node === null}
<div class="flex h-full items-center justify-center text-[13px] text-ink-3">从左侧选择一个文件夹或项目</div>
{:else}
<div class="mx-auto max-w-[880px] px-9 py-9">
<div class="mb-2 text-[12.5px] text-ink-3">
{#each crumbs as c, i (i)}
{#if i > 0}<span class="mx-1 text-line">/</span>{/if}
<span>{c.name ?? "…"}</span>
{/each}
</div>
<div class="mb-5 flex items-center justify-between">
<div class="flex items-center gap-2.5 text-[19px] font-semibold text-ink">
{node.name}
<span class="rounded-full border border-line-soft bg-panel px-2 py-0.5 font-mono text-[10.5px] text-ink-3">{node.kind === "PROJECT" ? "项目" : "文件夹"}</span>
</div>
<div class="flex gap-2">
{#if canEdit && node.kind === "FOLDER"}
<button class="rounded-lg border border-line bg-panel px-3 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showCreateChild = true)}>+ 新建</button>
{/if}
{#if canManage}
<button class="rounded-lg border border-line bg-panel px-3 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={renameNode}>重命名</button>
<button class="rounded-lg border border-transparent px-3 py-1.5 text-[12.5px] font-medium text-danger transition hover:bg-[#A13A3312]" onclick={deleteNode}>删除</button>
{/if}
</div>
</div>
{#if node.kind === "FOLDER"}
<div class="py-7 text-[13px] text-ink-3">点击左侧树展开以浏览子内容</div>
{:else}
<div class="mb-5 flex gap-1 border-b border-line-soft">
{#each [["detail", "概览"], ["files", "文件"]] as [id, label] (id)}
<button
class="border-b-2 px-3.5 py-2 text-[13px] transition {tab === id ? 'border-accent font-semibold text-ink' : 'border-transparent text-ink-3 hover:text-ink'}"
onclick={() => (tab = id as "detail" | "files")}
>{label}</button>
{/each}
</div>
{#if tab === "detail"}
<OverviewPanel {node} />
{:else}
<FilesPanel {node} />
{/if}
{/if}
</div>
{/if}
{#if showCreateChild && node}
<Modal title="新建子节点" onclose={() => (showCreateChild = false)}>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="child-name">名称</label>
<input id="child-name" class="w-full rounded-lg border border-line bg-panel px-3 py-2 text-[13px] outline-none focus:border-accent" bind:value={newName} placeholder="例如:物理必修一" />
</div>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="child-kind">类型</label>
<select id="child-kind" class="w-full rounded-lg border border-line bg-panel px-3 py-2 text-[13px] outline-none focus:border-accent" bind:value={newKind}>
<option value="FOLDER">文件夹</option>
<option value="PROJECT">项目(课程资源库)</option>
</select>
</div>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="child-desc">简介(可选)</label>
<textarea id="child-desc" rows="3" class="w-full rounded-lg border border-line bg-panel px-3 py-2 font-mono text-xs outline-none focus:border-accent" bind:value={newDesc} placeholder="简要说明用途…"></textarea>
</div>
<div class="mt-4 flex justify-end gap-2">
<button class="rounded-lg border border-line bg-panel px-3.5 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showCreateChild = false)}>取消</button>
<button class="rounded-lg bg-accent px-3.5 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={createChild}>创建</button>
</div>
</Modal>
{/if}
@@ -0,0 +1,123 @@
<script lang="ts">
import { api } from "./api.js";
import { toastOk, toastErr } from "./stores.js";
import { currentNode } from "./browser.js";
import type { ExportJob, NodeDetail } from "./types.js";
import Modal from "./Modal.svelte";
let { node }: { node: NodeDetail } = $props();
let showEditDesc = $state(false);
let descDraft = $state("");
let exportJob = $state<ExportJob | null>(null);
const canEdit = $derived(node.role === "MANAGE" || node.role === "EDIT");
const roleLabel = $derived(node.role === "MANAGE" ? "可管理" : node.role === "EDIT" ? "可编辑" : "只读");
$effect(() => {
void node.id;
exportJob = null;
});
function openEditDesc(): void {
descDraft = node.description ?? "";
showEditDesc = true;
}
async function saveDesc(): Promise<void> {
const description = descDraft.trim();
try {
await api(`/database/api/nodes/${node.id}`, {
method: "PATCH",
body: { description: description === "" ? null : description },
});
toastOk("简介已保存");
showEditDesc = false;
const next = description === "" ? null : description;
currentNode.update((n) => (n && n.id === node.id ? { ...n, description: next } : n));
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function submitExport(): Promise<void> {
try {
const r = await api<{ jobId: string; status: string }>(`/database/api/projects/${node.id}/exports`, {
method: "POST",
body: { target: "manifest" },
});
toastOk("导出已提交");
void pollExport(r.jobId);
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
async function pollExport(jobId: string): Promise<void> {
for (;;) {
await new Promise((r) => setTimeout(r, 800));
try {
const job = await api<ExportJob>(`/database/api/exports/${jobId}`);
exportJob = job;
if (job.status === "DONE" || job.status === "FAILED") break;
} catch {
break;
}
}
}
</script>
<div class="rounded-xl border border-line-soft bg-panel p-5">
<div class="mb-4">
<div class="mb-1.5 text-[11.5px] text-ink-3">简介</div>
<div class="text-[13.5px] leading-7 text-ink">
{#if node.description}
{node.description}
{:else}
<span class="italic text-ink-3">暂无简介</span>
{/if}
{#if canEdit}
<button class="ml-2.5 rounded-lg border border-line bg-panel px-2.5 py-0.5 align-middle text-[11.5px] text-ink transition hover:bg-hover" onclick={openEditDesc}>编辑</button>
{/if}
</div>
</div>
<div class="my-4 border-t border-line-soft"></div>
<div class="flex flex-col gap-1.5 text-[13px] text-ink-2">
<div>我的角色 <b class="font-semibold text-ink">{roleLabel}</b></div>
<div>创建时间 <b class="font-semibold text-ink">{new Date(node.createdAt).toLocaleDateString("zh-CN", { year: "numeric", month: "long", day: "numeric" })}</b></div>
<div>最近修改 <b class="font-semibold text-ink">{new Date(node.updatedAt).toLocaleDateString("zh-CN", { year: "numeric", month: "long", day: "numeric" })}</b></div>
</div>
<div class="my-4 border-t border-line-soft"></div>
<div class="mb-2 text-[12.5px] font-semibold">导出</div>
<div class="flex items-center gap-2">
<button class="rounded-lg border border-line bg-panel px-3 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={submitExport}>开始导出</button>
{#if exportJob}
<span class="font-mono text-[11px] text-ink-3">
{#if exportJob.status === "DONE"}
完成 · <a class="text-accent underline" href="/database/api/exports/{exportJob.id}/download">下载</a>
{:else if exportJob.status === "FAILED"}
失败:{exportJob.error ?? ""}
{:else}
{exportJob.status}
{/if}
</span>
{/if}
</div>
</div>
{#if showEditDesc}
<Modal title="编辑简介" onclose={() => (showEditDesc = false)}>
<div class="mb-3">
<label class="mb-1 block text-[11.5px] text-ink-3" for="desc-draft">简要说明这个项目的内容</label>
<textarea id="desc-draft" rows="5" class="w-full rounded-lg border border-line bg-panel px-3 py-2 text-[13px] leading-7 outline-none focus:border-accent" bind:value={descDraft} placeholder="例如:高中物理必修一第三章,表面张力相关内容……"></textarea>
</div>
<div class="mt-4 flex justify-end gap-2">
<button class="rounded-lg border border-line bg-panel px-3.5 py-1.5 text-[12.5px] font-medium text-ink transition hover:bg-hover" onclick={() => (showEditDesc = false)}>取消</button>
<button class="rounded-lg bg-accent px-3.5 py-1.5 text-[12.5px] font-medium text-white transition hover:bg-accent-hover" onclick={saveDesc}>保存</button>
</div>
</Modal>
{/if}
+11
View File
@@ -0,0 +1,11 @@
<script lang="ts">
import { toasts } from "./stores.js";
</script>
<div class="fixed bottom-4 right-4 z-50 flex flex-col gap-2">
{#each $toasts as t (t.id)}
<div class="max-w-[340px] rounded-lg px-4 py-2 text-sm text-white {t.kind === 'err' ? 'bg-[#7E2C26]' : 'bg-[#333230]'}">
{t.message}
</div>
{/each}
</div>
+82
View File
@@ -0,0 +1,82 @@
<script lang="ts">
import TreeNode from "./TreeNode.svelte";
import { api } from "./api.js";
import { expanded, currentNode, breadcrumb, toggleExpanded, treeVersion } from "./browser.js";
import { toastErr } from "./stores.js";
import type { BreadcrumbEntry, NodeChild, NodeDetail } from "./types.js";
let { node, depth }: { node: NodeChild; depth: number } = $props();
let children = $state<NodeChild[] | null>(null);
const isOpen = $derived($expanded.has(node.id));
const isSelected = $derived($currentNode?.id === node.id);
// 树刷新信号(增/删/移/重命名)→ 失效子节点缓存,展开状态下随之重载
$effect(() => {
void $treeVersion;
children = null;
});
$effect(() => {
if (isOpen && node.kind === "FOLDER" && children === null) {
api<{ nodes: NodeChild[] }>(`/database/api/nodes?parentId=${encodeURIComponent(node.id)}`)
.then((r) => (children = r.nodes))
.catch((e) => toastErr(e instanceof Error ? e.message : String(e)));
}
});
async function select(): Promise<void> {
if (node.kind === "FOLDER") toggleExpanded(node.id);
try {
const [detail, crumb] = await Promise.all([
api<{ node: NodeDetail }>(`/database/api/nodes/${node.id}`),
api<{ breadcrumb: BreadcrumbEntry[] }>(`/database/api/nodes/${node.id}/breadcrumb`),
]);
currentNode.set(detail.node);
breadcrumb.set(crumb.breadcrumb);
} catch (e) {
toastErr(e instanceof Error ? e.message : String(e));
}
}
</script>
<div>
<div
class="tree-item flex cursor-pointer items-center gap-1 rounded-lg px-1.5 py-1.5 select-none {isSelected ? 'bg-selected' : 'hover:bg-hover'}"
role="button"
tabindex="0"
onclick={select}
onkeydown={(e) => e.key === "Enter" && select()}
>
<span class="flex h-4 w-4 shrink-0 items-center justify-center text-ink-3">
{#if node.kind === "FOLDER"}
<svg width="9" height="9" viewBox="0 0 24 24" fill="currentColor">
{#if isOpen}<path d="M6 9l6 6 6-6z" />{:else}<path d="M9 6l6 6-6 6z" />{/if}
</svg>
{/if}
</span>
<span class="flex h-4 w-4 shrink-0 items-center justify-center {node.kind === 'PROJECT' ? 'text-ink' : 'text-ink-3'}">
{#if node.kind === "PROJECT"}
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="M20 7l-8-4-8 4m16 0l-8 4m8-4v10l-8 4m0-10L4 7m8 4v10M4 7v10l8 4" /></svg>
{:else}
<svg width="16" height="16" viewBox="0 0 24 24" fill="currentColor"><path d="M3 7a2 2 0 0 1 2-2h4l2 2h8a2 2 0 0 1 2 2v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V7Z" /></svg>
{/if}
</span>
<span class="truncate">{node.name}</span>
{#if node.role !== "MANAGE"}
<span class="ml-auto pr-1 font-mono text-[10px] text-ink-3">{node.role}</span>
{/if}
</div>
{#if node.kind === "FOLDER" && isOpen}
<div class="ml-[15px] border-l border-guide pl-1">
{#if children === null}
<div class="px-3 py-1.5 text-xs text-ink-3"></div>
{:else}
{#each children as child (child.id)}
<TreeNode node={child} depth={depth + 1} />
{/each}
{/if}
</div>
{/if}
</div>
+49
View File
@@ -0,0 +1,49 @@
/** 与 /database/api/* 的约定一致;401 时清空会话(回到登录视图)。 */
import { me } from "./stores.js";
export class ApiError extends Error {
constructor(
readonly status: number,
readonly code: string,
message: string,
readonly details?: Record<string, unknown>,
) {
super(message);
this.name = "ApiError";
}
}
export class UnauthenticatedError extends Error {
constructor() {
super("unauthenticated");
this.name = "UnauthenticatedError";
}
}
interface RequestOpts {
readonly method?: string;
readonly body?: unknown;
}
export async function api<T = unknown>(path: string, opts: RequestOpts = {}): Promise<T> {
const res = await fetch(path, {
credentials: "same-origin",
method: opts.method ?? "GET",
...(opts.body !== undefined
? { headers: { "Content-Type": "application/json" }, body: JSON.stringify(opts.body) }
: {}),
});
if (res.status === 401) {
me.set(null);
throw new UnauthenticatedError();
}
if (res.status === 204) return null as T;
const text = await res.text();
const data = text === "" ? null : (JSON.parse(text) as unknown);
if (!res.ok) {
const err = (data as { error?: { code?: string; message?: string } } | null)?.error ?? {};
throw new ApiError(res.status, err.code ?? "unknown", err.message ?? res.statusText, err as Record<string, unknown>);
}
return data as T;
}
+34
View File
@@ -0,0 +1,34 @@
import { writable } from "svelte/store";
import type { BreadcrumbEntry, NodeDetail } from "./types.js";
/** 树展开集合 / 当前选中节点 / 面包屑 / 树刷新计数。 */
export const expanded = writable<Set<string>>(new Set());
export const currentNode = writable<NodeDetail | null>(null);
export const breadcrumb = writable<BreadcrumbEntry[]>([]);
export const treeVersion = writable(0);
/** 右侧预览栏:当前选中文件路径(项目内);切换节点时清空。 */
export const selectedFilePath = writable<string | null>(null);
/** 文件列表刷新计数(编辑器保存/删除后 bump,列表随之重载)。 */
export const filesVersion = writable(0);
export function bumpTree(): void {
treeVersion.update((v) => v + 1);
}
export function bumpFiles(): void {
filesVersion.update((v) => v + 1);
}
export function clearSelectedFile(): void {
selectedFilePath.set(null);
}
export function toggleExpanded(id: string): void {
expanded.update((set) => {
const next = new Set(set);
if (next.has(id)) next.delete(id);
else next.add(id);
return next;
});
}
+26
View File
@@ -0,0 +1,26 @@
import { writable } from "svelte/store";
import type { MeResponse } from "./types.js";
/** 当前登录身份;null = 未登录(显示登录视图)。 */
export const me = writable<MeResponse | null>(null);
export const authChecked = writable(false);
export interface ToastItem {
readonly id: number;
readonly message: string;
readonly kind: "info" | "err";
}
let nextToastId = 1;
export const toasts = writable<ToastItem[]>([]);
export function toast(message: string, kind: ToastItem["kind"] = "info"): void {
const id = nextToastId++;
toasts.update((list) => [...list, { id, message, kind }]);
setTimeout(() => {
toasts.update((list) => list.filter((t) => t.id !== id));
}, 3600);
}
export const toastOk = (m: string): void => toast(m, "info");
export const toastErr = (m: string): void => toast(m, "err");
+85
View File
@@ -0,0 +1,85 @@
/** 与后端 /database/api/* 响应形状对齐。 */
export type NodeKind = "FOLDER" | "PROJECT";
export type Role = "VIEW" | "EDIT" | "MANAGE";
export interface NodeChild {
readonly id: string;
readonly parentId: string | null;
readonly kind: NodeKind;
readonly name: string;
readonly role: Role;
readonly createdAt: string;
readonly updatedAt: string;
}
export interface BreadcrumbEntry {
readonly depth: number;
readonly id: string | null;
readonly name: string | null;
readonly kind: NodeKind;
}
export interface NodeDetail {
readonly id: string;
readonly parentId: string | null;
readonly kind: NodeKind;
readonly name: string;
readonly description: string | null;
readonly role: Role;
readonly provisionStatus: "PROVISIONING" | "READY" | "FAILED";
readonly independentPermission: boolean;
readonly createdAt: string;
readonly updatedAt: string;
}
export interface MeResponse {
readonly userId: string;
readonly isWebsiteAdmin: boolean;
}
export interface FileEntry {
readonly path: string;
readonly size: number;
}
export type FileContentEncoding = "utf8" | "base64";
export interface FileContent {
readonly path: string;
readonly version: string;
readonly encoding: FileContentEncoding;
readonly content: string;
readonly size: number;
}
export interface VersionInfo {
readonly version: string;
readonly message: string;
readonly author?: string;
readonly committedAt: string;
}
export interface ExportJob {
readonly id: string;
readonly nodeId: string;
readonly target: string;
readonly status: "QUEUED" | "RUNNING" | "DONE" | "FAILED";
readonly error: string | null;
readonly createdAt: string;
}
export interface Grant {
readonly id: string;
readonly principalType: "USER" | "GROUP";
readonly principalId: string;
readonly role: Role;
readonly isCreatorGrant: boolean;
readonly createdAt: string;
}
export interface GroupSearchResult {
readonly id: string;
readonly name: string;
readonly breadcrumb: string;
}
+5
View File
@@ -0,0 +1,5 @@
import { mount } from "svelte";
import App from "./App.svelte";
import "./app.css";
export default mount(App, { target: document.getElementById("app")! });
+17
View File
@@ -0,0 +1,17 @@
{
"compilerOptions": {
"target": "ES2022",
"module": "ESNext",
"moduleResolution": "bundler",
"strict": true,
"noUncheckedIndexedAccess": true,
"exactOptionalPropertyTypes": true,
"verbatimModuleSyntax": true,
"skipLibCheck": true,
"isolatedModules": true,
"resolveJsonModule": true,
"useDefineForClassFields": true,
"lib": ["ES2022", "DOM", "DOM.Iterable"]
},
"include": ["src/**/*.ts", "src/**/*.svelte"]
}
+25
View File
@@ -0,0 +1,25 @@
import { defineConfig } from "vite";
import { svelte } from "@sveltejs/vite-plugin-svelte";
import tailwindcss from "@tailwindcss/vite";
// 老师端独立 SPA:构建产物由 hub 后端静态托管于 /app;
// 开发时 vite dev(:5173)把 API/认证请求代理到后端(:8788)。
const backend = "http://127.0.0.1:8788";
export default defineConfig({
plugins: [svelte(), tailwindcss()],
base: "/app/",
build: {
outDir: "dist",
emptyOutDir: true,
},
server: {
port: 5173,
proxy: {
"/database/api": backend,
"/auth": backend,
"/app/dev-login": backend,
"/app/dev-login-teacher": backend,
},
},
});
+205 -10
View File
@@ -13,6 +13,7 @@
"@alicloud/tea-util": "^1.4.11", "@alicloud/tea-util": "^1.4.11",
"@anthropic-ai/claude-agent-sdk": "^0.3.202", "@anthropic-ai/claude-agent-sdk": "^0.3.202",
"@fastify/cookie": "^11.0.2", "@fastify/cookie": "^11.0.2",
"@fastify/static": "^10.1.2",
"@larksuiteoapi/node-sdk": "^1.70.0", "@larksuiteoapi/node-sdk": "^1.70.0",
"@prisma/client": "^6.19.3", "@prisma/client": "^6.19.3",
"ai": "^7.0.16", "ai": "^7.0.16",
@@ -902,6 +903,22 @@
"node": ">=18" "node": ">=18"
} }
}, },
"node_modules/@fastify/accept-negotiator": {
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/@fastify/accept-negotiator/-/accept-negotiator-2.0.1.tgz",
"integrity": "sha512-/c/TW2bO/v9JeEgoD/g1G5GxGeCF1Hafdf79WPmUlgYiBXummY0oX3VVq4yFkKKVBKDNlaDUYoab7g38RpPqCQ==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/fastify"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fastify"
}
],
"license": "MIT"
},
"node_modules/@fastify/ajv-compiler": { "node_modules/@fastify/ajv-compiler": {
"version": "4.0.5", "version": "4.0.5",
"resolved": "https://registry.npmjs.org/@fastify/ajv-compiler/-/ajv-compiler-4.0.5.tgz", "resolved": "https://registry.npmjs.org/@fastify/ajv-compiler/-/ajv-compiler-4.0.5.tgz",
@@ -1033,6 +1050,83 @@
"ipaddr.js": "^2.1.0" "ipaddr.js": "^2.1.0"
} }
}, },
"node_modules/@fastify/send": {
"version": "4.1.0",
"resolved": "https://registry.npmjs.org/@fastify/send/-/send-4.1.0.tgz",
"integrity": "sha512-TMYeQLCBSy2TOFmV95hQWkiTYgC/SEx7vMdV+wnZVX4tt8VBLKzmH8vV9OzJehV0+XBfg+WxPMt5wp+JBUKsVw==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/fastify"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fastify"
}
],
"license": "MIT",
"dependencies": {
"@lukeed/ms": "^2.0.2",
"escape-html": "~1.0.3",
"fast-decode-uri-component": "^1.0.1",
"http-errors": "^2.0.0",
"mime": "^3"
}
},
"node_modules/@fastify/static": {
"version": "10.1.2",
"resolved": "https://registry.npmjs.org/@fastify/static/-/static-10.1.2.tgz",
"integrity": "sha512-G/g18cG9tLutT/OVyN1AIsHIl9L1UwmJ+S3dkyhVpplIx0nEMicd7RGQ+uJLyhKKF4a3tTcQydccn3Mop1fX+Q==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/fastify"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fastify"
}
],
"license": "MIT",
"dependencies": {
"@fastify/accept-negotiator": "^2.0.0",
"@fastify/error": "^4.0.0",
"@fastify/send": "^4.0.0",
"content-disposition": "^2.0.1",
"fastify-plugin": "^6.0.0",
"fastq": "^1.17.1",
"glob": "^13.0.0"
}
},
"node_modules/@fastify/static/node_modules/content-disposition": {
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-2.0.1.tgz",
"integrity": "sha512-e+H0ZXHSWYrENhQzw1LPuP4oF5MzVKmDU6d3hxlvaPEYLLg62MxtQNPRx4SYSuYJSBUgnQIG4HIN2tEtNv7Dog==",
"license": "MIT",
"engines": {
"node": ">=18"
},
"funding": {
"type": "opencollective",
"url": "https://opencollective.com/express"
}
},
"node_modules/@fastify/static/node_modules/fastify-plugin": {
"version": "6.0.0",
"resolved": "https://registry.npmjs.org/fastify-plugin/-/fastify-plugin-6.0.0.tgz",
"integrity": "sha512-fZOty7z3O7vOliF6d8bHE3wiEh1KcNnKEQensSgTk9C1DvN6nRLS++XVd86v33Hw/8u9Un8A1zDrQ8ujcQDHEg==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/fastify"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fastify"
}
],
"license": "MIT"
},
"node_modules/@hono/node-server": { "node_modules/@hono/node-server": {
"version": "1.19.14", "version": "1.19.14",
"resolved": "https://registry.npmjs.org/@hono/node-server/-/node-server-1.19.14.tgz", "resolved": "https://registry.npmjs.org/@hono/node-server/-/node-server-1.19.14.tgz",
@@ -1068,6 +1162,15 @@
"ws": "^8.19.0" "ws": "^8.19.0"
} }
}, },
"node_modules/@lukeed/ms": {
"version": "2.0.2",
"resolved": "https://registry.npmjs.org/@lukeed/ms/-/ms-2.0.2.tgz",
"integrity": "sha512-9I2Zn6+NJLfaGoz9jN3lpwDgAYvfGeNYdbAIjJOqzs4Tpc+VU3Jqq4IofSUBKajiDS8k9fZIg18/z13mpk1bsA==",
"license": "MIT",
"engines": {
"node": ">=8"
}
},
"node_modules/@modelcontextprotocol/sdk": { "node_modules/@modelcontextprotocol/sdk": {
"version": "1.29.0", "version": "1.29.0",
"resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.29.0.tgz", "resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.29.0.tgz",
@@ -1934,6 +2037,15 @@
"proxy-from-env": "^2.1.0" "proxy-from-env": "^2.1.0"
} }
}, },
"node_modules/balanced-match": {
"version": "4.0.4",
"resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz",
"integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==",
"license": "MIT",
"engines": {
"node": "18 || 20 || >=22"
}
},
"node_modules/body-parser": { "node_modules/body-parser": {
"version": "2.3.0", "version": "2.3.0",
"resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz", "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz",
@@ -1973,6 +2085,18 @@
"url": "https://opencollective.com/express" "url": "https://opencollective.com/express"
} }
}, },
"node_modules/brace-expansion": {
"version": "5.0.7",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz",
"integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==",
"license": "MIT",
"dependencies": {
"balanced-match": "^4.0.2"
},
"engines": {
"node": "18 || 20 || >=22"
}
},
"node_modules/bytes": { "node_modules/bytes": {
"version": "3.1.2", "version": "3.1.2",
"resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz", "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz",
@@ -2254,7 +2378,6 @@
"resolved": "https://registry.npmjs.org/depd/-/depd-2.0.0.tgz", "resolved": "https://registry.npmjs.org/depd/-/depd-2.0.0.tgz",
"integrity": "sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==", "integrity": "sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==",
"license": "MIT", "license": "MIT",
"peer": true,
"engines": { "engines": {
"node": ">= 0.8" "node": ">= 0.8"
} }
@@ -2447,8 +2570,7 @@
"version": "1.0.3", "version": "1.0.3",
"resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz", "resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz",
"integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==", "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==",
"license": "MIT", "license": "MIT"
"peer": true
}, },
"node_modules/estree-walker": { "node_modules/estree-walker": {
"version": "3.0.3", "version": "3.0.3",
@@ -2947,6 +3069,23 @@
"giget": "dist/cli.mjs" "giget": "dist/cli.mjs"
} }
}, },
"node_modules/glob": {
"version": "13.0.6",
"resolved": "https://registry.npmjs.org/glob/-/glob-13.0.6.tgz",
"integrity": "sha512-Wjlyrolmm8uDpm/ogGyXZXb1Z+Ca2B8NbJwqBVg0axK9GbBeoS7yGV6vjXnYdGm6X53iehEuxxbyiKp8QmN4Vw==",
"license": "BlueOak-1.0.0",
"dependencies": {
"minimatch": "^10.2.2",
"minipass": "^7.1.3",
"path-scurry": "^2.0.2"
},
"engines": {
"node": "18 || 20 || >=22"
},
"funding": {
"url": "https://github.com/sponsors/isaacs"
}
},
"node_modules/gopd": { "node_modules/gopd": {
"version": "1.2.0", "version": "1.2.0",
"resolved": "https://registry.npmjs.org/gopd/-/gopd-1.2.0.tgz", "resolved": "https://registry.npmjs.org/gopd/-/gopd-1.2.0.tgz",
@@ -3013,7 +3152,6 @@
"resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.1.tgz", "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.1.tgz",
"integrity": "sha512-4FbRdAX+bSdmo4AUFuS0WNiPz8NgFt+r8ThgNWmlrjQjt1Q7ZR9+zTlce2859x4KSXrwIsaeTqDoKQmtP8pLmQ==", "integrity": "sha512-4FbRdAX+bSdmo4AUFuS0WNiPz8NgFt+r8ThgNWmlrjQjt1Q7ZR9+zTlce2859x4KSXrwIsaeTqDoKQmtP8pLmQ==",
"license": "MIT", "license": "MIT",
"peer": true,
"dependencies": { "dependencies": {
"depd": "~2.0.0", "depd": "~2.0.0",
"inherits": "~2.0.4", "inherits": "~2.0.4",
@@ -3096,8 +3234,7 @@
"version": "2.0.4", "version": "2.0.4",
"resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz", "resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz",
"integrity": "sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==", "integrity": "sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==",
"license": "ISC", "license": "ISC"
"peer": true
}, },
"node_modules/ini": { "node_modules/ini": {
"version": "1.3.8", "version": "1.3.8",
@@ -3546,6 +3683,15 @@
"integrity": "sha512-mNAgZ1GmyNhD7AuqnTG3/VQ26o760+ZYBPKjPvugO8+nLbYfX6TVpJPseBvopbdY+qpZ/lKUnmEc1LeZYS3QAA==", "integrity": "sha512-mNAgZ1GmyNhD7AuqnTG3/VQ26o760+ZYBPKjPvugO8+nLbYfX6TVpJPseBvopbdY+qpZ/lKUnmEc1LeZYS3QAA==",
"license": "Apache-2.0" "license": "Apache-2.0"
}, },
"node_modules/lru-cache": {
"version": "11.5.2",
"resolved": "https://registry.npmjs.org/lru-cache/-/lru-cache-11.5.2.tgz",
"integrity": "sha512-4pfM1Ff0x50o0tQwb5ucw/RzNyD0/YJME6IVcStalZuMWxdt3sR3huStTtxz4PUmvZfRguvDejasvQ2kifR11g==",
"license": "BlueOak-1.0.0",
"engines": {
"node": "20 || >=22"
}
},
"node_modules/magic-string": { "node_modules/magic-string": {
"version": "0.30.21", "version": "0.30.21",
"resolved": "https://registry.npmjs.org/magic-string/-/magic-string-0.30.21.tgz", "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-0.30.21.tgz",
@@ -3588,6 +3734,18 @@
"url": "https://github.com/sponsors/sindresorhus" "url": "https://github.com/sponsors/sindresorhus"
} }
}, },
"node_modules/mime": {
"version": "3.0.0",
"resolved": "https://registry.npmjs.org/mime/-/mime-3.0.0.tgz",
"integrity": "sha512-jSCU7/VB1loIWBZe14aEYHU/+1UMEHoaO7qxCOVJOw9GgH72VAWppxNcjU+x9a2k3GSIBXNKxXQFqRvvZ7vr3A==",
"license": "MIT",
"bin": {
"mime": "cli.js"
},
"engines": {
"node": ">=10.0.0"
}
},
"node_modules/mime-db": { "node_modules/mime-db": {
"version": "1.52.0", "version": "1.52.0",
"resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.52.0.tgz", "resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.52.0.tgz",
@@ -3609,6 +3767,30 @@
"node": ">= 0.6" "node": ">= 0.6"
} }
}, },
"node_modules/minimatch": {
"version": "10.2.5",
"resolved": "https://registry.npmjs.org/minimatch/-/minimatch-10.2.5.tgz",
"integrity": "sha512-MULkVLfKGYDFYejP07QOurDLLQpcjk7Fw+7jXS2R2czRQzR56yHRveU5NDJEOviH+hETZKSkIk5c+T23GjFUMg==",
"license": "BlueOak-1.0.0",
"dependencies": {
"brace-expansion": "^5.0.5"
},
"engines": {
"node": "18 || 20 || >=22"
},
"funding": {
"url": "https://github.com/sponsors/isaacs"
}
},
"node_modules/minipass": {
"version": "7.1.3",
"resolved": "https://registry.npmjs.org/minipass/-/minipass-7.1.3.tgz",
"integrity": "sha512-tEBHqDnIoM/1rXME1zgka9g6Q2lcoCkxHLuc7ODJ5BxbP5d4c2Z5cGgtXAku59200Cx7diuHTOYfSBD8n6mm8A==",
"license": "BlueOak-1.0.0",
"engines": {
"node": ">=16 || 14 >=14.17"
}
},
"node_modules/moment": { "node_modules/moment": {
"version": "2.30.1", "version": "2.30.1",
"resolved": "https://registry.npmjs.org/moment/-/moment-2.30.1.tgz", "resolved": "https://registry.npmjs.org/moment/-/moment-2.30.1.tgz",
@@ -3792,6 +3974,22 @@
"node": ">=8" "node": ">=8"
} }
}, },
"node_modules/path-scurry": {
"version": "2.0.2",
"resolved": "https://registry.npmjs.org/path-scurry/-/path-scurry-2.0.2.tgz",
"integrity": "sha512-3O/iVVsJAPsOnpwWIeD+d6z/7PmqApyQePUtCndjatj/9I5LylHvt5qluFaBT3I5h3r1ejfR056c+FCv+NnNXg==",
"license": "BlueOak-1.0.0",
"dependencies": {
"lru-cache": "^11.0.0",
"minipass": "^7.1.2"
},
"engines": {
"node": "18 || 20 || >=22"
},
"funding": {
"url": "https://github.com/sponsors/isaacs"
}
},
"node_modules/path-to-regexp": { "node_modules/path-to-regexp": {
"version": "8.4.2", "version": "8.4.2",
"resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-8.4.2.tgz", "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-8.4.2.tgz",
@@ -4370,8 +4568,7 @@
"version": "1.2.0", "version": "1.2.0",
"resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.2.0.tgz", "resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.2.0.tgz",
"integrity": "sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==", "integrity": "sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==",
"license": "ISC", "license": "ISC"
"peer": true
}, },
"node_modules/shebang-command": { "node_modules/shebang-command": {
"version": "2.0.0", "version": "2.0.0",
@@ -4570,7 +4767,6 @@
"resolved": "https://registry.npmjs.org/statuses/-/statuses-2.0.2.tgz", "resolved": "https://registry.npmjs.org/statuses/-/statuses-2.0.2.tgz",
"integrity": "sha512-DvEy55V3DB7uknRo+4iOGT5fP1slR8wQohVdknigZPMpMstaKJQWhwiYBACJE3Ul2pTnATihhBYnRhZQHGBiRw==", "integrity": "sha512-DvEy55V3DB7uknRo+4iOGT5fP1slR8wQohVdknigZPMpMstaKJQWhwiYBACJE3Ul2pTnATihhBYnRhZQHGBiRw==",
"license": "MIT", "license": "MIT",
"peer": true,
"engines": { "engines": {
"node": ">= 0.8" "node": ">= 0.8"
} }
@@ -4658,7 +4854,6 @@
"resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.1.tgz", "resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.1.tgz",
"integrity": "sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==", "integrity": "sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==",
"license": "MIT", "license": "MIT",
"peer": true,
"engines": { "engines": {
"node": ">=0.6" "node": ">=0.6"
} }
+5 -2
View File
@@ -12,6 +12,7 @@
"@alicloud/tea-util": "^1.4.11", "@alicloud/tea-util": "^1.4.11",
"@anthropic-ai/claude-agent-sdk": "^0.3.202", "@anthropic-ai/claude-agent-sdk": "^0.3.202",
"@fastify/cookie": "^11.0.2", "@fastify/cookie": "^11.0.2",
"@fastify/static": "^10.1.2",
"@larksuiteoapi/node-sdk": "^1.70.0", "@larksuiteoapi/node-sdk": "^1.70.0",
"@prisma/client": "^6.19.3", "@prisma/client": "^6.19.3",
"ai": "^7.0.16", "ai": "^7.0.16",
@@ -33,7 +34,7 @@
"description": "Curriculum Project Hub — org-scoped Feishu collaboration and confined Agent runtime. Semantics pinned by docs/adr/ (ADR-0001 through ADR-0027).", "description": "Curriculum Project Hub — org-scoped Feishu collaboration and confined Agent runtime. Semantics pinned by docs/adr/ (ADR-0001 through ADR-0027).",
"scripts": { "scripts": {
"dev": "npm run prisma:migrate && tsx watch src/server.ts", "dev": "npm run prisma:migrate && tsx watch src/server.ts",
"build": "tsc -p tsconfig.json && npm run admin:build", "build": "tsc -p tsconfig.json && npm run admin:build && npm run filelib:build",
"start": "npm run prisma:migrate && node dist/server.js", "start": "npm run prisma:migrate && node dist/server.js",
"check": "tsc -p tsconfig.json --noEmit", "check": "tsc -p tsconfig.json --noEmit",
"audit:production": "npm audit --omit=dev --audit-level=high", "audit:production": "npm audit --omit=dev --audit-level=high",
@@ -48,6 +49,8 @@
"test": "vitest run", "test": "vitest run",
"test:watch": "vitest", "test:watch": "vitest",
"admin:dev": "npm run dev --prefix admin-web", "admin:dev": "npm run dev --prefix admin-web",
"admin:build": "npm run build --prefix admin-web" "admin:build": "npm run build --prefix admin-web",
"filelib:dev": "npm run dev --prefix filelib-web",
"filelib:build": "npm run build --prefix filelib-web"
} }
} }
@@ -0,0 +1,92 @@
-- File library (文件库) — 语义锚定:仓库根《文件库-接口契约.md》、.omo/文件库-开工计划.md (D11D19)。
-- 本地无 PG 时手写;有 PG 后可用 `prisma migrate diff` 核对与 schema 的一致性。
-- CreateEnum
CREATE TYPE "FileLibNodeKind" AS ENUM ('FOLDER', 'PROJECT');
CREATE TYPE "FileLibProvisionStatus" AS ENUM ('PROVISIONING', 'READY', 'FAILED');
CREATE TYPE "FileLibRole" AS ENUM ('VIEW', 'EDIT', 'MANAGE');
CREATE TYPE "FileLibPrincipalType" AS ENUM ('USER', 'GROUP');
CREATE TYPE "FileLibExportStatus" AS ENUM ('QUEUED', 'RUNNING', 'DONE', 'FAILED');
-- CreateTable
CREATE TABLE "FileLibNode" (
"id" TEXT NOT NULL,
"organizationId" TEXT NOT NULL,
"parentId" TEXT,
"kind" "FileLibNodeKind" NOT NULL,
"name" TEXT NOT NULL,
"nameLower" TEXT NOT NULL,
"pathIds" TEXT NOT NULL,
"creatorId" TEXT NOT NULL,
"provisionStatus" "FileLibProvisionStatus" NOT NULL DEFAULT 'READY',
"storageDir" TEXT,
"deletedAt" TIMESTAMP(3),
"createdAt" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
"updatedAt" TIMESTAMP(3) NOT NULL,
CONSTRAINT "FileLibNode_pkey" PRIMARY KEY ("id")
);
CREATE TABLE "FileLibGrant" (
"id" TEXT NOT NULL,
"organizationId" TEXT NOT NULL,
"nodeId" TEXT NOT NULL,
"principalType" "FileLibPrincipalType" NOT NULL,
"principalId" TEXT NOT NULL,
"role" "FileLibRole" NOT NULL,
"isCreatorGrant" BOOLEAN NOT NULL DEFAULT false,
"createdByUserId" TEXT,
"createdAt" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
"revokedAt" TIMESTAMP(3),
CONSTRAINT "FileLibGrant_pkey" PRIMARY KEY ("id")
);
CREATE TABLE "FileLibProjectSettings" (
"nodeId" TEXT NOT NULL,
"independentPermissionsEnabled" BOOLEAN NOT NULL DEFAULT false,
CONSTRAINT "FileLibProjectSettings_pkey" PRIMARY KEY ("nodeId")
);
CREATE TABLE "FileLibExportJob" (
"id" TEXT NOT NULL,
"organizationId" TEXT NOT NULL,
"nodeId" TEXT NOT NULL,
"target" TEXT NOT NULL,
"params" JSONB NOT NULL,
"status" "FileLibExportStatus" NOT NULL DEFAULT 'QUEUED',
"downloadUrl" TEXT,
"error" TEXT,
"createdByUserId" TEXT NOT NULL,
"createdAt" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
"updatedAt" TIMESTAMP(3) NOT NULL,
CONSTRAINT "FileLibExportJob_pkey" PRIMARY KEY ("id")
);
-- CreateIndex (schema-declared)
CREATE INDEX "FileLibNode_organizationId_parentId_deletedAt_idx" ON "FileLibNode"("organizationId", "parentId", "deletedAt");
CREATE INDEX "FileLibNode_organizationId_pathIds_idx" ON "FileLibNode"("organizationId", "pathIds");
CREATE INDEX "FileLibNode_creatorId_idx" ON "FileLibNode"("creatorId");
CREATE INDEX "FileLibGrant_organizationId_revokedAt_idx" ON "FileLibGrant"("organizationId", "revokedAt");
CREATE INDEX "FileLibGrant_principalType_principalId_revokedAt_idx" ON "FileLibGrant"("principalType", "principalId", "revokedAt");
CREATE INDEX "FileLibGrant_nodeId_revokedAt_idx" ON "FileLibGrant"("nodeId", "revokedAt");
CREATE INDEX "FileLibExportJob_organizationId_status_idx" ON "FileLibExportJob"("organizationId", "status");
-- D14:活跃兄弟节点大小写不敏感唯一。root 的 parentId 为 NULL,用 COALESCE 归入同一键空间。
CREATE UNIQUE INDEX "FileLibNode_active_sibling_name_key"
ON "FileLibNode"("organizationId", COALESCE("parentId", ''), "nameLower")
WHERE "deletedAt" IS NULL;
-- 契约 2.3:同一节点上同一 principal 至多一条活跃授权(Postgres 原生 UNIQUE 无法约束 NULL revokedAt)。
CREATE UNIQUE INDEX "FileLibGrant_active_unique"
ON "FileLibGrant"("nodeId", "principalType", "principalId")
WHERE "revokedAt" IS NULL;
-- AddForeignKey
ALTER TABLE "FileLibNode" ADD CONSTRAINT "FileLibNode_organizationId_fkey" FOREIGN KEY ("organizationId") REFERENCES "Organization"("id") ON DELETE CASCADE ON UPDATE CASCADE;
ALTER TABLE "FileLibNode" ADD CONSTRAINT "FileLibNode_parentId_fkey" FOREIGN KEY ("parentId") REFERENCES "FileLibNode"("id") ON DELETE RESTRICT ON UPDATE CASCADE;
ALTER TABLE "FileLibGrant" ADD CONSTRAINT "FileLibGrant_nodeId_fkey" FOREIGN KEY ("nodeId") REFERENCES "FileLibNode"("id") ON DELETE CASCADE ON UPDATE CASCADE;
ALTER TABLE "FileLibProjectSettings" ADD CONSTRAINT "FileLibProjectSettings_nodeId_fkey" FOREIGN KEY ("nodeId") REFERENCES "FileLibNode"("id") ON DELETE CASCADE ON UPDATE CASCADE;
ALTER TABLE "FileLibExportJob" ADD CONSTRAINT "FileLibExportJob_nodeId_fkey" FOREIGN KEY ("nodeId") REFERENCES "FileLibNode"("id") ON DELETE CASCADE ON UPDATE CASCADE;
@@ -0,0 +1,2 @@
-- 为 FileLibNode 加简介字段,老师在创建/概览页填写。
ALTER TABLE "FileLibNode" ADD COLUMN "description" TEXT;
+125
View File
@@ -50,6 +50,7 @@ model Organization {
projectGroupBindings ProjectGroupBinding[] projectGroupBindings ProjectGroupBinding[]
auditEntries AuditEntry[] @relation("organizationAudit") auditEntries AuditEntry[] @relation("organizationAudit")
projectSearchDocuments ProjectSearchDocument[] projectSearchDocuments ProjectSearchDocument[]
fileLibNodes FileLibNode[]
@@index([status]) @@index([status])
} }
@@ -923,3 +924,127 @@ model CapabilityCredentialVersion {
@@index([keyId]) @@index([keyId])
@@index([createdByUserId]) @@index([createdByUserId])
} }
// --- File library (文件库) -------------------------------------------------
//
// 独立模块,语义由仓库根《文件库-接口契约.md》(C/D 编号)与 .omo/文件库-开工计划.md
// (D11D19)锚定。与上面的 Folder/Project(hub 自己的 explorer,ADR-0021)是两套
// 体系,不复用、不互相引用。
/// 文件库目录树节点:文件夹(容器)或项目(叶子,关联 git 仓库)。
/// parentId 是树的权威关系;pathIds 是 id 编码的物化路径(派生),随 create/move
/// 在事务内维护(计划 D12;name 不入路径,rename 不重写后代)。
model FileLibNode {
id String @id
organizationId String
parentId String?
kind FileLibNodeKind
name String
/// D14:NFC+trim 的小写形式;活跃兄弟节点大小写不敏感唯一(部分唯一索引在迁移 SQL)。
nameLower String
/// id 编码物化路径,形如 "/rootId/childId/selfId"。祖先展开与前缀查询都用它。
pathIds String
/// D11:创建者不可变,自动持有 isCreatorGrant=true 的 MANAGE grant。
/// 故意不建 FK:这是不可变历史事实,不随 User 生命周期变化。
creatorId String
/// 老师可填写的简介,创建/概览页展示,通俗易懂地说明这个节点的用途。
description String?
/// 项目 provisioning 状态机(DB/git 双写协调,Metis 风险#1);文件夹恒 READY。
provisionStatus FileLibProvisionStatus @default(READY)
/// 项目仓库目录(绝对路径);文件夹为 null。
storageDir String?
deletedAt DateTime?
createdAt DateTime @default(now())
updatedAt DateTime @updatedAt
organization Organization @relation(fields: [organizationId], references: [id], onDelete: Cascade)
parent FileLibNode? @relation("fileLibTree", fields: [parentId], references: [id], onDelete: Restrict)
children FileLibNode[] @relation("fileLibTree")
grants FileLibGrant[]
projectSettings FileLibProjectSettings?
exportJobs FileLibExportJob[]
@@index([organizationId, parentId, deletedAt])
@@index([organizationId, pathIds])
@@index([creatorId])
}
enum FileLibNodeKind {
FOLDER
PROJECT
}
enum FileLibProvisionStatus {
PROVISIONING
READY
FAILED
}
/// 文件库权限级别:MANAGE > EDIT > VIEW(契约 2.2,只取最高、无降权)。
enum FileLibRole {
VIEW
EDIT
MANAGE
}
enum FileLibPrincipalType {
USER
GROUP
}
/// 契约 2.3:grant 直接挂在节点上,最终权限 = max(个人, 递归 Group, 祖先继承)。
/// 活跃授权唯一性由迁移里的部分唯一索引保证(revokedAt IS NULL)。
model FileLibGrant {
id String @id @default(cuid())
organizationId String
nodeId String
principalType FileLibPrincipalType
principalId String
role FileLibRole
/// D11:创建者自动 grant;独立权限开关关闭时,项目级 grant 里只有它仍生效。
isCreatorGrant Boolean @default(false)
createdByUserId String?
createdAt DateTime @default(now())
revokedAt DateTime?
node FileLibNode @relation(fields: [nodeId], references: [id], onDelete: Cascade)
@@index([organizationId, revokedAt])
@@index([principalType, principalId, revokedAt])
@@index([nodeId, revokedAt])
}
/// 契约 P5/D11:项目独立权限开关。默认关闭(仅继承);关闭时项目级非创建者
/// grant 冻结不删除,重新开启即恢复。
model FileLibProjectSettings {
nodeId String @id
independentPermissionsEnabled Boolean @default(false)
node FileLibNode @relation(fields: [nodeId], references: [id], onDelete: Cascade)
}
enum FileLibExportStatus {
QUEUED
RUNNING
DONE
FAILED
}
/// 契约 D10:导出为异步任务。外部导出工具参数 OPEN-6,adapter 就位前先建模型。
model FileLibExportJob {
id String @id @default(cuid())
organizationId String
nodeId String
target String
params Json
status FileLibExportStatus @default(QUEUED)
downloadUrl String?
error String?
createdByUserId String
createdAt DateTime @default(now())
updatedAt DateTime @updatedAt
node FileLibNode @relation(fields: [nodeId], references: [id], onDelete: Cascade)
@@index([organizationId, status])
}
+45 -1
View File
@@ -58,12 +58,56 @@ allowDevLoginBypass = (NODE_ENV !== "production") && HUB_DEV_LOGIN_BYPASS 为真
| 文件 | 职责 | | 文件 | 职责 |
|------|------| |------|------|
| `plugin.ts` | 模块对外入口,`hub.ts``registerDatabasePlugin()` | | `plugin.ts` | 模块对外入口,`hub.ts``registerDatabasePlugin()` |
| `routes/databaseRoutes.ts` | 路由 + 页面渲染,**你主要在这里加内容** | | `routes/databaseRoutes.ts` | 登录页/dashboard + 各子路由装配点 |
| `routes/filelibRoutes.ts` | 文件库 树/授权/搜索 API |
| `routes/fileRoutes.ts` | 文件库 文件内容/导出 API |
| `routes/libraryPage.ts` | `/database/library` 文件库浏览页 |
| `filelib/` | 文件库领域层(见下) |
新增一类端点时:要么直接往 `databaseRoutes.ts``app.get("/database/...")` 新增一类端点时:要么直接往 `databaseRoutes.ts``app.get("/database/...")`
要么新建 `routes/xxxRoutes.ts` 并在 `databaseRoutes.ts``registerXxxRoutes(app, {...})` 要么新建 `routes/xxxRoutes.ts` 并在 `databaseRoutes.ts``registerXxxRoutes(app, {...})`
注册一次。 注册一次。
## 文件库(filelib/)
独立文件库模块,语义由仓库根《文件库-接口契约.md》(C/D 编号)与
`.omo/文件库-开工计划.md`(D11D19)锚定。**与 hub 自己的 Folder/Project
(ADR-0021 explorer)是两套体系,不复用。**
| 文件 | 职责 |
|------|------|
| `filelib/model.ts` | 角色秩(MANAGE>EDIT>VIEW)、D14 命名规则、FileLibError |
| `filelib/permission.ts` | 纯权限 reducer(取最高/不降权/祖先继承/D11 冻结),不碰 IO |
| `filelib/treeService.ts` | 树增删改查;每个写操作同事务落审计 |
| `filelib/grantService.ts` | 授权管理 + 契约 8.1 矩阵强制 + force_adjust |
| `filelib/fileService.ts` | 文件路径安全 + 版本化读写(先 git 后审计的顺序铁律) |
| `filelib/exportService.ts` | 导出 job 状态机(D10 异步)+ ExportAdapter port |
| `filelib/versionStore.ts` | 契约 C1 port + 内存实现(版本团队 npm 包到位后替换) |
| `filelib/groupResolver.ts` | 契约 C2 port + Team 过渡实现 |
| `filelib/groupResolverHttp.ts` | C2 HTTP 实现(HUB_GROUP_SERVICE_URL 启用;失败 → 503) |
| `filelib/audit.ts` | 审计动作词表(C3 §6.3)+ 同事务写入 |
| `filelib/guards.ts` | session → FileLibActor;网站管理员 = org OWNER/ADMIN(D19) |
| `filelib/routeShared.ts` | 路由共享件(依赖装配/错误映射/请求体校验) |
环境变量:
- `HUB_FILELIB_STORAGE_ROOT` — 项目 git 仓库根目录(默认 `./.filelib-repos`)
- `HUB_GROUP_SERVICE_URL` — Group 团队服务地址(C2);未配置时读 hub Team(扁平)
> ⚠️ 开发期注意:当前 VersionStore 是**进程内存**实现,**服务重启后仓库全失**,
> 此前创建的项目再访问文件会报 `repo_not_found`(需重建项目)。版本团队的
> 持久化 git 包到位后此问题消失。
关键语义速查:
- **D8**:无权限 → 404(不泄露存在性);越权 → 403;Group 服务故障 → 503
- **D11**:creator 不可变 + 自动 MANAGE;独立权限关闭时项目级非创建者 grant 冻结
- **D12**:move = 本节点 MANAGE + 目标父 EDIT+,事务 + pg 咨询锁
- **D15**:删除只打标本节点,"任一祖先已删"即整支不可见
- **8.1**:MANAGE 仅创建者可授/收;creator grant 不可动
- **审计**:一切写操作在业务事务内写 AuditEntry(同事务,失败即回滚);
文件内容写先 versionStore.commit 再审计(宁多版本,不造假审计)
## 约定(与 admin 面一致) ## 约定(与 admin 面一致)
1. 路由用**绝对路径** `"/database/..."`,不用 Fastify prefix —— 每条路由 grep 得到。 1. 路由用**绝对路径** `"/database/..."`,不用 Fastify prefix —— 每条路由 grep 得到。
+72
View File
@@ -0,0 +1,72 @@
/**
* 文件库审计 sink(契约 C3 的入驻适配)。
*
* 契约原文:本地 outbox 表(与业务同事务)→ 中继 POST 到独立审计服务。
* 入驻 hub 后的适配:审计同事 = 本库 AuditEntry,与业务写在同一 Prisma 事务
* 内落库 —— 同库同事务天然满足"操作成功则日志必存在",比 outbox+relay 更强。
* 若审计团队日后独立成服务,只换本文件的实现,action 词汇表保持不变。
*/
import type { Prisma } from "@prisma/client";
/** C3 §6.3:文件库审计动作词汇表(与契约文档逐条对应,改词需升契约版本)。 */
export const FILE_LIB_AUDIT_ACTIONS = {
folderCreate: "folder.create",
folderRename: "folder.rename",
folderMove: "folder.move",
folderDelete: "folder.delete",
projectCreate: "project.create",
projectRename: "project.rename",
projectMove: "project.move",
projectDelete: "project.delete",
permissionGrant: "permission.grant",
permissionUpdate: "permission.update",
permissionRevoke: "permission.revoke",
independentEnable: "project.independent_permission.enable",
independentDisable: "project.independent_permission.disable",
independentChange: "project.independent_permission.change",
fileUpload: "file.upload",
fileRename: "file.rename",
fileDelete: "file.delete",
fileCommit: "file.commit",
fileConflictDetected: "file.conflict_detected",
exportRun: "export.run",
adminForceAdjust: "admin.force_adjust",
} as const;
export type FileLibAuditObjectType = "folder" | "project" | "file" | "grant" | "export_job";
export interface FileLibAuditEntry {
readonly action: string;
readonly actorUserId: string;
readonly organizationId: string;
readonly objectType: FileLibAuditObjectType;
readonly objectId: string;
/** 节点 id 路径(pathIds)或项目内文件路径,便于按路径检索。 */
readonly objectPath: string;
readonly detail?: Record<string, unknown> | undefined;
}
/**
* 在调用方的事务里写一条审计。刻意不吞错:写不出来整个业务操作回滚
* (需求 5.1"操作成功则日志必存在"的强保证)。
*/
export async function writeFileLibAudit(
tx: Prisma.TransactionClient,
entry: FileLibAuditEntry,
): Promise<void> {
const metadata: Record<string, unknown> = {
objectType: entry.objectType,
objectId: entry.objectId,
objectPath: entry.objectPath,
...(entry.detail ?? {}),
};
await tx.auditEntry.create({
data: {
action: entry.action,
actorUserId: entry.actorUserId,
organizationId: entry.organizationId,
metadata: metadata as Prisma.InputJsonValue,
},
});
}
+195
View File
@@ -0,0 +1,195 @@
/**
* 导出(契约 D10):异步任务 + 状态机 QUEUED → RUNNING → DONE/FAILED。
*
* ExportAdapter 是外部导出工具的 port(参数清单 OPEN-6,真身到位后替换)。
* 当前 stub 适配器产出"文件清单 manifest"文本,证明状态机端到端可跑;
* 产物存进程内存(v1 stub;生产应落对象存储/磁盘 —— 见 OPEN 清单)。
*/
import { randomUUID } from "node:crypto";
import { FileLibError } from "./model.js";
import { FILE_LIB_AUDIT_ACTIONS, writeFileLibAudit } from "./audit.js";
import { requireAccessInTx, type FileLibActor } from "./treeService.js";
import type { FileDeps } from "./fileService.js";
export interface ExportAdapterInput {
readonly storageDir: string;
readonly target: string;
readonly params: Record<string, unknown>;
readonly listFiles: (prefix?: string) => Promise<readonly { path: string; size: number }[]>;
readonly readFile: (path: string) => Promise<Buffer>;
}
export interface ExportArtifact {
readonly filename: string;
readonly content: Buffer;
}
export interface ExportAdapter {
readonly target: string;
run(input: ExportAdapterInput): Promise<ExportArtifact>;
}
/** stub 适配器:生成项目文件清单,端到端验证 job 状态机。OPEN-6 后换真导出工具。 */
export function createManifestStubAdapter(versionStore: FileDeps["versionStore"]): ExportAdapter {
return {
target: "manifest",
async run(input) {
const files = await input.listFiles();
const lines = [
`# Export manifest (stub adapter)`,
`target: ${input.target}`,
`storageDir: ${input.storageDir}`,
`files: ${files.length}`,
``,
...files.map((f) => `${String(f.size).padStart(10)} ${f.path}`),
];
return { filename: "manifest.txt", content: Buffer.from(lines.join("\n"), "utf8") };
},
};
}
// v1 stub 产物存储(进程内存,重启即失;生产替换为持久存储)。
const artifacts = new Map<string, ExportArtifact>();
export interface ExportDeps extends FileDeps {
readonly adapters: readonly ExportAdapter[];
}
export interface ExportJobDto {
readonly id: string;
readonly nodeId: string;
readonly target: string;
readonly status: "QUEUED" | "RUNNING" | "DONE" | "FAILED";
readonly error: string | null;
readonly createdAt: Date;
}
/** 提交导出(需 VIEW):建行(QUEUED)+ export.run 审计,同事务;异步执行。 */
export async function submitExport(
deps: ExportDeps,
actor: FileLibActor,
projectId: string,
target: string,
params: Record<string, unknown>,
): Promise<ExportJobDto> {
const { node } = await deps.prisma.$transaction(async (tx) =>
requireAccessInTx(tx, deps, actor, projectId, "VIEW"),
);
if (node.kind !== "PROJECT") {
throw new FileLibError(400, "invalid_node_kind", "export applies to projects only");
}
const adapter = deps.adapters.find((a) => a.target === target);
if (adapter === undefined) {
throw new FileLibError(400, "unknown_target", `no export adapter for target "${target}"`);
}
if (node.storageDir === null) {
throw new FileLibError(409, "project_not_ready", "project repository is not ready");
}
const jobId = randomUUID();
const job = await deps.prisma.$transaction(async (tx) => {
const created = await tx.fileLibExportJob.create({
data: {
id: jobId,
organizationId: deps.organizationId,
nodeId: node.id,
target,
params: params as never,
status: "QUEUED",
createdByUserId: actor.userId,
},
});
await writeFileLibAudit(tx, {
action: FILE_LIB_AUDIT_ACTIONS.exportRun,
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: "export_job",
objectId: jobId,
objectPath: node.pathIds,
detail: { target, params },
});
return created;
});
const storageDir = node.storageDir;
setImmediate(() => {
void runExportJob(deps, adapter, jobId, storageDir, target, params).catch(() => undefined);
});
return toDto(job);
}
async function runExportJob(
deps: ExportDeps,
adapter: ExportAdapter,
jobId: string,
storageDir: string,
target: string,
params: Record<string, unknown>,
): Promise<void> {
await deps.prisma.fileLibExportJob.update({ where: { id: jobId }, data: { status: "RUNNING" } });
try {
const artifact = await adapter.run({
storageDir,
target,
params,
listFiles: (prefix) => deps.versionStore.list(storageDir, prefix),
readFile: (path) => deps.versionStore.read(storageDir, path),
});
artifacts.set(jobId, artifact);
await deps.prisma.fileLibExportJob.update({
where: { id: jobId },
data: { status: "DONE", downloadUrl: `/database/api/exports/${jobId}/download` },
});
} catch (error) {
await deps.prisma.fileLibExportJob.update({
where: { id: jobId },
data: { status: "FAILED", error: String(error) },
});
}
}
export async function getExportJob(
deps: ExportDeps,
actor: FileLibActor,
jobId: string,
): Promise<ExportJobDto> {
const job = await deps.prisma.fileLibExportJob.findFirst({
where: { id: jobId, organizationId: deps.organizationId },
});
if (job === null) throw new FileLibError(404, "export_not_found", "export job not found");
// D8:对源项目无 View → 404(不泄露 job 存在性)。
await deps.prisma.$transaction(async (tx) => requireAccessInTx(tx, deps, actor, job.nodeId, "VIEW"));
return toDto(job);
}
export async function downloadExport(
deps: ExportDeps,
actor: FileLibActor,
jobId: string,
): Promise<ExportArtifact> {
await getExportJob(deps, actor, jobId);
const artifact = artifacts.get(jobId);
if (artifact === undefined) {
throw new FileLibError(409, "export_not_ready", "export artifact is not available");
}
return artifact;
}
function toDto(job: {
id: string;
nodeId: string;
target: string;
status: "QUEUED" | "RUNNING" | "DONE" | "FAILED";
error: string | null;
createdAt: Date;
}): ExportJobDto {
return {
id: job.id,
nodeId: job.nodeId,
target: job.target,
status: job.status,
error: job.error,
createdAt: job.createdAt,
};
}
+275
View File
@@ -0,0 +1,275 @@
/**
* 文件内容服务(Phase 3):路径安全 + 版本化文件操作 + 审计。
*
* 顺序铁律(Metis 风险#1 的落地):
* - 内容写:先 versionStore.commit(业务事实本体)→ 再 DB 事务(审计)。
* 宁多一个无审计的版本,不造一条假审计。
* - conflict:写 file.conflict_detected(冲突本身就是事件),再抛 409。
* - 读:随取随读,不写审计(需求 5.2 未列读操作)。
*/
import { FileLibError } from "./model.js";
import { FILE_LIB_AUDIT_ACTIONS, writeFileLibAudit } from "./audit.js";
import type { CommitResult, FileEntry, VersionInfo, VersionStore } from "./versionStore.js";
import type { AccessDeps, FileLibActor } from "./treeService.js";
import { requireAccessInTx } from "./treeService.js";
import type { FileLibNode, PrismaClient } from "@prisma/client";
export const FILE_PATH_MAX_LENGTH = 512;
export const FILE_PATH_MAX_DEPTH = 32;
export const FILE_CONTENT_MAX_BYTES = 10 * 1024 * 1024; // OPEN-5 初值
const CONTROL_CHARS = /[\p{C}]/u;
const FORBIDDEN_SEGMENTS = new Set(["", ".", "..", ".git"]);
/**
* 路径安全(Metis 安全红线):NFC;拒绝反斜杠、控制字符、空段、
* "." / ".." / ".git" 段、绝对路径、超长/超深。返回规范化相对路径。
*/
export function validateFilePath(raw: string): string {
const normalized = raw.normalize("NFC");
if (normalized.length === 0 || normalized.length > FILE_PATH_MAX_LENGTH) {
throw new FileLibError(400, "invalid_path", `path must be 1..${FILE_PATH_MAX_LENGTH} characters`);
}
if (normalized.includes("\\")) {
throw new FileLibError(400, "invalid_path", "path must use '/' separators");
}
if (CONTROL_CHARS.test(normalized)) {
throw new FileLibError(400, "invalid_path", "path must not contain control characters");
}
const segments = normalized.split("/");
if (segments.length > FILE_PATH_MAX_DEPTH) {
throw new FileLibError(400, "invalid_path", `path depth exceeds ${FILE_PATH_MAX_DEPTH}`);
}
for (const segment of segments) {
if (FORBIDDEN_SEGMENTS.has(segment)) {
throw new FileLibError(400, "invalid_path", `forbidden path segment: "${segment}"`);
}
}
return normalized;
}
export interface FileDeps extends AccessDeps {
readonly prisma: PrismaClient;
readonly versionStore: VersionStore;
}
type ProjectChain = { readonly node: FileLibNode; readonly storageDir: string };
async function requireProject(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
minRole: "VIEW" | "EDIT",
): Promise<ProjectChain> {
const { node } = await deps.prisma.$transaction(async (tx) =>
requireAccessInTx(tx, deps, actor, projectId, minRole),
);
if (node.kind !== "PROJECT") {
throw new FileLibError(400, "invalid_node_kind", "file operations apply to projects only");
}
if (node.provisionStatus === "PROVISIONING") {
throw new FileLibError(409, "project_not_ready", "project repository is still provisioning");
}
if (node.provisionStatus === "FAILED") {
throw new FileLibError(409, "project_not_ready", "project repository provisioning failed");
}
if (node.storageDir === null) {
throw new FileLibError(500, "storage_missing", "project has no storage directory");
}
return { node, storageDir: node.storageDir };
}
export type FileContentEncoding = "utf8" | "base64";
export interface FileContentDto {
readonly path: string;
readonly version: string;
readonly encoding: FileContentEncoding;
readonly content: string;
readonly size: number;
}
export function decodeContent(content: string, encoding: FileContentEncoding): string | Buffer {
return encoding === "base64" ? Buffer.from(content, "base64") : content;
}
function encodeContent(buffer: Buffer): { readonly encoding: FileContentEncoding; readonly content: string } {
// 粗判二进制:含 NUL 字节即按 base64 返回(需求 2.5 在线编辑仅针对文本)。
return buffer.includes(0)
? { encoding: "base64", content: buffer.toString("base64") }
: { encoding: "utf8", content: buffer.toString("utf8") };
}
function checkSize(content: string | Buffer): void {
const bytes = typeof content === "string" ? Buffer.byteLength(content, "utf8") : content.byteLength;
if (bytes > FILE_CONTENT_MAX_BYTES) {
throw new FileLibError(413, "file_too_large", `file exceeds ${FILE_CONTENT_MAX_BYTES} bytes`);
}
}
async function auditFile(
deps: FileDeps,
actor: FileLibActor,
action: string,
project: ProjectChain,
filePath: string,
detail: Record<string, unknown>,
): Promise<void> {
await deps.prisma.$transaction(async (tx) => {
await writeFileLibAudit(tx, {
action,
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: "file",
objectId: project.node.id,
objectPath: `${project.node.pathIds}:${filePath}`,
detail,
});
});
}
/* ---------------------------------------------------------------- 读操作 */
export async function listFiles(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
prefix?: string,
): Promise<readonly FileEntry[]> {
const project = await requireProject(deps, actor, projectId, "VIEW");
return deps.versionStore.list(project.storageDir, prefix === undefined ? undefined : validateFilePath(prefix));
}
export async function readFile(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
rawPath: string,
): Promise<FileContentDto> {
const filePath = validateFilePath(rawPath);
const project = await requireProject(deps, actor, projectId, "VIEW");
const [version, buffer] = await Promise.all([
deps.versionStore.head(project.storageDir, filePath),
deps.versionStore.read(project.storageDir, filePath),
]);
const { encoding, content } = encodeContent(buffer);
return { path: filePath, version, encoding, content, size: buffer.byteLength };
}
/** 原始字节下载(浏览器 save-as 用):JSON 之外的第二条读取通道,同样的 VIEW 门禁。 */
export async function readFileRaw(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
rawPath: string,
): Promise<{ readonly buffer: Buffer; readonly version: string; readonly filename: string }> {
const filePath = validateFilePath(rawPath);
const project = await requireProject(deps, actor, projectId, "VIEW");
const [version, buffer] = await Promise.all([
deps.versionStore.head(project.storageDir, filePath),
deps.versionStore.read(project.storageDir, filePath),
]);
return { buffer, version, filename: filePath.split("/").pop() ?? "download" };
}
export async function fileHistory(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
rawPath: string,
limit?: number,
): Promise<readonly VersionInfo[]> {
const filePath = validateFilePath(rawPath);
const project = await requireProject(deps, actor, projectId, "VIEW");
return deps.versionStore.history(project.storageDir, filePath, limit);
}
export async function diffFile(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
rawPath: string,
from: string,
to: string,
): Promise<{ readonly diff: string }> {
const filePath = validateFilePath(rawPath);
const project = await requireProject(deps, actor, projectId, "VIEW");
return { diff: await deps.versionStore.diff(project.storageDir, filePath, from, to) };
}
/* ---------------------------------------------------------------- 写操作 */
export interface CommitInput {
readonly path: string;
/** null = 新建(已存在则 409);编辑时传 readFile 拿到的 version。 */
readonly baseVersion: string | null;
readonly content: string;
readonly encoding?: FileContentEncoding | undefined;
readonly message?: string | undefined;
}
/**
* 统一写入口(上传/编辑共用):先 commit,成功写 file.commit / file.upload 审计;
* 冲突写 file.conflict_detected 后抛 409(details 带 currentVersion,编辑 UI 用它拉 diff)。
*/
export async function commitFile(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
input: CommitInput,
): Promise<{ readonly version: string }> {
const filePath = validateFilePath(input.path);
const content = decodeContent(input.content, input.encoding ?? "utf8");
checkSize(content);
const project = await requireProject(deps, actor, projectId, "EDIT");
const result: CommitResult = await deps.versionStore.commit(project.storageDir, filePath, {
baseVersion: input.baseVersion,
content,
message: input.message,
author: actor.userId,
});
if (result.status === "conflict") {
await auditFile(deps, actor, FILE_LIB_AUDIT_ACTIONS.fileConflictDetected, project, filePath, {
baseVersion: input.baseVersion,
currentVersion: result.currentVersion,
});
throw new FileLibError(409, "version_conflict", "file was modified since baseVersion", {
currentVersion: result.currentVersion,
});
}
await auditFile(
deps,
actor,
input.baseVersion === null ? FILE_LIB_AUDIT_ACTIONS.fileUpload : FILE_LIB_AUDIT_ACTIONS.fileCommit,
project,
filePath,
{ version: result.version, message: input.message ?? null },
);
return { version: result.version };
}
export async function deleteFile(
deps: FileDeps,
actor: FileLibActor,
projectId: string,
rawPath: string,
baseVersion: string,
): Promise<void> {
const filePath = validateFilePath(rawPath);
const project = await requireProject(deps, actor, projectId, "EDIT");
const result = await deps.versionStore.remove(project.storageDir, filePath, baseVersion);
if (result.status === "conflict") {
await auditFile(deps, actor, FILE_LIB_AUDIT_ACTIONS.fileConflictDetected, project, filePath, {
baseVersion,
currentVersion: result.currentVersion,
});
throw new FileLibError(409, "version_conflict", "file was modified since baseVersion", {
currentVersion: result.currentVersion,
});
}
await auditFile(deps, actor, FILE_LIB_AUDIT_ACTIONS.fileDelete, project, filePath, { baseVersion });
}
+319
View File
@@ -0,0 +1,319 @@
/**
* 授权管理(契约 8.1 矩阵的服务端强制)。
*
* 矩阵:
* - 创建者(creatorId 不可变):可授/改/收 MANAGE、EDIT、VIEW;自身 creator grant 不可动
* - MANAGE 持有者:可授/改/收 EDIT、VIEW;不可碰 MANAGE;不可动创建者
* - EDIT/VIEW:无授权能力(requireAccess MANAGE 已挡)
* - 网站管理员:走 forceAdjustGrants(不查节点权限,D19),全部留 admin.force_adjust 审计
*
* D8:目标节点不可见/无权限 → 404;有权限但矩阵禁止 → 403。
*/
import { Prisma } from "@prisma/client";
import type { FileLibGrant, FileLibNode, PrismaClient } from "@prisma/client";
import { FileLibError, type FileLibRole } from "./model.js";
import { FILE_LIB_AUDIT_ACTIONS, writeFileLibAudit } from "./audit.js";
import {
requireAccessInTx,
type AccessDeps,
type FileLibActor,
type InitialGrant,
} from "./treeService.js";
export interface GrantDto {
readonly id: string;
readonly principalType: "USER" | "GROUP";
readonly principalId: string;
readonly role: FileLibRole;
readonly isCreatorGrant: boolean;
readonly createdAt: Date;
}
function toDto(grant: FileLibGrant): GrantDto {
return {
id: grant.id,
principalType: grant.principalType,
principalId: grant.principalId,
role: grant.role,
isCreatorGrant: grant.isCreatorGrant,
createdAt: grant.createdAt,
};
}
type Tx = Prisma.TransactionClient;
type Deps = AccessDeps & { readonly prisma: PrismaClient };
/** MANAGE 门禁:带 tx 时用调用方事务(与后续写同绳),不带时自开一个。 */
async function requireManage(
deps: Deps,
actor: FileLibActor,
nodeId: string,
tx?: Tx,
): Promise<{ readonly node: FileLibNode; readonly role: FileLibRole }> {
if (tx !== undefined) return requireAccessInTx(tx, deps, actor, nodeId, "MANAGE");
return deps.prisma.$transaction(async (inner) => requireAccessInTx(inner, deps, actor, nodeId, "MANAGE"));
}
/** 列出节点活跃授权(需 MANAGE)。 */
export async function listGrants(
deps: Deps,
actor: FileLibActor,
nodeId: string,
): Promise<readonly GrantDto[]> {
await requireManage(deps, actor, nodeId);
const grants = await deps.prisma.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, nodeId, revokedAt: null },
orderBy: [{ isCreatorGrant: "desc" }, { createdAt: "asc" }],
});
return grants.map(toDto);
}
export interface PutGrantsResult {
readonly granted: number;
readonly updated: number;
readonly grants: readonly GrantDto[];
}
/**
* 批量授予/修改(upsert 语义):同 principal 已有活跃授权 → 改级别(permission.update);
* 没有 → 新建(permission.grant)。8.1 矩阵在写之前整体校验。
*/
export async function putGrants(
deps: Deps,
actor: FileLibActor,
nodeId: string,
items: readonly InitialGrant[],
): Promise<PutGrantsResult> {
validateGrantItems(items);
return deps.prisma.$transaction(async (tx) => {
const { node } = await requireManage(deps, actor, nodeId, tx);
const isCreator = node.creatorId === actor.userId;
for (const item of items) {
if (item.role === "MANAGE" && !isCreator) {
throw new FileLibError(403, "only_creator_can_grant_manage", "only the creator can grant MANAGE");
}
if (item.principalType === "USER" && item.principalId === node.creatorId) {
throw new FileLibError(403, "cannot_touch_creator", "the creator's grant is immutable");
}
}
let granted = 0;
let updated = 0;
for (const item of items) {
const existing = await tx.fileLibGrant.findFirst({
where: {
nodeId: node.id,
principalType: item.principalType,
principalId: item.principalId,
revokedAt: null,
},
});
if (existing !== null) {
if (existing.isCreatorGrant) {
throw new FileLibError(403, "cannot_touch_creator", "the creator's grant is immutable");
}
if (existing.role !== item.role) {
await tx.fileLibGrant.update({ where: { id: existing.id }, data: { role: item.role } });
updated += 1;
await audit(tx, deps, actor, FILE_LIB_AUDIT_ACTIONS.permissionUpdate, node.id, node.pathIds, { ...item });
}
} else {
await tx.fileLibGrant.create({
data: {
organizationId: deps.organizationId,
nodeId: node.id,
principalType: item.principalType,
principalId: item.principalId,
role: item.role,
createdByUserId: actor.userId,
},
});
granted += 1;
await audit(tx, deps, actor, FILE_LIB_AUDIT_ACTIONS.permissionGrant, node.id, node.pathIds, { ...item });
}
}
const grants = await tx.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, nodeId: node.id, revokedAt: null },
orderBy: [{ isCreatorGrant: "desc" }, { createdAt: "asc" }],
});
return { granted, updated, grants: grants.map(toDto) };
});
}
/** 收回授权(需 MANAGE;creator grant 与 MANAGE grant 有额外限制,见 8.1)。 */
export async function revokeGrant(
deps: Deps,
actor: FileLibActor,
nodeId: string,
grantId: string,
): Promise<void> {
await deps.prisma.$transaction(async (tx) => {
const { node } = await requireManage(deps, actor, nodeId, tx);
const grant = await tx.fileLibGrant.findFirst({
where: { id: grantId, nodeId: node.id, revokedAt: null },
});
if (grant === null) throw new FileLibError(404, "grant_not_found", "grant not found");
if (grant.isCreatorGrant) {
throw new FileLibError(403, "cannot_touch_creator", "the creator's grant is immutable");
}
if (grant.role === "MANAGE" && node.creatorId !== actor.userId) {
throw new FileLibError(403, "only_creator_can_revoke_manage", "only the creator can revoke MANAGE");
}
await tx.fileLibGrant.update({ where: { id: grant.id }, data: { revokedAt: new Date() } });
await audit(tx, deps, actor, FILE_LIB_AUDIT_ACTIONS.permissionRevoke, node.id, node.pathIds, {
principalType: grant.principalType,
principalId: grant.principalId,
role: grant.role,
});
});
}
/**
* 网站管理员强制调整(D19):凭 node id 操作,不查操作者节点权限;矩阵豁免;
* 每一条变更都落 admin.force_adjust 审计(高危留痕)。
*/
export async function forceAdjustGrants(
deps: Deps,
actor: FileLibActor,
nodeId: string,
items: readonly InitialGrant[],
): Promise<PutGrantsResult> {
if (!actor.isWebsiteAdmin) {
throw new FileLibError(403, "forbidden", "force adjust requires website administrator");
}
validateGrantItems(items);
return deps.prisma.$transaction(async (tx) => {
const node = await tx.fileLibNode.findFirst({
where: { id: nodeId, organizationId: deps.organizationId, deletedAt: null },
});
if (node === null) throw new FileLibError(404, "node_not_found", "node not found");
let granted = 0;
let updated = 0;
for (const item of items) {
const existing = await tx.fileLibGrant.findFirst({
where: {
nodeId: node.id,
principalType: item.principalType,
principalId: item.principalId,
revokedAt: null,
},
});
if (existing !== null) {
if (existing.role !== item.role) {
await tx.fileLibGrant.update({ where: { id: existing.id }, data: { role: item.role } });
updated += 1;
await audit(tx, deps, actor, FILE_LIB_AUDIT_ACTIONS.adminForceAdjust, node.id, node.pathIds, {
change: "update",
principalType: item.principalType,
principalId: item.principalId,
from: existing.role,
to: item.role,
});
}
} else {
await tx.fileLibGrant.create({
data: {
organizationId: deps.organizationId,
nodeId: node.id,
principalType: item.principalType,
principalId: item.principalId,
role: item.role,
createdByUserId: actor.userId,
},
});
granted += 1;
await audit(tx, deps, actor, FILE_LIB_AUDIT_ACTIONS.adminForceAdjust, node.id, node.pathIds, {
change: "grant",
principalType: item.principalType,
principalId: item.principalId,
role: item.role,
});
}
}
const grants = await tx.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, nodeId: node.id, revokedAt: null },
orderBy: [{ isCreatorGrant: "desc" }, { createdAt: "asc" }],
});
return { granted, updated, grants: grants.map(toDto) };
});
}
/** 项目独立权限开关(P5/D11):需 MANAGE;状态不变则空操作。 */
export async function setIndependentPermission(
deps: Deps,
actor: FileLibActor,
nodeId: string,
enabled: boolean,
): Promise<{ readonly enabled: boolean }> {
return deps.prisma.$transaction(async (tx) => {
const { node } = await requireManage(deps, actor, nodeId, tx);
if (node.kind !== "PROJECT") {
throw new FileLibError(400, "invalid_node_kind", "independent permission applies to projects only");
}
const current = await tx.fileLibProjectSettings.findUnique({
where: { nodeId: node.id },
select: { independentPermissionsEnabled: true },
});
if ((current?.independentPermissionsEnabled ?? false) === enabled) {
return { enabled }; // 状态未变:空操作,不产生审计
}
await tx.fileLibProjectSettings.upsert({
where: { nodeId: node.id },
update: { independentPermissionsEnabled: enabled },
create: { nodeId: node.id, independentPermissionsEnabled: enabled },
});
await writeFileLibAudit(tx, {
action: enabled
? FILE_LIB_AUDIT_ACTIONS.independentEnable
: FILE_LIB_AUDIT_ACTIONS.independentDisable,
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: "project",
objectId: node.id,
objectPath: node.pathIds,
detail: { enabled },
});
return { enabled };
});
}
function validateGrantItems(items: readonly InitialGrant[]): void {
if (items.length === 0) throw new FileLibError(400, "invalid_request", "grants must not be empty");
const seen = new Set<string>();
for (const item of items) {
if (item.principalType !== "USER" && item.principalType !== "GROUP") {
throw new FileLibError(400, "invalid_request", `bad principalType: ${String(item.principalType)}`);
}
if (item.role !== "VIEW" && item.role !== "EDIT" && item.role !== "MANAGE") {
throw new FileLibError(400, "invalid_request", `bad role: ${String(item.role)}`);
}
if (item.principalId.trim() === "") {
throw new FileLibError(400, "invalid_request", "principalId must not be empty");
}
const key = `${item.principalType}:${item.principalId}`;
if (seen.has(key)) throw new FileLibError(400, "duplicate_principal", `duplicate principal: ${key}`);
seen.add(key);
}
}
async function audit(
tx: Prisma.TransactionClient,
deps: Deps,
actor: FileLibActor,
action: string,
nodeId: string,
pathIds: string,
detail: Record<string, unknown>,
): Promise<void> {
await writeFileLibAudit(tx, {
action,
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: "grant",
objectId: nodeId,
objectPath: pathIds,
detail,
});
}
+48
View File
@@ -0,0 +1,48 @@
/**
* GroupResolver port(契约 C2)。
*
* 权限计算只依赖这一个查询:"用户 → 所属 Group(含全部祖先)"。
* Group 系统(需求系统二:全局、无限嵌套)由别的团队交付;调用方只依赖此
* port,真身到位后替换实现,不换调用点。
*/
import type { PrismaClient } from "@prisma/client";
export interface GroupResolver {
resolveMemberGroupIds(userId: string): Promise<readonly string[]>;
}
/**
* 过渡实现:读 hub 既有 Team(org 内、扁平无嵌套 → "祖先即自身")。
* 需求 3.2 的祖先递归语义在嵌套 Group 落地前无从谈起;此实现保证权限引擎
* 的 Group 通路今天就是真的,而不是 mock。
*/
export function createTeamGroupResolver(
prisma: PrismaClient,
organizationId: string,
): GroupResolver {
return {
async resolveMemberGroupIds(userId) {
const memberships = await prisma.teamMembership.findMany({
where: {
userId,
revokedAt: null,
team: { organizationId, archivedAt: null },
},
select: { teamId: true },
});
return memberships.map((m) => m.teamId);
},
};
}
/** 单测 mock:静态 用户→组 映射。 */
export function createStaticGroupResolver(
map: Readonly<Record<string, readonly string[]>>,
): GroupResolver {
return {
async resolveMemberGroupIds(userId) {
return map[userId] ?? [];
},
};
}
@@ -0,0 +1,49 @@
/**
* GroupResolver 的 HTTP 实现(契约 C2,Group 团队服务到位后启用,
* 经 HUB_GROUP_SERVICE_URL 配置)。
*
* 语义红线:
* - 失败 → FileLibError(503, group_unavailable)。依赖故障不是"无权限",
* 绝不伪装成 404/403(计划 D13)。
* - 我方绝不自己推祖先:返回什么用什么,不在本地补逻辑。
*/
import { FileLibError } from "./model.js";
import type { GroupResolver } from "./groupResolver.js";
export interface HttpGroupResolverConfig {
readonly baseUrl: string;
readonly timeoutMs?: number;
/** 测试可注入假 fetch;生产用全局 fetch。 */
readonly fetchFn?: typeof fetch;
}
export function createHttpGroupResolver(config: HttpGroupResolverConfig): GroupResolver {
const timeoutMs = config.timeoutMs ?? 2_000;
const fetchFn = config.fetchFn ?? fetch;
return {
async resolveMemberGroupIds(userId) {
const url = `${config.baseUrl.replace(/\/$/, "")}/groups/resolve-member-groups?userId=${encodeURIComponent(userId)}`;
let response: Response;
try {
response = await fetchFn(url, { signal: AbortSignal.timeout(timeoutMs) });
} catch (error) {
throw new FileLibError(503, "group_unavailable", `group service unreachable: ${String(error)}`);
}
if (!response.ok) {
throw new FileLibError(503, "group_unavailable", `group service returned ${response.status}`);
}
let body: unknown;
try {
body = await response.json();
} catch {
throw new FileLibError(503, "group_unavailable", "group service returned malformed JSON");
}
const groupIds = (body as { groupIds?: unknown }).groupIds;
if (!Array.isArray(groupIds) || groupIds.some((id) => typeof id !== "string")) {
throw new FileLibError(503, "group_unavailable", "group service returned malformed payload");
}
return groupIds as readonly string[];
},
};
}
+47
View File
@@ -0,0 +1,47 @@
/**
* 文件库 HTTP 门禁(契约 C4 的入驻适配)。
*
* 身份链:hub session(飞书 OAuth / dev bypass)→ silo org membership。
* 网站管理员 = org 的 OWNER/ADMIN(D19:仅 root 创建与 force_adjust 特权,
* 不给内容读旁路);普通成员 = 任何活跃 membership;非成员 = 403。
*/
import type { FastifyReply, FastifyRequest } from "fastify";
import type { OrganizationMemberRole, PrismaClient } from "@prisma/client";
import { requireSession, sendError } from "../../admin/auth/guards.js";
import type { FileLibActor } from "./treeService.js";
export interface FileLibGuardDeps {
readonly prisma: PrismaClient;
readonly sessionSecret: string;
/** 文件库归属的 silo org(ADR-0020/0025)。 */
readonly organizationId: string;
}
const WEBSITE_ADMIN_ROLES: readonly OrganizationMemberRole[] = ["OWNER", "ADMIN"];
/** 每个 /database/api/* 端点第一行调它;返回 null 时响应已发出,fail closed。 */
export async function requireFileLibActor(
request: FastifyRequest,
reply: FastifyReply,
deps: FileLibGuardDeps,
): Promise<FileLibActor | null> {
const auth = await requireSession(request, reply, {
prisma: deps.prisma,
sessionSecret: deps.sessionSecret,
});
if (auth === null) return null;
const membership = await deps.prisma.organizationMembership.findFirst({
where: { organizationId: deps.organizationId, userId: auth.user.id, revokedAt: null },
select: { role: true },
});
if (membership === null) {
await sendError(reply, 403, "forbidden", "not a member of this organization");
return null;
}
return {
userId: auth.user.id,
isWebsiteAdmin: WEBSITE_ADMIN_ROLES.includes(membership.role),
};
}
+59
View File
@@ -0,0 +1,59 @@
/**
* 文件库领域基础:角色秩、命名规则(D14)、错误类型。
*
* 语义锚定:仓库根《文件库-接口契约.md》(2.2 权限等级 / D8 可见性 / D14 命名)
* 与 .omo/文件库-开工计划.md。本模块是独立文件库,不复用 hub 的
* Folder/Project/PermissionGrant 体系。
*/
export const FILE_LIB_ROLES = ["VIEW", "EDIT", "MANAGE"] as const;
export type FileLibRole = (typeof FILE_LIB_ROLES)[number];
/** 契约 2.2:MANAGE > EDIT > VIEW,严格全序。 */
export const ROLE_RANK: Record<FileLibRole, number> = { VIEW: 1, EDIT: 2, MANAGE: 3 };
export function roleAtLeast(role: FileLibRole, min: FileLibRole): boolean {
return ROLE_RANK[role] >= ROLE_RANK[min];
}
/** 业务错误。statusCode 由路由层映射为 HTTP 响应(D8 语义在此层只表达为 code)。 */
export class FileLibError extends Error {
constructor(
readonly statusCode: number,
readonly code: string,
message: string,
/** 结构化附加信息(如 409 时的 currentVersion),路由层并入错误响应。 */
readonly details?: Record<string, unknown>,
) {
super(message);
this.name = "FileLibError";
}
}
export const NODE_NAME_MAX_LENGTH = 128;
/** D14:禁 `/`;反斜杠同样禁止(它会变成存储路径的分隔符,且易用于伪装)。控制字符禁。 */
const FORBIDDEN_NAME_CHARS = /[/\\\p{C}]/u;
/**
* D14:NFC 归一化 + trim,然后校验长度与字符集。
* 违规抛 FileLibError(400, "invalid_name"),路由层原样透传。
*/
export function normalizeNodeName(raw: string): string {
const name = raw.normalize("NFC").trim();
if (name.length === 0) {
throw new FileLibError(400, "invalid_name", "name must not be empty");
}
if (name.length > NODE_NAME_MAX_LENGTH) {
throw new FileLibError(400, "invalid_name", `name exceeds ${NODE_NAME_MAX_LENGTH} characters`);
}
if (FORBIDDEN_NAME_CHARS.test(name)) {
throw new FileLibError(400, "invalid_name", "name must not contain '/', '\\' or control characters");
}
return name;
}
/** D14:活跃兄弟节点大小写不敏感唯一的比较键(DB 层另有部分唯一索引兜底)。 */
export function nameKey(normalizedName: string): string {
return normalizedName.toLowerCase();
}
+74
View File
@@ -0,0 +1,74 @@
/**
* 纯权限 reducer(契约 P6 / D11 / D8)。
*
* 设计约束(Metis 评审):本文件是纯函数层 —— 输入是"已解析好的" grant、祖先链
* 与用户组集合,不碰 DB / 网络。数据获取在 treeService。这样权限代数可以脱离
* 存储做密集单测与随机化不变量测试。
*/
import type { FileLibRole } from "./model.js";
import { ROLE_RANK } from "./model.js";
export interface FileLibGrantFact {
readonly nodeId: string;
readonly principalType: "USER" | "GROUP";
readonly principalId: string;
readonly role: FileLibRole;
readonly isCreatorGrant: boolean;
}
export interface EffectiveRoleInput {
/** 目标节点(self)。 */
readonly nodeId: string;
readonly nodeKind: "FOLDER" | "PROJECT";
/** 目标的全部祖先 id(不含 self,顺序无关)。 */
readonly ancestorIds: readonly string[];
/** 项目独立权限开关(D11/P5);文件夹忽略此值。 */
readonly independentPermissionsEnabled: boolean;
readonly userId: string;
/** C2 resolve 结果:用户直接所属 + 全部祖先 group 的 id 集合。 */
readonly groupIds: readonly string[];
/** self ancestors 上的全部活跃 grant(revokedAt 已由获取层过滤)。 */
readonly grants: readonly FileLibGrantFact[];
}
/**
* 契约 P6:effective(user, R) = max { grant.role | s ∈ {user} groups*(user),
* r ∈ {R} ancestors(R) };无匹配 → null(无任何权限)。
* "个人权限不能降权"在 max 语义下天然成立 —— 只取最高,不做减法。
*
* D11:目标为 PROJECT 且独立权限关闭时,项目级(挂在 self 上)非创建者 grant
* 冻结不参与计算;创建者的自动 grant(isCreatorGrant)始终生效。祖先链上的
* grant 不受开关影响。
*/
export function effectiveRole(input: EffectiveRoleInput): FileLibRole | null {
const onChain = new Set<string>([input.nodeId, ...input.ancestorIds]);
const groups = new Set(input.groupIds);
const freezeProjectGrants =
input.nodeKind === "PROJECT" && !input.independentPermissionsEnabled;
let best: FileLibRole | null = null;
for (const grant of input.grants) {
if (!onChain.has(grant.nodeId)) continue;
if (freezeProjectGrants && grant.nodeId === input.nodeId && !grant.isCreatorGrant) continue;
if (grant.principalType === "USER" && grant.principalId !== input.userId) continue;
if (grant.principalType === "GROUP" && !groups.has(grant.principalId)) continue;
if (best === null || ROLE_RANK[grant.role] > ROLE_RANK[best]) best = grant.role;
}
return best;
}
/**
* D8 可见性语义:
* - 完全无权限(effective === null)→ "not_found"(路由层映射 404,不泄露存在性);
* - 有权限但不足 → "forbidden"(路由层映射 403)。
*/
export type AccessVerdict =
| { readonly allowed: true; readonly role: FileLibRole }
| { readonly allowed: false; readonly reason: "not_found" | "forbidden" };
export function checkAccess(effective: FileLibRole | null, min: FileLibRole): AccessVerdict {
if (effective === null) return { allowed: false, reason: "not_found" };
if (ROLE_RANK[effective] < ROLE_RANK[min]) return { allowed: false, reason: "forbidden" };
return { allowed: true, role: effective };
}
+89
View File
@@ -0,0 +1,89 @@
/**
* /database/api/* 路由共享件:依赖装配、actor 门禁、统一错误映射。
* 约定(与 admin 面一致):绝对路径;guard 前置 fail closed;查询 scope 到 silo org。
*/
import type { FastifyReply, FastifyRequest } from "fastify";
import { Prisma } from "@prisma/client";
import type { PrismaClient } from "@prisma/client";
import { FileLibError } from "./model.js";
import { requireFileLibActor } from "./guards.js";
import type { FileLibActor, TreeServiceDeps } from "./treeService.js";
import type { GroupResolver } from "./groupResolver.js";
import type { VersionStore } from "./versionStore.js";
import type { ExportAdapter } from "./exportService.js";
export interface FileLibRouteDeps {
readonly prisma: PrismaClient;
readonly sessionSecret: string;
readonly organizationId: string;
readonly storageRoot: string;
readonly groupResolver: GroupResolver;
readonly versionStore: VersionStore;
readonly exportAdapters: readonly ExportAdapter[];
}
/** 组装 treeService 依赖(路由处理内直接使用)。 */
export function treeDeps(deps: FileLibRouteDeps): TreeServiceDeps {
return {
prisma: deps.prisma,
groupResolver: deps.groupResolver,
versionStore: deps.versionStore,
organizationId: deps.organizationId,
storageRoot: deps.storageRoot,
};
}
/** 端点第一行调用;null = 响应已发(401/403),fail closed。 */
export async function actorOrNull(
request: FastifyRequest,
reply: FastifyReply,
deps: FileLibRouteDeps,
): Promise<FileLibActor | null> {
return requireFileLibActor(request, reply, {
prisma: deps.prisma,
sessionSecret: deps.sessionSecret,
organizationId: deps.organizationId,
});
}
/** 统一错误出口:FileLibError → 语义码;P2002 → 409;其余 → 500(不泄露内部)。 */
export async function sendRouteError(reply: FastifyReply, error: unknown): Promise<void> {
if (error instanceof FileLibError) {
await reply.status(error.statusCode).send({
error: { code: error.code, message: error.message, ...(error.details ?? {}) },
});
return;
}
if (error instanceof Prisma.PrismaClientKnownRequestError && error.code === "P2002") {
await reply.status(409).send({ error: { code: "conflict", message: "uniqueness conflict" } });
return;
}
reply.log.error({ err: error }, "filelib route: unexpected error");
await reply.status(500).send({ error: { code: "internal", message: "internal error" } });
}
/** 请求体轻量校验(抛 FileLibError 400)。 */
export function bodyObject(body: unknown): Record<string, unknown> {
if (typeof body !== "object" || body === null || Array.isArray(body)) {
throw new FileLibError(400, "invalid_request", "request body must be a JSON object");
}
return body as Record<string, unknown>;
}
export function requireString(obj: Record<string, unknown>, key: string): string {
const value = obj[key];
if (typeof value !== "string" || value === "") {
throw new FileLibError(400, "invalid_request", `missing or invalid field: ${key}`);
}
return value;
}
export function optionalString(obj: Record<string, unknown>, key: string): string | undefined {
const value = obj[key];
if (value === undefined || value === null) return undefined;
if (typeof value !== "string") {
throw new FileLibError(400, "invalid_request", `invalid field: ${key}`);
}
return value;
}
+598
View File
@@ -0,0 +1,598 @@
/**
* 文件库树服务(Phase 1 服务层,Phase 2 路由直接调用)。
*
* 语义锚定:
* - D8 无权限 → 404 不泄露;越权 → 403(loadChain / requireAccess)
* - D11 creator 不可变 + 自动 MANAGE grant;独立权限开关语义在 permission.ts
* - D12 move = 本节点 MANAGE + 目标父 EDIT+,事务 + pg 咨询锁防并发成环
* - D14 命名规则(model.ts)+ 活跃兄弟唯一(DB 部分唯一索引兜底)
* - D15 删除只打标本节点;"任一祖先已删"即整支不可见
* - D17 breadcrumb 无 View 的祖先只给占位,不泄露名字
* - 树表示:parentId 权威;pathIds 为 id 编码的派生物化路径(name 不入路径,
* rename 不重写后代;move 用一次前缀重写维护)
*
* 网站管理员(D19)= silo org 的 OWNER/ADMIN(契约 C4 的入驻适配):仅 root 创建
* 与 force_adjust 特权,不隐式穿透内容权限 —— 本文件所有读路径对它同样走
* effectiveRole,没有 admin 旁路。
*/
import { randomUUID } from "node:crypto";
import path from "node:path";
import { Prisma } from "@prisma/client";
import type { PrismaClient, FileLibNode } from "@prisma/client";
import {
FileLibError,
nameKey,
normalizeNodeName,
type FileLibRole,
} from "./model.js";
import { checkAccess, effectiveRole } from "./permission.js";
import type { GroupResolver } from "./groupResolver.js";
import type { VersionStore } from "./versionStore.js";
import { FILE_LIB_AUDIT_ACTIONS, writeFileLibAudit } from "./audit.js";
export interface FileLibActor {
readonly userId: string;
/** silo org OWNER/ADMIN(契约 C4 适配)。仅 root 创建/force_adjust 用,不给读旁路。 */
readonly isWebsiteAdmin: boolean;
}
export interface TreeServiceDeps {
readonly prisma: PrismaClient;
readonly groupResolver: GroupResolver;
readonly versionStore: VersionStore;
/** 文件库归属的 silo org(ADR-0020 租户隔离,一切查询 scope 到它)。 */
readonly organizationId: string;
/** 项目 git 仓库的磁盘根目录;项目仓 = <storageRoot>/<nodeId>。 */
readonly storageRoot: string;
}
/** 权限判定实际需要的最小依赖(grantService 等兄弟模块复用)。 */
export type AccessDeps = Pick<TreeServiceDeps, "organizationId" | "groupResolver">;
export interface InitialGrant {
readonly principalType: "USER" | "GROUP";
readonly principalId: string;
readonly role: FileLibRole;
}
type Tx = Prisma.TransactionClient;
interface Chain {
readonly node: FileLibNode;
/** 根在前、直接父在后;不含 node 自身。 */
readonly ancestors: readonly FileLibNode[];
}
/* ---------------------------------------------------------------- 内部工具 */
/** pathIds = "/rootId/.../selfId";切出祖先 id(不含 self)。 */
function ancestorIdsOf(node: FileLibNode): string[] {
return node.pathIds.split("/").filter((seg) => seg !== "").slice(0, -1);
}
/** 取节点 + 祖先链(org scope);D15:自身或任一祖先已删 → 404。 */
async function loadVisibleChain(
tx: Tx,
organizationId: string,
nodeId: string,
): Promise<Chain> {
const node = await tx.fileLibNode.findFirst({ where: { id: nodeId, organizationId } });
if (node === null) throw new FileLibError(404, "node_not_found", "node not found");
const ancestorIds = ancestorIdsOf(node);
const ancestors = ancestorIds.length === 0
? []
: await tx.fileLibNode.findMany({ where: { organizationId, id: { in: ancestorIds } } });
if (node.deletedAt !== null || ancestors.some((a) => a.deletedAt !== null)) {
// D15:已删子树对外"不存在"(D8 不泄露)。
throw new FileLibError(404, "node_not_found", "node not found");
}
const byId = new Map(ancestors.map((a) => [a.id, a]));
const ordered = ancestorIds
.map((id) => byId.get(id))
.filter((a): a is FileLibNode => a !== undefined);
return { node, ancestors: ordered };
}
/** 数据获取层:把 chain、grants、groups、toggle 装配成纯 reducer 的输入。 */
async function resolveRole(
tx: Tx,
deps: AccessDeps,
actor: FileLibActor,
chain: Chain,
): Promise<FileLibRole | null> {
const chainIds = [...chain.ancestors.map((a) => a.id), chain.node.id];
const grants = await tx.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, revokedAt: null, nodeId: { in: chainIds } },
select: { nodeId: true, principalType: true, principalId: true, role: true, isCreatorGrant: true },
});
let independentPermissionsEnabled = false;
if (chain.node.kind === "PROJECT") {
const settings = await tx.fileLibProjectSettings.findUnique({
where: { nodeId: chain.node.id },
select: { independentPermissionsEnabled: true },
});
independentPermissionsEnabled = settings?.independentPermissionsEnabled ?? false;
}
const groupIds = await deps.groupResolver.resolveMemberGroupIds(actor.userId);
return effectiveRole({
nodeId: chain.node.id,
nodeKind: chain.node.kind,
ancestorIds: chain.ancestors.map((a) => a.id),
independentPermissionsEnabled,
userId: actor.userId,
groupIds,
grants,
});
}
/** D8 门禁:loadVisibleChain + resolveRole + checkAccess,失败抛 FileLibError。 */
async function requireAccess(
tx: Tx,
deps: AccessDeps,
actor: FileLibActor,
nodeId: string,
minRole: FileLibRole,
): Promise<Chain & { readonly role: FileLibRole }> {
const chain = await loadVisibleChain(tx, deps.organizationId, nodeId);
const role = await resolveRole(tx, deps, actor, chain);
const verdict = checkAccess(role, minRole);
if (!verdict.allowed) {
throw verdict.reason === "not_found"
? new FileLibError(404, "node_not_found", "node not found")
: new FileLibError(403, "forbidden", `requires ${minRole}`);
}
return { ...chain, role: verdict.role };
}
/**
* 兄弟模块(grantService 等)共用的 tx 内门禁:在调用方自己的事务里做
* 权限校验,校验与后续写同一根事务绳,避免 check-tx / write-tx 之间的竞态。
*/
export async function requireAccessInTx(
tx: Tx,
deps: AccessDeps,
actor: FileLibActor,
nodeId: string,
minRole: FileLibRole,
): Promise<Chain & { readonly role: FileLibRole }> {
return requireAccess(tx, deps, actor, nodeId, minRole);
}
/** P2002(活跃兄弟名部分唯一索引)→ 409。 */
function rethrowNameConflict(error: unknown, name: string): never {
if (error instanceof Prisma.PrismaClientKnownRequestError && error.code === "P2002") {
throw new FileLibError(409, "name_conflict", `an active sibling named "${name}" already exists`);
}
throw error;
}
function nodeAction(kind: FileLibNode["kind"], verb: "Create" | "Rename" | "Move" | "Delete"): string {
const table = kind === "PROJECT"
? { Create: FILE_LIB_AUDIT_ACTIONS.projectCreate, Rename: FILE_LIB_AUDIT_ACTIONS.projectRename, Move: FILE_LIB_AUDIT_ACTIONS.projectMove, Delete: FILE_LIB_AUDIT_ACTIONS.projectDelete }
: { Create: FILE_LIB_AUDIT_ACTIONS.folderCreate, Rename: FILE_LIB_AUDIT_ACTIONS.folderRename, Move: FILE_LIB_AUDIT_ACTIONS.folderMove, Delete: FILE_LIB_AUDIT_ACTIONS.folderDelete };
return table[verb];
}
function validateInitialGrants(actor: FileLibActor, grants: readonly InitialGrant[]): void {
const seen = new Set<string>();
for (const grant of grants) {
const key = `${grant.principalType}:${grant.principalId}`;
if (seen.has(key)) throw new FileLibError(400, "duplicate_principal", `duplicate grant principal: ${key}`);
seen.add(key);
if (grant.principalType === "USER" && grant.principalId === actor.userId) {
throw new FileLibError(400, "duplicate_principal", "creator already holds MANAGE via the creator grant");
}
// v1:不校验 group 存在性(C2 未提供批量校验口;给不存在 group 的授权天然无效,不危害)。
}
}
/* ---------------------------------------------------------------- 公共操作 */
export interface CreateNodeInput {
readonly parentId: string | null;
readonly kind: "FOLDER" | "PROJECT";
readonly name: string;
readonly description?: string | undefined;
readonly grants?: readonly InitialGrant[] | undefined;
}
/**
* 创建文件夹/项目。root 创建仅网站管理员(契约 2.1);非 root 需父节点 EDIT+。
* creator 自动 MANAGE(D11);项目走 provisioning 状态机:PROVISIONING → init → READY。
*/
export async function createNode(
deps: TreeServiceDeps,
actor: FileLibActor,
input: CreateNodeInput,
): Promise<FileLibNode> {
const name = normalizeNodeName(input.name);
const initialGrants = input.grants ?? [];
validateInitialGrants(actor, initialGrants);
const id = randomUUID();
let pathIds: string;
let storageDir: string | null = null;
const created = await deps.prisma.$transaction(async (tx) => {
if (input.parentId === null) {
if (!actor.isWebsiteAdmin) {
throw new FileLibError(403, "forbidden", "root creation requires website administrator");
}
pathIds = `/${id}`;
} else {
const parent = await requireAccess(tx, deps, actor, input.parentId, "EDIT");
if (parent.node.kind !== "FOLDER") {
throw new FileLibError(400, "invalid_parent", "projects cannot have children");
}
pathIds = `${parent.node.pathIds}/${id}`;
}
if (input.kind === "PROJECT") {
storageDir = path.join(deps.storageRoot, id);
}
let node: FileLibNode;
try {
node = await tx.fileLibNode.create({
data: {
id,
organizationId: deps.organizationId,
parentId: input.parentId,
kind: input.kind,
name,
nameLower: nameKey(name),
pathIds,
creatorId: actor.userId,
provisionStatus: input.kind === "PROJECT" ? "PROVISIONING" : "READY",
storageDir,
...(input.description !== undefined && input.description.trim() !== ""
? { description: input.description.trim() }
: {}),
},
});
} catch (error) {
rethrowNameConflict(error, name);
}
await tx.fileLibGrant.create({
data: {
organizationId: deps.organizationId,
nodeId: id,
principalType: "USER",
principalId: actor.userId,
role: "MANAGE",
isCreatorGrant: true,
createdByUserId: actor.userId,
},
});
for (const grant of initialGrants) {
await tx.fileLibGrant.create({
data: {
organizationId: deps.organizationId,
nodeId: id,
principalType: grant.principalType,
principalId: grant.principalId,
role: grant.role,
createdByUserId: actor.userId,
},
});
}
if (input.kind === "PROJECT") {
await tx.fileLibProjectSettings.create({
data: { nodeId: id, independentPermissionsEnabled: false },
});
}
await writeFileLibAudit(tx, {
action: nodeAction(input.kind, "Create"),
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: input.kind === "PROJECT" ? "project" : "folder",
objectId: id,
objectPath: pathIds,
detail: { name, parentId: input.parentId, initialGrants: initialGrants.length },
});
for (const grant of initialGrants) {
await writeFileLibAudit(tx, {
action: FILE_LIB_AUDIT_ACTIONS.permissionGrant,
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: "grant",
objectId: id,
objectPath: pathIds,
detail: { principalType: grant.principalType, principalId: grant.principalId, role: grant.role },
});
}
return node;
});
// provisioning 状态机(Metis 风险#1):DB 行已持久,init 失败 → FAILED 可重试/对账。
if (input.kind === "PROJECT" && storageDir !== null) {
try {
await deps.versionStore.init(storageDir);
return await deps.prisma.fileLibNode.update({
where: { id: created.id },
data: { provisionStatus: "READY" },
});
} catch (error) {
await deps.prisma.fileLibNode
.update({ where: { id: created.id }, data: { provisionStatus: "FAILED" } })
.catch(() => undefined);
throw new FileLibError(500, "provision_failed", `repository initialization failed: ${String(error)}`);
}
}
return created;
}
/** 重命名(需本节点 MANAGE,契约 8.2)。id 路径不含 name,后代无需重写。 */
export async function renameNode(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
rawName: string,
): Promise<FileLibNode> {
const name = normalizeNodeName(rawName);
return deps.prisma.$transaction(async (tx) => {
const { node } = await requireAccess(tx, deps, actor, nodeId, "MANAGE");
let updated: FileLibNode;
try {
updated = await tx.fileLibNode.update({
where: { id: node.id },
data: { name, nameLower: nameKey(name) },
});
} catch (error) {
rethrowNameConflict(error, name);
}
await writeFileLibAudit(tx, {
action: nodeAction(node.kind, "Rename"),
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: node.kind === "PROJECT" ? "project" : "folder",
objectId: node.id,
objectPath: node.pathIds,
detail: { from: node.name, to: name },
});
return updated;
});
}
/**
* 移动(D12):本节点 MANAGE + 目标父 EDIT+(移到 root 需网站管理员);
* 事务 + org 级咨询锁防并发成环;后代 pathIds 一次前缀重写。
*/
export async function moveNode(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
newParentId: string | null,
): Promise<FileLibNode> {
return deps.prisma.$transaction(async (tx) => {
await tx.$executeRaw`SELECT pg_advisory_xact_lock(hashtext(${"filelib:tree:" + deps.organizationId}))`;
const { node } = await requireAccess(tx, deps, actor, nodeId, "MANAGE");
if (node.parentId === newParentId) return node;
let newPathIds: string;
if (newParentId === null) {
if (!actor.isWebsiteAdmin) {
throw new FileLibError(403, "forbidden", "moving to root requires website administrator");
}
newPathIds = `/${node.id}`;
} else {
const parent = await requireAccess(tx, deps, actor, newParentId, "EDIT");
if (parent.node.kind !== "FOLDER") {
throw new FileLibError(400, "invalid_parent", "projects cannot have children");
}
if (parent.node.id === node.id || parent.node.pathIds.startsWith(`${node.pathIds}/`)) {
throw new FileLibError(400, "move_into_own_subtree", "cannot move a node into its own subtree");
}
newPathIds = `${parent.node.pathIds}/${node.id}`;
}
const oldPrefix = node.pathIds;
let updated: FileLibNode;
try {
updated = await tx.fileLibNode.update({
where: { id: node.id },
data: { parentId: newParentId, pathIds: newPathIds },
});
// 派生列维护:整支后代的前缀重写(id 编码,与 name 无关)。
await tx.$executeRaw`
UPDATE "FileLibNode"
SET "pathIds" = ${newPathIds} || substring("pathIds" from ${oldPrefix.length + 1}::int)
WHERE "organizationId" = ${deps.organizationId}
AND "pathIds" LIKE ${oldPrefix + "/%"}
`;
} catch (error) {
rethrowNameConflict(error, node.name);
}
await writeFileLibAudit(tx, {
action: nodeAction(node.kind, "Move"),
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: node.kind === "PROJECT" ? "project" : "folder",
objectId: node.id,
objectPath: newPathIds,
detail: { fromParentId: node.parentId, toParentId: newParentId },
});
return updated;
});
}
/** 软删除(D15):只打标本节点,后代靠"任一祖先已删"过滤;需 MANAGE。 */
export async function softDeleteNode(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
): Promise<void> {
await deps.prisma.$transaction(async (tx) => {
const { node } = await requireAccess(tx, deps, actor, nodeId, "MANAGE");
await tx.fileLibNode.update({ where: { id: node.id }, data: { deletedAt: new Date() } });
await writeFileLibAudit(tx, {
action: nodeAction(node.kind, "Delete"),
actorUserId: actor.userId,
organizationId: deps.organizationId,
objectType: node.kind === "PROJECT" ? "project" : "folder",
objectId: node.id,
objectPath: node.pathIds,
detail: { name: node.name },
});
});
}
/** 自查生效权限(契约 9.2 effective-permission)。D8:null 角色即不可见,404。 */
export async function getEffectiveRole(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
): Promise<FileLibRole | null> {
return deps.prisma.$transaction(async (tx) => {
const chain = await loadVisibleChain(tx, deps.organizationId, nodeId);
const role = await resolveRole(tx, deps, actor, chain);
if (role === null) throw new FileLibError(404, "node_not_found", "node not found");
return role;
});
}
export interface BreadcrumbEntry {
readonly depth: number;
/** D17:无 View 的祖先 id/name 都为 null(不泄露)。 */
readonly id: string | null;
readonly name: string | null;
readonly kind: "FOLDER" | "PROJECT";
}
/** D17 面包屑:需 self VIEW;链上每个节点单独算权限,无 View 只留占位。 */
export async function breadcrumb(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
): Promise<readonly BreadcrumbEntry[]> {
return deps.prisma.$transaction(async (tx) => {
const chain = await loadVisibleChain(tx, deps.organizationId, nodeId);
const selfRole = await resolveRole(tx, deps, actor, chain);
if (checkAccess(selfRole, "VIEW").allowed !== true) {
throw new FileLibError(404, "node_not_found", "node not found");
}
const groupIds = await deps.groupResolver.resolveMemberGroupIds(actor.userId);
const chainNodes = [...chain.ancestors, chain.node];
const chainIds = chainNodes.map((n) => n.id);
const allGrants = await tx.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, revokedAt: null, nodeId: { in: chainIds } },
select: { nodeId: true, principalType: true, principalId: true, role: true, isCreatorGrant: true },
});
const settings = chain.node.kind === "PROJECT"
? await tx.fileLibProjectSettings.findUnique({
where: { nodeId: chain.node.id },
select: { independentPermissionsEnabled: true },
})
: null;
return chainNodes.map((current, depth) => {
const role = effectiveRole({
nodeId: current.id,
nodeKind: current.kind,
ancestorIds: chainNodes.slice(0, depth).map((n) => n.id),
independentPermissionsEnabled:
current.id === chain.node.id ? settings?.independentPermissionsEnabled ?? false : false,
userId: actor.userId,
groupIds,
grants: allGrants,
});
const visible = role !== null;
return {
depth,
id: visible ? current.id : null,
name: visible ? current.name : null,
kind: current.kind,
};
});
});
}
export interface ChildNodeDto {
readonly id: string;
readonly parentId: string | null;
readonly kind: "FOLDER" | "PROJECT";
readonly name: string;
readonly role: FileLibRole;
readonly createdAt: Date;
readonly updatedAt: Date;
}
/** 列子节点(parentId=null 列 root);只返回调用者有 View 的(D8/P7)。 */
export async function listChildren(
deps: TreeServiceDeps,
actor: FileLibActor,
parentId: string | null,
): Promise<readonly ChildNodeDto[]> {
return deps.prisma.$transaction(async (tx) => {
let parentAncestorIds: string[] = [];
if (parentId !== null) {
const parent = await requireAccess(tx, deps, actor, parentId, "VIEW");
parentAncestorIds = [...parent.ancestors.map((a) => a.id), parent.node.id];
}
const children = await tx.fileLibNode.findMany({
where: { organizationId: deps.organizationId, parentId, deletedAt: null },
orderBy: [{ kind: "asc" }, { nameLower: "asc" }],
});
if (children.length === 0) return [];
// D13:一次请求只 resolve 一次组、拉一次 grant 集,批量计算,不做 per-child 往返。
const idsToFetch = [...parentAncestorIds, ...children.map((c) => c.id)];
const allGrants = await tx.fileLibGrant.findMany({
where: { organizationId: deps.organizationId, revokedAt: null, nodeId: { in: idsToFetch } },
select: { nodeId: true, principalType: true, principalId: true, role: true, isCreatorGrant: true },
});
const projectIds = children.filter((c) => c.kind === "PROJECT").map((c) => c.id);
const settingsRows = projectIds.length === 0
? []
: await tx.fileLibProjectSettings.findMany({
where: { nodeId: { in: projectIds } },
select: { nodeId: true, independentPermissionsEnabled: true },
});
const toggleByNode = new Map(settingsRows.map((s) => [s.nodeId, s.independentPermissionsEnabled]));
const groupIds = await deps.groupResolver.resolveMemberGroupIds(actor.userId);
const out: ChildNodeDto[] = [];
for (const child of children) {
const role = effectiveRole({
nodeId: child.id,
nodeKind: child.kind,
ancestorIds: parentAncestorIds,
independentPermissionsEnabled: toggleByNode.get(child.id) ?? false,
userId: actor.userId,
groupIds,
grants: allGrants,
});
if (role === null) continue;
out.push({
id: child.id,
parentId: child.parentId,
kind: child.kind,
name: child.name,
role,
createdAt: child.createdAt,
updatedAt: child.updatedAt,
});
}
return out;
});
}
/** 更新节点简介(需 EDIT+;不记审计,非权限敏感的内容字段)。 */
export async function updateNodeDescription(
deps: TreeServiceDeps,
actor: FileLibActor,
nodeId: string,
description: string | null,
): Promise<FileLibNode> {
return deps.prisma.$transaction(async (tx) => {
const { node } = await requireAccessInTx(tx, deps, actor, nodeId, "EDIT");
return tx.fileLibNode.update({
where: { id: node.id },
data: { description: description?.trim() || null },
});
});
}
+280
View File
@@ -0,0 +1,280 @@
/**
* VersionStore port(契约 C1)+ 开发用内存实现。
*
* 版本团队交付 npm 工具包后,用同一接口替换 createInMemoryVersionStore。
* 语义红线(计划"Mock 保真红线"):冲突走返回值(S1)、baseVersion=null 表新建(S2)、
* init 幂等(S7)、同 projectDir 写操作串行化(S4)、文件级版本(D16)。
*
* 持久化:传 persistPath 时把仓库快照落盘(JSON),重启后恢复 —— 纯粹为开发期
* demo 稳定,不改变任何语义;生产由真包替换,此文件不参与。
*/
import { mkdirSync, readFileSync, renameSync, writeFileSync } from "node:fs";
import path from "node:path";
import { FileLibError } from "./model.js";
export type VersionId = string;
export interface CommitRequest {
/** 编辑起始版本;null 表示新建文件(已存在则 conflict,S2)。 */
readonly baseVersion: VersionId | null;
readonly content: string | Buffer;
readonly message?: string | undefined;
readonly author?: string | undefined;
}
export type CommitResult =
| { readonly status: "ok"; readonly version: VersionId }
| { readonly status: "conflict"; readonly currentVersion: VersionId };
export interface VersionInfo {
readonly version: VersionId;
readonly message: string;
readonly author: string | undefined;
readonly committedAt: string;
}
export interface FileEntry {
readonly path: string;
readonly size: number;
}
export interface VersionStore {
init(projectDir: string): Promise<void>;
list(projectDir: string, prefix?: string): Promise<FileEntry[]>;
head(projectDir: string, filePath: string): Promise<VersionId>;
read(projectDir: string, filePath: string, at?: VersionId): Promise<Buffer>;
commit(projectDir: string, filePath: string, req: CommitRequest): Promise<CommitResult>;
remove(projectDir: string, filePath: string, baseVersion: VersionId): Promise<CommitResult>;
diff(projectDir: string, filePath: string, from: VersionId, to: VersionId): Promise<string>;
history(projectDir: string, filePath: string, limit?: number): Promise<VersionInfo[]>;
}
interface StoredVersion {
readonly version: VersionId;
readonly content: Buffer;
readonly message: string;
readonly author: string | undefined;
readonly committedAt: string;
readonly deleted: boolean;
}
interface Repo {
/** 每文件一条版本链(D16:版本是文件级的,互不干扰)。 */
readonly files: Map<string, StoredVersion[]>;
counter: number;
}
/** S4:同 projectDir 的写操作经 per-repo promise 链串行化。 */
function createKeySerializer(): <T>(key: string, fn: () => Promise<T>) => Promise<T> {
const tails = new Map<string, Promise<unknown>>();
return <T>(key: string, fn: () => Promise<T>): Promise<T> => {
const prev = tails.get(key) ?? Promise.resolve();
const next = prev.then(fn, fn);
tails.set(key, next.catch(() => undefined));
return next;
};
}
function toBuffer(content: string | Buffer): Buffer {
return typeof content === "string" ? Buffer.from(content, "utf8") : content;
}
/** 极简 unified-diff(mock 保真够用;真包的 diff 以版本团队为准)。 */
function naiveDiff(fromText: string, toText: string): string {
const a = fromText.split("\n");
const b = toText.split("\n");
const out: string[] = ["--- a", "+++ b"];
const max = Math.max(a.length, b.length);
for (let i = 0; i < max; i += 1) {
const al = a[i];
const bl = b[i];
if (al === bl) {
if (al !== undefined) out.push(` ${al}`);
} else {
if (al !== undefined) out.push(`-${al}`);
if (bl !== undefined) out.push(`+${bl}`);
}
}
return out.join("\n");
}
export function createInMemoryVersionStore(persistPath?: string): VersionStore {
const repos = new Map<string, Repo>();
const serialize = createKeySerializer();
/* ---------------- 开发期快照持久化(语义不变,仅防重启丢失) ---------------- */
interface PersistedVersion extends Omit<StoredVersion, "content"> {
content: string; // base64
}
function loadPersisted(): void {
if (persistPath === undefined) return;
try {
const raw = JSON.parse(readFileSync(persistPath, "utf8")) as {
repos: Record<string, { counter: number; files: Record<string, PersistedVersion[]> }>;
};
for (const [dir, repo] of Object.entries(raw.repos)) {
const files = new Map<string, StoredVersion[]>();
for (const [filePath, versions] of Object.entries(repo.files)) {
files.set(filePath, versions.map((v) => ({ ...v, content: Buffer.from(v.content, "base64") })));
}
repos.set(dir, { files, counter: repo.counter });
}
} catch { /* 无快照或损坏 → 空库起步(开发语义) */ }
}
function savePersisted(): void {
if (persistPath === undefined) return;
const out: Record<string, { counter: number; files: Record<string, PersistedVersion[]> }> = {};
for (const [dir, repo] of repos) {
const files: Record<string, PersistedVersion[]> = {};
for (const [filePath, versions] of repo.files) {
files[filePath] = versions.map((v) => ({ ...v, content: v.content.toString("base64") }));
}
out[dir] = { counter: repo.counter, files };
}
try {
mkdirSync(path.dirname(persistPath), { recursive: true });
const tmp = `${persistPath}.tmp`;
writeFileSync(tmp, JSON.stringify({ repos: out }), "utf8");
renameSync(tmp, persistPath);
} catch { /* 快照失败不影响开发使用 */ }
}
loadPersisted();
function requireRepo(projectDir: string): Repo {
const repo = repos.get(projectDir);
if (repo === undefined) {
throw new FileLibError(404, "repo_not_found", `repository not initialized: ${projectDir}`);
}
return repo;
}
function liveVersion(repo: Repo, filePath: string): StoredVersion {
const chain = repo.files.get(filePath);
const latest = chain?.[chain.length - 1];
if (chain === undefined || latest === undefined || latest.deleted) {
throw new FileLibError(404, "file_not_found", `file not found: ${filePath}`);
}
return latest;
}
function findVersion(repo: Repo, filePath: string, version: VersionId): StoredVersion {
const found = repo.files.get(filePath)?.find((v) => v.version === version);
if (found === undefined) {
throw new FileLibError(404, "version_not_found", `version not found: ${filePath}@${version}`);
}
return found;
}
return {
async init(projectDir) {
await serialize(projectDir, async () => {
// S7:幂等,重复调用不报错、不重建。
const created = repos.get(projectDir) === undefined;
repos.set(projectDir, repos.get(projectDir) ?? { files: new Map(), counter: 0 });
if (created) savePersisted();
});
},
async list(projectDir, prefix) {
const repo = requireRepo(projectDir);
const out: FileEntry[] = [];
for (const [path, chain] of repo.files) {
const latest = chain[chain.length - 1];
if (latest === undefined || latest.deleted) continue;
if (prefix !== undefined && !path.startsWith(prefix)) continue;
out.push({ path, size: latest.content.byteLength });
}
return out.sort((a, b) => a.path.localeCompare(b.path));
},
async head(projectDir, filePath) {
return liveVersion(requireRepo(projectDir), filePath).version;
},
async read(projectDir, filePath, at) {
const repo = requireRepo(projectDir);
if (at !== undefined) return findVersion(repo, filePath, at).content;
return liveVersion(repo, filePath).content;
},
async commit(projectDir, filePath, req) {
return serialize(projectDir, async (): Promise<CommitResult> => {
const repo = requireRepo(projectDir);
const chain = repo.files.get(filePath) ?? [];
const latest = chain[chain.length - 1];
const currentVersion = latest !== undefined && !latest.deleted ? latest.version : null;
// S2:新建(baseVersion null)要求文件当前不存在;否则要求 baseVersion 精确等于当前版本(S1)。
if (req.baseVersion === null) {
if (currentVersion !== null) return { status: "conflict", currentVersion };
} else if (req.baseVersion !== currentVersion) {
return {
status: "conflict",
currentVersion: currentVersion ?? req.baseVersion,
};
}
repo.counter += 1;
const version = `v${repo.counter}`;
chain.push({
version,
content: toBuffer(req.content),
message: req.message ?? `commit ${version}`,
author: req.author,
committedAt: new Date().toISOString(),
deleted: false,
});
repo.files.set(filePath, chain);
savePersisted();
return { status: "ok", version };
});
},
async remove(projectDir, filePath, baseVersion) {
return serialize(projectDir, async (): Promise<CommitResult> => {
const repo = requireRepo(projectDir);
const chain = repo.files.get(filePath) ?? [];
const latest = chain[chain.length - 1];
const currentVersion = latest !== undefined && !latest.deleted ? latest.version : null;
if (currentVersion === null) {
throw new FileLibError(404, "file_not_found", `file not found: ${filePath}`);
}
if (baseVersion !== currentVersion) return { status: "conflict", currentVersion };
repo.counter += 1;
const version = `v${repo.counter}`;
chain.push({
version,
content: Buffer.alloc(0),
message: `remove ${filePath}`,
author: undefined,
committedAt: new Date().toISOString(),
deleted: true,
});
repo.files.set(filePath, chain);
savePersisted();
return { status: "ok", version };
});
},
async diff(projectDir, filePath, from, to) {
const repo = requireRepo(projectDir);
const a = findVersion(repo, filePath, from);
const b = findVersion(repo, filePath, to);
return naiveDiff(a.content.toString("utf8"), b.content.toString("utf8"));
},
async history(projectDir, filePath, limit) {
const repo = requireRepo(projectDir);
const chain = repo.files.get(filePath) ?? [];
const infos: VersionInfo[] = chain.map((v) => ({
version: v.version,
message: v.message,
author: v.author,
committedAt: v.committedAt,
}));
const ordered = infos.reverse();
return limit !== undefined ? ordered.slice(0, limit) : ordered;
},
};
}
+227
View File
@@ -0,0 +1,227 @@
/**
* 管理员后台「用户管理」「Group 管理」面板(复用 hub 已有 org 管理 API)。
*
* 用户管理 = org 成员(/api/org/:orgSlug/members);
* Group 管理 = Team(当前 Group 的过渡实现,/api/org/:orgSlug/teams),
* 真 Group 系统落地后此面板改接新 API 即可,文件库授权侧不动。
*/
function apiBase(orgSlug: string): string {
return `/api/org/${encodeURIComponent(orgSlug)}`;
}
/* ---------------------------------------------------------------- 用户管理 */
export function renderUsersPanel(orgSlug: string): string {
return `
<div id="users-root" style="max-width:880px">
<div class="panel" style="margin-bottom:14px">
<div class="section-title">添加成员</div>
<div class="inline-form">
<input id="u-openid" class="input" placeholder="用户 openId(飞书 ou_ 开头)" style="flex:2"/>
<input id="u-name" class="input" placeholder="显示名(可选)" style="flex:1"/>
<select id="u-role" class="select" style="width:130px">
<option value="MEMBER">普通老师</option>
<option value="ADMIN">管理员</option>
<option value="OWNER">所有者</option>
</select>
<button id="u-add" class="btn btn-primary">添加</button>
</div>
</div>
<div class="panel">
<div class="section-title">成员列表</div>
<table class="list">
<thead><tr><th>成员</th><th>userId</th><th>角色</th><th></th></tr></thead>
<tbody id="u-tbody"></tbody>
</table>
</div>
</div>
<script>
(function () {
const BASE = "${apiBase(orgSlug)}";
const tbody = document.getElementById("u-tbody");
const esc = (s) => String(s).replace(/&/g,"&amp;").replace(/</g,"&lt;").replace(/>/g,"&gt;").replace(/"/g,"&quot;");
const ROLE_LABEL = { OWNER: "所有者", ADMIN: "管理员", MEMBER: "普通老师" };
async function req(path, opts = {}) {
const res = await fetch(BASE + path, {
credentials: "same-origin",
headers: opts.body ? { "Content-Type": "application/json" } : undefined,
method: opts.method ?? "GET",
body: opts.body ? JSON.stringify(opts.body) : undefined,
});
if (res.status === 401) { location.href = "/database/admin"; throw new Error("unauthenticated"); }
const text = await res.text();
const data = text ? JSON.parse(text) : null;
if (!res.ok) throw new Error((data && data.error && data.error.message) || res.statusText);
return data;
}
async function load() {
const { members } = await req("/members");
tbody.innerHTML = members.length === 0
? '<tr><td colspan="4" class="quiet" style="text-align:center;padding:18px">暂无成员</td></tr>'
: members.map((m) =>
"<tr>" +
"<td>" + esc(m.displayName || m.userId) + "</td>" +
'<td class="file-meta">' + esc(m.userId) + "</td>" +
'<td><select class="select" style="width:110px;padding:3px 8px;font-size:12px" data-user="' + esc(m.userId) + '">' +
["OWNER","ADMIN","MEMBER"].map((r) =>
'<option value="' + r + '"' + (m.role === r ? " selected" : "") + ">" + ROLE_LABEL[r] + "</option>").join("") +
"</select></td>" +
'<td style="text-align:right"><button class="link-danger" data-revoke="' + esc(m.userId) + '">移除</button></td>' +
"</tr>").join("");
tbody.querySelectorAll("select[data-user]").forEach((sel) => {
sel.onchange = async () => {
try { await req("/members/" + encodeURIComponent(sel.dataset.user), { method: "PATCH", body: { role: sel.value } }); }
catch (e) { alert(e.message); load(); }
};
});
tbody.querySelectorAll("button[data-revoke]").forEach((btn) => {
btn.onclick = async () => {
if (!confirm("移除该成员?")) return;
try { await req("/members/" + encodeURIComponent(btn.dataset.revoke) + "/revoke", { method: "POST" }); load(); }
catch (e) { alert(e.message); }
};
});
}
document.getElementById("u-add").onclick = async () => {
const openId = document.getElementById("u-openid").value.trim();
if (!openId) return alert("请填写用户 openId");
const displayName = document.getElementById("u-name").value.trim();
try {
await req("/members", { method: "POST", body: {
feishuOpenId: openId,
role: document.getElementById("u-role").value,
...(displayName ? { displayName } : {}),
}});
document.getElementById("u-openid").value = "";
document.getElementById("u-name").value = "";
load();
} catch (e) { alert(e.message); }
};
load().catch((e) => { tbody.innerHTML = '<tr><td colspan="4" style="color:var(--danger);padding:12px">' + esc(e.message) + "</td></tr>"; });
})();
</script>`;
}
/* ---------------------------------------------------------------- Group 管理 */
export function renderGroupsPanel(orgSlug: string): string {
return `
<div id="groups-root" style="display:flex;gap:14px;align-items:flex-start">
<div style="width:340px;flex-shrink:0">
<div class="panel" style="margin-bottom:14px">
<div class="section-title">新建 Group</div>
<div class="form-row"><label class="form-label">标识(slug)</label><input id="g-slug" class="input" placeholder="physics-dept"/></div>
<div class="form-row"><label class="form-label">名称</label><input id="g-name" class="input" placeholder="物理教研组"/></div>
<div class="form-row"><label class="form-label">描述(可选)</label><input id="g-desc" class="input" placeholder="一句话说明"/></div>
<div style="text-align:right"><button id="g-create" class="btn btn-primary">创建</button></div>
</div>
<div class="panel">
<div class="section-title">Group 列表</div>
<div id="g-list"></div>
</div>
</div>
<div class="panel" style="flex:1;min-height:200px">
<div id="g-detail" class="quiet" style="padding:18px;text-align:center">从左侧选择一个 Group 查看成员</div>
</div>
</div>
<script>
(function () {
const BASE = "${apiBase(orgSlug)}";
const listEl = document.getElementById("g-list");
const detailEl = document.getElementById("g-detail");
const esc = (s) => String(s).replace(/&/g,"&amp;").replace(/</g,"&lt;").replace(/>/g,"&gt;").replace(/"/g,"&quot;");
let selected = null;
async function req(path, opts = {}) {
const res = await fetch(BASE + path, {
credentials: "same-origin",
headers: opts.body ? { "Content-Type": "application/json" } : undefined,
method: opts.method ?? "GET",
body: opts.body ? JSON.stringify(opts.body) : undefined,
});
if (res.status === 401) { location.href = "/database/admin"; throw new Error("unauthenticated"); }
const text = await res.text();
const data = text ? JSON.parse(text) : null;
if (!res.ok) throw new Error((data && data.error && data.error.message) || res.statusText);
return data;
}
async function loadList() {
const { teams } = await req("/teams");
listEl.innerHTML = teams.length === 0
? '<div class="quiet" style="text-align:center;padding:12px">暂无 Group</div>'
: teams.map((t) =>
'<div class="g-team" data-id="' + esc(t.id) + '" data-name="' + esc(t.name) + '" style="display:flex;align-items:center;gap:8px;padding:8px 6px;border-radius:8px;cursor:pointer">' +
'<span style="flex:1"><b>' + esc(t.name) + '</b> <span class="file-meta">' + esc(t.slug) + "</span></span>" +
'<button class="link-danger" data-archive="' + esc(t.id) + '" style="font-size:11px">归档</button>' +
"</div>").join("");
listEl.querySelectorAll(".g-team").forEach((el) => {
el.onclick = (e) => {
if (e.target.closest("button")) return;
selected = { id: el.dataset.id, name: el.dataset.name };
listEl.querySelectorAll(".g-team").forEach((x) => x.style.background = "");
el.style.background = "var(--selected)";
loadMembers();
};
});
listEl.querySelectorAll("button[data-archive]").forEach((btn) => {
btn.onclick = async () => {
if (!confirm("归档该 Group?其成员授权将失效。")) return;
try { await req("/teams/" + encodeURIComponent(btn.dataset.archive) + "/archive", { method: "POST" }); selected = null; detailEl.innerHTML = '<div class="quiet" style="padding:18px;text-align:center">从左侧选择一个 Group 查看成员</div>'; loadList(); }
catch (e) { alert(e.message); }
};
});
}
async function loadMembers() {
if (!selected) return;
detailEl.innerHTML = '<div class="quiet" style="padding:12px;text-align:center">加载中…</div>';
const { members } = await req("/teams/" + encodeURIComponent(selected.id) + "/members");
detailEl.innerHTML =
'<div class="section-title">' + esc(selected.name) + " · 成员(" + members.length + ")</div>" +
'<table class="list"><tbody>' +
(members.length === 0
? '<tr><td class="quiet" style="text-align:center;padding:14px">暂无成员</td></tr>'
: members.map((m) =>
"<tr><td>" + esc(m.displayName || m.userId) + '</td><td class="file-meta">' + esc(m.userId) + "</td>" +
'<td style="text-align:right"><button class="link-danger" data-revoke="' + esc(m.userId) + '">移除</button></td></tr>').join("")) +
"</tbody></table>" +
'<div class="divider"></div>' +
'<div class="section-title">添加成员</div>' +
'<div class="inline-form">' +
'<input id="g-add-openid" class="input" placeholder="用户 openId 或 userId"/>' +
'<button id="g-add" class="btn btn-primary">添加</button>' +
"</div>";
detailEl.querySelectorAll("button[data-revoke]").forEach((btn) => {
btn.onclick = async () => {
try { await req("/teams/" + encodeURIComponent(selected.id) + "/members/" + encodeURIComponent(btn.dataset.revoke) + "/revoke", { method: "POST" }); loadMembers(); }
catch (e) { alert(e.message); }
};
});
detailEl.querySelector("#g-add").onclick = async () => {
const v = detailEl.querySelector("#g-add-openid").value.trim();
if (!v) return alert("请填写用户 id");
try {
await req("/teams/" + encodeURIComponent(selected.id) + "/members", {
method: "POST",
body: v.startsWith("ou_") ? { feishuOpenId: v } : { userId: v },
});
loadMembers();
} catch (e) { alert(e.message); }
};
}
document.getElementById("g-create").onclick = async () => {
const slug = document.getElementById("g-slug").value.trim();
const name = document.getElementById("g-name").value.trim();
const description = document.getElementById("g-desc").value.trim();
if (!slug || !name) return alert("slug 和名称必填");
try {
await req("/teams", { method: "POST", body: { slug, name, ...(description ? { description } : {}) } });
document.getElementById("g-slug").value = "";
document.getElementById("g-name").value = "";
document.getElementById("g-desc").value = "";
loadList();
} catch (e) { alert(e.message); }
};
loadList().catch((e) => { listEl.innerHTML = '<div style="color:var(--danger);padding:12px">' + esc(e.message) + "</div>"; });
})();
</script>`;
}
+245 -134
View File
@@ -15,7 +15,20 @@
*/ */
import type { FastifyInstance } from "fastify"; import type { FastifyInstance } from "fastify";
import type { PrismaClient } from "@prisma/client"; import type { PrismaClient } from "@prisma/client";
import path from "node:path";
import { SESSION_COOKIE_NAME, signSession, verifySession } from "../../admin/auth/session.js"; import { SESSION_COOKIE_NAME, signSession, verifySession } from "../../admin/auth/session.js";
import { registerFileLibRoutes } from "./filelibRoutes.js";
import { registerFileRoutes } from "./fileRoutes.js";
import { registerTeacherApp } from "./teacherApp.js";
import { renderLibraryBrowser } from "./libraryBrowser.js";
import { renderGroupsPanel, renderUsersPanel } from "./adminPanels.js";
import { createInMemoryVersionStore } from "../filelib/versionStore.js";
import { createTeamGroupResolver } from "../filelib/groupResolver.js";
import { createHttpGroupResolver } from "../filelib/groupResolverHttp.js";
import { createManifestStubAdapter } from "../filelib/exportService.js";
import { FILE_LIB_AUDIT_ACTIONS } from "../filelib/audit.js";
import { UI_HEAD_FONTS, UI_THEME_CSS } from "./uiTheme.js";
import type { FileLibRouteDeps } from "../filelib/routeShared.js";
export interface DatabaseRouteConfig { export interface DatabaseRouteConfig {
readonly prisma: PrismaClient; readonly prisma: PrismaClient;
@@ -31,6 +44,9 @@ export async function registerDatabaseRoutes(
app: FastifyInstance, app: FastifyInstance,
config: DatabaseRouteConfig, config: DatabaseRouteConfig,
): Promise<void> { ): Promise<void> {
// 文件库依赖在下方装配;概览页统计在请求时经此引用读取(请求一定晚于装配完成)。
let filelibDepsForStats: FileLibRouteDeps | null = null;
app.get("/database/admin", async (request, reply) => { app.get("/database/admin", async (request, reply) => {
// Already signed in → straight to the dashboard. // Already signed in → straight to the dashboard.
if ((await resolveUser(request.cookies[SESSION_COOKIE_NAME], config)) !== null) { if ((await resolveUser(request.cookies[SESSION_COOKIE_NAME], config)) !== null) {
@@ -42,7 +58,8 @@ export async function registerDatabaseRoutes(
app.get("/database/dashboard", async (request, reply) => { app.get("/database/dashboard", async (request, reply) => {
const user = await resolveUser(request.cookies[SESSION_COOKIE_NAME], config); const user = await resolveUser(request.cookies[SESSION_COOKIE_NAME], config);
if (user === null) return reply.redirect("/database/admin"); if (user === null) return reply.redirect("/database/admin");
return reply.type("text/html").send(renderDashboard(user.displayName)); const stats = await loadDashboardStats(config.prisma, filelibDepsForStats);
return reply.type("text/html").send(renderDashboard(user.displayName, stats, config.siloOrganizationSlug));
}); });
// DEV ONLY bypass — self-contained here, registered only when the flag is on // DEV ONLY bypass — self-contained here, registered only when the flag is on
@@ -96,9 +113,116 @@ export async function registerDatabaseRoutes(
}); });
} }
// Add more /database/* routes here. Guard data routes with requireSession / // 文件库(独立模块,《文件库-接口契约.md》):API + 浏览页 + 老师端 /app。
// requireOrgRole (../../admin/auth/guards.js) and scope every query to the // 依赖装配:VersionStore 当前为内存+快照实现(版本团队 npm 包到位后替换);
// caller's org (ADR-0020). Access the DB via config.prisma. // GroupResolver 默认读 hub Team,HUB_GROUP_SERVICE_URL 配置后切 HTTP(C2);
// 导出适配器当前为 manifest stub(OPEN-6,真导出工具到位后替换)。
const siloOrg = await config.prisma.organization.findUnique({
where: { slug: config.siloOrganizationSlug },
select: { id: true },
});
if (siloOrg === null) {
app.log.warn({ slug: config.siloOrganizationSlug }, "filelib: silo organization not found, routes not registered");
return;
}
const storageRoot = process.env["HUB_FILELIB_STORAGE_ROOT"] ?? path.resolve(".filelib-repos");
const versionStore = createInMemoryVersionStore(path.join(storageRoot, ".version-store.json"));
const groupServiceUrl = process.env["HUB_GROUP_SERVICE_URL"];
const filelibDeps: FileLibRouteDeps = {
prisma: config.prisma,
sessionSecret: config.sessionSecret,
organizationId: siloOrg.id,
storageRoot,
groupResolver: groupServiceUrl === undefined || groupServiceUrl.trim() === ""
? createTeamGroupResolver(config.prisma, siloOrg.id)
: createHttpGroupResolver({ baseUrl: groupServiceUrl }),
versionStore,
exportAdapters: [createManifestStubAdapter(versionStore)],
};
await registerFileLibRoutes(app, filelibDeps);
await registerFileRoutes(app, filelibDeps);
await registerTeacherApp(app, {
prisma: config.prisma,
sessionSecret: config.sessionSecret,
siloOrganizationSlug: config.siloOrganizationSlug,
allowDevLoginBypass: config.allowDevLoginBypass,
});
// 独立文件库页已并入后台「文件库」tab(/database/dashboard#library),旧地址跳转保留兼容。
app.get("/database/library", async (_request, reply) =>
reply.redirect("/database/dashboard#library"),
);
filelibDepsForStats = filelibDeps;
}
/* ------------------------------------------------------------ 概览页统计 */
interface DashboardStats {
readonly folders: number;
readonly projects: number;
readonly files: number;
readonly grants: number;
readonly recent: ReadonlyArray<{
readonly action: string;
readonly actor: string;
readonly label: string;
readonly when: Date;
}>;
}
/** 概览页统计:org 范围内的文件夹/项目/授权(DB)+ 文件(版本库)+ 最近活动(AuditEntry)。 */
async function loadDashboardStats(
prisma: PrismaClient,
deps: FileLibRouteDeps | null,
): Promise<DashboardStats | null> {
if (deps === null) return null;
const organizationId = deps.organizationId;
const [folders, projects, grants] = await Promise.all([
prisma.fileLibNode.count({ where: { organizationId, kind: "FOLDER", deletedAt: null } }),
prisma.fileLibNode.count({ where: { organizationId, kind: "PROJECT", deletedAt: null } }),
prisma.fileLibGrant.count({ where: { organizationId, revokedAt: null } }),
]);
// 文件计数:遍历 READY 项目问版本库(demo 规模;真版本包到位后应换成存储侧统计)
const readyProjects = await prisma.fileLibNode.findMany({
where: {
organizationId, kind: "PROJECT", deletedAt: null,
provisionStatus: "READY", storageDir: { not: null },
},
select: { storageDir: true },
});
let files = 0;
for (const project of readyProjects) {
if (project.storageDir === null) continue;
try {
files += (await deps.versionStore.list(project.storageDir)).length;
} catch { /* repo 缺失(如重启未恢复)不计 */ }
}
const entries = await prisma.auditEntry.findMany({
where: { organizationId, action: { in: Object.values(FILE_LIB_AUDIT_ACTIONS) } },
orderBy: { createdAt: "desc" },
take: 8,
});
const actorIds = [...new Set(entries.map((e) => e.actorUserId).filter((x): x is string => x !== null))];
const users = actorIds.length === 0
? []
: await prisma.user.findMany({ where: { id: { in: actorIds } }, select: { id: true, displayName: true } });
const nameById = new Map(users.map((u) => [u.id, u.displayName]));
const recent = entries.map((entry) => {
const meta = (entry.metadata ?? {}) as Record<string, unknown>;
const label =
(typeof meta["name"] === "string" ? meta["name"] : undefined) ??
(typeof meta["to"] === "string" ? meta["to"] : undefined) ??
(typeof meta["path"] === "string" ? meta["path"] : undefined) ??
(typeof meta["objectId"] === "string" ? meta["objectId"].slice(0, 8) : "");
return {
action: entry.action,
actor: nameById.get(entry.actorUserId ?? "") ?? entry.actorUserId ?? "unknown",
label,
when: entry.createdAt,
};
});
return { folders, projects, files, grants, recent };
} }
/** Verify the session cookie and load the user, or null if not signed in. */ /** Verify the session cookie and load the user, or null if not signed in. */
@@ -116,183 +240,170 @@ async function resolveUser(
return user; return user;
} }
/** /** 管理后台共享 head(全局 UI 主题,与老师端 /app 同源)。 */
* Shared document head: Tailwind CDN + a small design system (fonts, keyframes
* for the aurora background, fade-in, shimmer). Both pages import it so the
* look stays consistent.
*/
function pageHead(title: string): string { function pageHead(title: string): string {
return `<head> return `<head>
<meta charset="utf-8"/> <meta charset="utf-8"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/> <meta name="viewport" content="width=device-width, initial-scale=1"/>
<title>${title}</title> <title>${title}</title>
<script src="https://cdn.tailwindcss.com"></script> ${UI_HEAD_FONTS}
<link rel="preconnect" href="https://fonts.googleapis.com"/> <style>${UI_THEME_CSS}</style>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap" rel="stylesheet"/>
<style>
:root { font-family: 'Inter', system-ui, sans-serif; }
@keyframes aurora {
0% { transform: translate(0,0) scale(1); }
33% { transform: translate(6%, -8%) scale(1.15); }
66% { transform: translate(-8%, 6%) scale(0.9); }
100% { transform: translate(0,0) scale(1); }
}
@keyframes rise {
from { opacity: 0; transform: translateY(16px); }
to { opacity: 1; transform: translateY(0); }
}
@keyframes shimmer {
0% { background-position: -200% 0; }
100% { background-position: 200% 0; }
}
.aurora { filter: blur(80px); animation: aurora 18s ease-in-out infinite; }
.rise { animation: rise .7s cubic-bezier(.16,1,.3,1) both; }
.rise-2 { animation: rise .7s cubic-bezier(.16,1,.3,1) .1s both; }
.rise-3 { animation: rise .7s cubic-bezier(.16,1,.3,1) .2s both; }
.grad-text {
background: linear-gradient(120deg,#7c3aed,#0891b2,#4f46e5);
background-size: 200% auto;
-webkit-background-clip: text; background-clip: text; color: transparent;
animation: shimmer 6s linear infinite;
}
.glass { background: rgba(255,255,255,.7); backdrop-filter: blur(16px); -webkit-backdrop-filter: blur(16px); }
.glow-btn { box-shadow: 0 12px 32px -10px rgba(124,58,237,.45); }
</style>
</head>`; </head>`;
} }
/** The animated aurora background blobs, shared by both pages (soft pastels on light). */
const AURORA = `
<div class="pointer-events-none fixed inset-0 overflow-hidden">
<div class="aurora absolute -left-32 -top-32 h-96 w-96 rounded-full bg-violet-300/50"></div>
<div class="aurora absolute right-0 top-1/4 h-96 w-96 rounded-full bg-cyan-300/40" style="animation-delay:-6s"></div>
<div class="aurora absolute bottom-0 left-1/3 h-96 w-96 rounded-full bg-indigo-300/40" style="animation-delay:-12s"></div>
</div>`;
function renderLoginPage(config: DatabaseRouteConfig): string { function renderLoginPage(config: DatabaseRouteConfig): string {
const feishuHref = `/auth/feishu/${encodeURIComponent(config.siloOrganizationSlug)}`; const feishuHref = `/auth/feishu/${encodeURIComponent(config.siloOrganizationSlug)}`;
const devButton = config.allowDevLoginBypass const devButton = config.allowDevLoginBypass
? ` ? `<div style="display:flex;align-items:center;gap:10px;margin:22px 0;color:var(--text-3);font-size:11px">
<div class="relative my-6 rise-3"> <span style="flex:1;border-top:1px solid var(--border-soft)"></span>开发模式
<div class="absolute inset-0 flex items-center"><div class="w-full border-t border-slate-200"></div></div> <span style="flex:1;border-top:1px solid var(--border-soft)"></span>
<div class="relative flex justify-center"><span class="bg-white/70 px-3 text-[11px] font-medium uppercase tracking-[0.2em] text-slate-400">开发模式</span></div>
</div> </div>
<a href="/database/dev-login" <a href="/database/dev-login" class="btn" style="width:100%;justify-content:center">⚡ 一键登录管理员</a>
class="rise-3 group flex w-full items-center justify-center gap-2 rounded-xl border border-amber-300 bg-amber-50 px-4 py-3 text-sm font-semibold text-amber-700 transition hover:border-amber-400 hover:bg-amber-100"> <p style="margin:10px 0 0;text-align:center;font-size:11px;color:var(--text-3)">仅开发环境可见 · 跳过飞书 OAuth</p>`
<span>⚡</span> 一键登录管理员
</a>
<p class="rise-3 mt-2 text-center text-xs text-slate-400">仅开发环境可见 · 跳过飞书 OAuth</p>`
: ""; : "";
return `<!doctype html> return `<!doctype html>
<html lang="zh-CN"> <html lang="zh-CN">
${pageHead("Database Admin · 登录")} ${pageHead("Database Admin · 登录")}
<body class="relative min-h-screen overflow-hidden bg-gradient-to-br from-slate-50 via-white to-indigo-50 text-slate-800 flex items-center justify-center p-4"> <body>
${AURORA} <div style="min-height:100vh;display:flex;align-items:center;justify-content:center;padding:24px">
<main class="rise glass relative w-full max-w-sm rounded-3xl border border-white/80 p-8 shadow-2xl shadow-indigo-200/50"> <div style="width:100%;max-width:380px;background:var(--panel);border:1px solid var(--border-soft);border-radius:16px;padding:40px 36px;box-shadow:var(--shadow-pop)">
<div class="mb-7 text-center"> <div style="font-size:26px;font-weight:600;text-align:center">Database Admin</div>
<div class="mx-auto mb-5 flex h-14 w-14 items-center justify-center rounded-2xl bg-gradient-to-br from-violet-500 to-cyan-400 text-2xl font-bold text-white glow-btn">D</div> <p style="margin:10px 0 30px;text-align:center;font-size:13px;color:var(--text-3)">使用飞书登录以管理数据库</p>
<h1 class="text-2xl font-bold tracking-tight grad-text">Database Admin</h1> <a href="${feishuHref}" class="btn btn-primary" style="width:100%;justify-content:center;padding:11px 16px;font-size:14px">使用飞书登录</a>
<p class="mt-2 text-sm text-slate-500">使用飞书登录以管理数据库</p>
</div>
<a href="${feishuHref}"
class="rise-2 glow-btn group flex w-full items-center justify-center gap-2 rounded-xl bg-gradient-to-r from-violet-500 to-indigo-500 px-4 py-3.5 text-sm font-semibold text-white transition hover:from-violet-400 hover:to-indigo-400">
<svg class="h-4 w-4" viewBox="0 0 24 24" fill="currentColor"><path d="M12 2 3 7v10l9 5 9-5V7l-9-5Zm0 2.3 6.5 3.6L12 11.5 5.5 7.9 12 4.3Z"/></svg>
使用飞书登录
</a>
${devButton} ${devButton}
</main> </div>
</div>
</body> </body>
</html>`; </html>`;
} }
/** Sidebar nav items. `active` marks the current page. `href` "#" = placeholder. */ /** Sidebar nav items. `active` marks the current page. `href` "#" = placeholder. */
const NAV_ITEMS: ReadonlyArray<{ label: string; icon: string; href: string; active: boolean }> = [ const NAV_TABS: ReadonlyArray<{ id: string; label: string; icon: string }> = [
{ label: "概览", icon: "M4 13h6V4H4v9Zm0 7h6v-5H4v5Zm10 0h6V11h-6v9Zm0-16v5h6V4h-6Z", href: "/database/dashboard", active: true }, { id: "overview", label: "概览", icon: "M4 13h6V4H4v9Zm0 7h6v-5H4v5Zm10 0h6V11h-6v9Zm0-16v5h6V4h-6Z" },
{ label: "数据表", icon: "M4 5h16v4H4V5Zm0 6h16v4H4v-4Zm0 6h16v2H4v-2Z", href: "#", active: false }, { id: "library", label: "文件库", icon: "M3 7a2 2 0 0 1 2-2h4l2 2h8a2 2 0 0 1 2 2v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V7Z" },
{ label: "查询", icon: "m21 21-4.3-4.3M11 18a7 7 0 1 0 0-14 7 7 0 0 0 0 14Z", href: "#", active: false }, { id: "users", label: "用户管理", icon: "M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2M9 11a4 4 0 1 0 0-8 4 4 0 0 0 0 8Zm13 10v-2a4 4 0 0 0-3-3.87M16 3.13a4 4 0 0 1 0 7.75" },
{ label: "设置", icon: "M12 15a3 3 0 1 0 0-6 3 3 0 0 0 0 6Zm7-3 2 1-2 3-2-1a7 7 0 0 1-2 1l-1 2h-4l-1-2a7 7 0 0 1-2-1l-2 1-2-3 2-1a7 7 0 0 1 0-2l-2-1 2-3 2 1a7 7 0 0 1 2-1l1-2h4l1 2a7 7 0 0 1 2 1l2-1 2 3-2 1a7 7 0 0 1 0 2Z", href: "#", active: false }, { id: "groups", label: "Group 管理", icon: "M17 21v-2a4 4 0 0 0-4-4H5a4 4 0 0 0-4 4v2M9 11a4 4 0 1 0 0-8 4 4 0 0 0 0 8Zm14 10v-2a4 4 0 0 0-3-3.87M16 3.13a4 4 0 0 1 0 7.75M23 21v-2a4 4 0 0 0-3-3.87" },
{ id: "search", label: "查询", icon: "m21 21-4.3-4.3M11 18a7 7 0 1 0 0-14 7 7 0 0 0 0 14Z" },
{ id: "settings", label: "设置", icon: "M12 15a3 3 0 1 0 0-6 3 3 0 0 0 0 6Zm7-3 2 1-2 3-2-1a7 7 0 0 1-2 1l-1 2h-4l-1-2a7 7 0 0 1-2-1l-2 1-2-3 2-1a7 7 0 0 1 0-2l-2-1 2-3 2 1a7 7 0 0 1 2 1l1-2h4l1 2a7 7 0 0 1 0 2l2-1 2 3-2 1a7 7 0 0 1 0 2Z" },
]; ];
function renderDashboard(displayName: string): string { function renderDashboard(displayName: string, stats: DashboardStats | null, orgSlug: string): string {
const nav = NAV_ITEMS.map((item) => { const nav = NAV_TABS.map((t) => `
const cls = item.active <button class="admin-tab" data-tab="${t.id}" style="display:flex;align-items:center;gap:10px;border-radius:10px;padding:9px 14px;font-size:13px;color:var(--text-3);background:none;border:none;cursor:pointer;text-align:left;width:100%">
? "group flex items-center gap-3 rounded-xl bg-gradient-to-r from-violet-500 to-indigo-500 px-3 py-2.5 text-sm font-semibold text-white shadow-lg shadow-indigo-300/50" <svg style="width:16px;height:16px;flex-shrink:0" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="${t.icon}"/></svg>
: "group flex items-center gap-3 rounded-xl px-3 py-2.5 text-sm font-medium text-slate-500 transition hover:bg-slate-100 hover:text-slate-900"; ${t.label}
return `<a href="${item.href}" class="${cls}"> </button>`).join("\n");
<svg class="h-4 w-4 shrink-0" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="${item.icon}"/></svg>
${item.label}
</a>`;
}).join("\n ");
const stats = [ const cards = [
{ label: "数据表", value: "—", accent: "from-violet-200/60 to-transparent" }, { label: "文件夹", value: stats?.folders ?? "—" },
{ label: "记录数", value: "—", accent: "from-cyan-200/60 to-transparent" }, { label: "项目", value: stats?.projects ?? "—" },
{ label: "最近查询", value: "—", accent: "from-indigo-200/60 to-transparent" }, { label: "文件", value: stats?.files ?? "—" },
].map((s, i) => ` { label: "活跃授权", value: stats?.grants ?? "—" },
<div class="rise-${i + 1} group relative overflow-hidden rounded-2xl border border-white/80 glass p-5 shadow-lg shadow-slate-200/50 transition hover:-translate-y-0.5 hover:shadow-xl hover:shadow-indigo-200/50"> ].map((s) => `
<div class="absolute inset-0 bg-gradient-to-br ${s.accent} opacity-0 transition group-hover:opacity-100"></div> <div class="panel" style="padding:18px 20px">
<p class="relative text-sm text-slate-500">${s.label}</p> <p style="font-size:12.5px;color:var(--text-3)">${s.label}</p>
<p class="relative mt-2 text-3xl font-bold text-slate-900">${s.value}</p> <p style="margin-top:6px;font-size:28px;font-weight:600;color:var(--text)">${s.value}</p>
</div>`).join("");
const recentRows = stats === null || stats.recent.length === 0
? `<div style="padding:26px 0;text-align:center;font-size:12.5px;color:var(--text-3)">暂无文件库活动 · 到「文件库」里创建第一个文件夹吧</div>`
: stats.recent.map((r) => `
<div style="display:flex;align-items:center;gap:12px;border-top:1px solid var(--border-soft);padding:9px 0;font-size:13px">
<span class="tag">${escapeHtml(r.action)}</span>
<span style="overflow:hidden;text-overflow:ellipsis;white-space:nowrap;color:var(--text)">${escapeHtml(r.label)}</span>
<span style="margin-left:auto;flex-shrink:0;font-size:11.5px;color:var(--text-3)">${escapeHtml(r.actor)} · ${escapeHtml(r.when.toLocaleString("zh-CN"))}</span>
</div>`).join(""); </div>`).join("");
const initial = escapeHtml(displayName.slice(0, 1) || "U"); const initial = escapeHtml(displayName.slice(0, 1) || "U");
return `<!doctype html> return `<!doctype html>
<html lang="zh-CN"> <html lang="zh-CN">
${pageHead("Database Admin · 概览")} ${pageHead("Database Admin")}
<body class="relative min-h-screen overflow-hidden bg-gradient-to-br from-slate-50 via-white to-indigo-50 text-slate-700"> <body>
${AURORA} <div style="display:flex;height:100vh">
<div class="relative flex min-h-screen"> <aside style="width:240px;flex-shrink:0;background:var(--sidebar);border-right:1px solid var(--border-soft);display:flex;flex-direction:column">
<!-- 左侧菜单栏 --> <div style="padding:16px 16px 12px;border-bottom:1px solid var(--border-soft)">
<aside class="flex w-64 shrink-0 flex-col border-r border-slate-200/80 glass"> <span style="font-size:15px;font-weight:600">Database Admin</span>
<div class="flex items-center gap-3 px-5 py-6">
<div class="flex h-10 w-10 items-center justify-center rounded-xl bg-gradient-to-br from-violet-500 to-cyan-400 text-lg font-bold text-white glow-btn">D</div>
<span class="text-base font-bold grad-text">Database Admin</span>
</div> </div>
<nav class="flex flex-1 flex-col gap-1.5 px-3 py-2"> <nav style="flex:1;display:flex;flex-direction:column;gap:2px;padding:10px">
${nav} ${nav}
</nav> </nav>
<div class="m-3 flex items-center gap-3 rounded-xl border border-slate-200 bg-white/60 px-3 py-3"> <div style="margin:10px;padding:10px 12px;border-top:1px solid var(--border-soft);display:flex;align-items:center;gap:9px">
<div class="flex h-9 w-9 items-center justify-center rounded-full bg-gradient-to-br from-violet-500 to-indigo-500 text-sm font-semibold text-white">${initial}</div> <div style="width:26px;height:26px;border-radius:50%;background:var(--accent);color:#fff;display:flex;align-items:center;justify-content:center;font-size:11px;font-weight:600;flex-shrink:0">${initial}</div>
<div class="min-w-0"> <div style="min-width:0;flex:1">
<p class="text-[11px] uppercase tracking-wider text-slate-400">已登录</p> <p style="font-size:10.5px;color:var(--text-3)">已登录</p>
<p class="truncate text-sm font-medium text-slate-700">${escapeHtml(displayName)}</p> <p style="overflow:hidden;text-overflow:ellipsis;white-space:nowrap;font-size:12.5px;color:var(--text)">${escapeHtml(displayName)}</p>
</div> </div>
<button id="logout" class="btn" style="padding:3px 10px;font-size:11px">退出</button>
</div> </div>
</aside> </aside>
<!-- 右侧内容 --> <div style="flex:1;display:flex;flex-direction:column;min-width:0">
<div class="flex flex-1 flex-col"> <section id="tab-overview" class="admin-tab-section" style="flex:1;overflow-y:auto;padding:28px">
<header class="flex items-center justify-between border-b border-slate-200/80 glass px-8 py-4"> <h1 style="font-size:18px;font-weight:600;margin-bottom:4px">概览</h1>
<div> <p style="font-size:11.5px;color:var(--text-3);margin-bottom:20px">文件库实时数据</p>
<h1 class="text-lg font-bold text-slate-900">概览</h1> <div style="display:grid;grid-template-columns:repeat(4,1fr);gap:16px">
<p class="text-xs text-slate-400">欢迎回来,这里是数据库管理台</p> ${cards}
</div> </div>
<button id="logout" <div class="panel" style="margin-top:18px">
class="rounded-xl border border-slate-200 bg-white px-4 py-2 text-sm font-medium text-slate-600 transition hover:border-slate-300 hover:bg-slate-50 hover:text-slate-900"> <h2 style="font-size:13.5px;font-weight:600;margin-bottom:8px">最近活动</h2>
退出登录 ${recentRows}
</button> </div>
</header> </section>
<main class="flex-1 p-8"> <section id="tab-library" class="admin-tab-section" style="display:none;flex:1;min-height:0">
<div class="grid grid-cols-1 gap-5 sm:grid-cols-3"> ${renderLibraryBrowser()}
${stats} </section>
</div>
<div class="rise-3 mt-6 flex h-64 items-center justify-center rounded-2xl border border-dashed border-slate-300 glass text-sm text-slate-400"> <section id="tab-users" class="admin-tab-section" style="display:none;flex:1;overflow-y:auto;padding:28px">
内容区占位 · 在 src/database/routes/databaseRoutes.ts 里继续搭建 <h1 style="font-size:18px;font-weight:600;margin-bottom:16px">用户管理</h1>
</div> ${renderUsersPanel(orgSlug)}
</main> </section>
<section id="tab-groups" class="admin-tab-section" style="display:none;flex:1;overflow-y:auto;padding:28px">
<h1 style="font-size:18px;font-weight:600;margin-bottom:16px">Group 管理</h1>
${renderGroupsPanel(orgSlug)}
</section>
<section id="tab-search" class="admin-tab-section" style="display:none;flex:1;overflow-y:auto;padding:28px">
<h1 style="font-size:18px;font-weight:600;margin-bottom:4px">查询</h1>
<p style="font-size:12.5px;color:var(--text-3)">查询功能建设中</p>
</section>
<section id="tab-settings" class="admin-tab-section" style="display:none;flex:1;overflow-y:auto;padding:28px">
<h1 style="font-size:18px;font-weight:600;margin-bottom:4px">设置</h1>
<p style="font-size:12.5px;color:var(--text-3)">设置功能建设中</p>
</section>
</div> </div>
</div> </div>
<script> <script>
document.getElementById("logout").addEventListener("click", async () => { (function () {
await fetch("/auth/logout", { method: "POST" }); const tabs = [...document.querySelectorAll(".admin-tab")];
window.location.href = "/database/admin"; const sections = Object.fromEntries(
[...document.querySelectorAll(".admin-tab-section")].map((s) => [s.id.replace("tab-", ""), s]),
);
function activate(id) {
tabs.forEach((t) => {
const on = t.dataset.tab === id;
t.style.background = on ? "var(--selected)" : "none";
t.style.color = on ? "var(--text)" : "var(--text-3)";
t.style.fontWeight = on ? "600" : "400";
}); });
Object.entries(sections).forEach(([key, s]) => {
s.style.display = key === id ? (key === "library" ? "block" : "block") : "none";
});
if (location.hash !== "#" + id) history.replaceState(null, "", "#" + id);
}
tabs.forEach((t) => t.addEventListener("click", () => activate(t.dataset.tab)));
document.getElementById("logout").addEventListener("click", async () => {
try { await fetch("/auth/logout", { method: "POST", credentials: "same-origin" }); } catch (e) {}
location.href = "/database/admin";
});
const fromHash = location.hash.replace(/^#/, "");
activate(tabs.some((t) => t.dataset.tab === fromHash) ? fromHash : "overview");
})();
</script> </script>
</body> </body>
</html>`; </html>`;
+235
View File
@@ -0,0 +1,235 @@
/**
* /database/api/* 文件内容与导出端点(契约 9.3/9.4)。
* 冲突流:POST commits 返回 200 {version} 或 409 {currentVersion}(编辑 UI 拉 diff 后重提)。
*/
import type { FastifyInstance, FastifyRequest } from "fastify";
import {
commitFile,
deleteFile,
diffFile,
fileHistory,
listFiles,
readFile,
readFileRaw,
type FileContentEncoding,
} from "../filelib/fileService.js";
import {
createManifestStubAdapter,
downloadExport,
getExportJob,
submitExport,
} from "../filelib/exportService.js";
import { FileLibError } from "../filelib/model.js";
import {
actorOrNull,
bodyObject,
optionalString,
requireString,
sendRouteError,
type FileLibRouteDeps,
} from "../filelib/routeShared.js";
export async function registerFileRoutes(
app: FastifyInstance,
deps: FileLibRouteDeps,
): Promise<void> {
const fileDeps = {
prisma: deps.prisma,
organizationId: deps.organizationId,
groupResolver: deps.groupResolver,
versionStore: deps.versionStore,
};
const exportDeps = { ...fileDeps, adapters: deps.exportAdapters };
function pathParam(request: FastifyRequest): string {
const path = (request.query as { path?: string }).path;
if (path === undefined) throw new FileLibError(400, "invalid_request", "missing query: path");
return path;
}
function encodingParam(raw: unknown): FileContentEncoding {
if (raw === undefined || raw === "utf8") return "utf8";
if (raw === "base64") return "base64";
throw new FileLibError(400, "invalid_request", "encoding must be utf8 or base64");
}
app.get("/database/api/projects/:id/files", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const prefix = (request.query as { prefix?: string }).prefix;
return { files: await listFiles(fileDeps, actor, id, prefix) };
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/projects/:id/file", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
return await readFile(fileDeps, actor, id, pathParam(request));
} catch (error) {
return sendRouteError(reply, error);
}
});
// 原始字节下载(Content-Disposition: attachment;浏览器直接 save-as)
app.get("/database/api/projects/:id/file/raw", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const raw = await readFileRaw(fileDeps, actor, id, pathParam(request));
return reply
.header("Content-Disposition",
`attachment; filename="${encodeURIComponent(raw.filename)}"; filename*=UTF-8''${encodeURIComponent(raw.filename)}`)
.header("X-Content-Version", raw.version)
.type("application/octet-stream")
.send(raw.buffer);
} catch (error) {
return sendRouteError(reply, error);
}
});
// 新建/上传(baseVersion 恒 null;已存在 → 409)
app.put("/database/api/projects/:id/file", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const result = await commitFile(fileDeps, actor, id, {
path: requireString(body, "path"),
baseVersion: null,
content: requireString(body, "content"),
encoding: encodingParam(body["encoding"]),
message: optionalString(body, "message"),
});
return reply.status(201).send(result);
} catch (error) {
return sendRouteError(reply, error);
}
});
// 提交编辑(乐观并发;409 → details.currentVersion + file.conflict_detected 审计)
app.post("/database/api/projects/:id/file/commits", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const baseVersion = body["baseVersion"];
if (typeof baseVersion !== "string" || baseVersion === "") {
throw new FileLibError(400, "invalid_request", "baseVersion must be a non-empty string");
}
return await commitFile(fileDeps, actor, id, {
path: requireString(body, "path"),
baseVersion,
content: requireString(body, "content"),
encoding: encodingParam(body["encoding"]),
message: optionalString(body, "message"),
});
} catch (error) {
return sendRouteError(reply, error);
}
});
app.delete("/database/api/projects/:id/file", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
await deleteFile(fileDeps, actor, id, pathParam(request), requireString(body, "baseVersion"));
return reply.status(204).send();
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/projects/:id/file/diff", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const query = request.query as { from?: string; to?: string };
if (query.from === undefined || query.to === undefined) {
throw new FileLibError(400, "invalid_request", "missing query: from / to");
}
return await diffFile(fileDeps, actor, id, pathParam(request), query.from, query.to);
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/projects/:id/file/history", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const rawLimit = (request.query as { limit?: string }).limit;
const limit = rawLimit === undefined ? undefined : Number.parseInt(rawLimit, 10);
if (limit !== undefined && (!Number.isSafeInteger(limit) || limit <= 0)) {
throw new FileLibError(400, "invalid_request", "limit must be a positive integer");
}
return { history: await fileHistory(fileDeps, actor, id, pathParam(request), limit) };
} catch (error) {
return sendRouteError(reply, error);
}
});
/* ------------------------------------------------------------ 导出(D10 异步) */
app.post("/database/api/projects/:id/exports", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const params = body["params"];
if (params !== undefined && (typeof params !== "object" || params === null || Array.isArray(params))) {
throw new FileLibError(400, "invalid_request", "params must be an object");
}
const job = await submitExport(
exportDeps,
actor,
id,
requireString(body, "target"),
(params as Record<string, unknown> | undefined) ?? {},
);
return reply.status(202).send({ jobId: job.id, status: job.status });
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/exports/:jobId", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { jobId } = request.params as { jobId: string };
return await getExportJob(exportDeps, actor, jobId);
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/exports/:jobId/download", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { jobId } = request.params as { jobId: string };
const artifact = await downloadExport(exportDeps, actor, jobId);
return reply
.header("Content-Disposition", `attachment; filename="${artifact.filename}"`)
.type("application/octet-stream")
.send(artifact.content);
} catch (error) {
return sendRouteError(reply, error);
}
});
}
+310
View File
@@ -0,0 +1,310 @@
/**
* /database/api/* 树与授权端点(契约 9.1/9.2 + C2 过渡搜索)。
* 约定:绝对路径;actorOrNull 前置;业务全走 filelib 服务层;错误统一 sendRouteError。
*/
import type { FastifyInstance } from "fastify";
import {
breadcrumb,
createNode,
getEffectiveRole,
listChildren,
moveNode,
renameNode,
softDeleteNode,
updateNodeDescription,
type FileLibActor,
type InitialGrant,
} from "../filelib/treeService.js";
import {
forceAdjustGrants,
listGrants,
putGrants,
revokeGrant,
setIndependentPermission,
} from "../filelib/grantService.js";
import { FileLibError } from "../filelib/model.js";
import {
actorOrNull,
bodyObject,
optionalString,
requireString,
sendRouteError,
treeDeps,
type FileLibRouteDeps,
} from "../filelib/routeShared.js";
export async function registerFileLibRoutes(
app: FastifyInstance,
deps: FileLibRouteDeps,
): Promise<void> {
const tree = treeDeps(deps);
const grantDeps = { prisma: deps.prisma, organizationId: deps.organizationId, groupResolver: deps.groupResolver };
/* ------------------------------------------------------------ 身份 */
// 前端判断能力面用:是否网站管理员(root 创建按钮显隐)。
app.get("/database/api/me", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
return { userId: actor.userId, isWebsiteAdmin: actor.isWebsiteAdmin };
});
/* ------------------------------------------------------------ 树节点 */
app.get("/database/api/nodes", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const query = request.query as { parentId?: string };
const parentId = query.parentId === undefined || query.parentId === "" ? null : query.parentId;
return { nodes: await listChildren(tree, actor, parentId) };
} catch (error) {
return sendRouteError(reply, error);
}
});
app.post("/database/api/nodes", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const body = bodyObject(request.body);
const parentIdRaw = body["parentId"];
if (parentIdRaw !== null && typeof parentIdRaw !== "string") {
throw new FileLibError(400, "invalid_request", "parentId must be a string or null");
}
const kindRaw = requireString(body, "kind");
if (kindRaw !== "FOLDER" && kindRaw !== "PROJECT") {
throw new FileLibError(400, "invalid_request", "kind must be FOLDER or PROJECT");
}
const grants = parseGrants(body["grants"]);
const description = optionalString(body, "description");
const node = await createNode(tree, actor, {
parentId: parentIdRaw,
kind: kindRaw,
name: requireString(body, "name"),
description: description || undefined,
grants,
});
return reply.status(201).send({ node });
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/nodes/:id", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const role = await getEffectiveRole(tree, actor, id); // 无权限即 404(D8)
const node = await deps.prisma.fileLibNode.findFirst({
where: { id, organizationId: deps.organizationId },
});
if (node === null) throw new FileLibError(404, "node_not_found", "node not found");
const settings = node.kind === "PROJECT"
? await deps.prisma.fileLibProjectSettings.findUnique({ where: { nodeId: node.id } })
: null;
return {
node: {
id: node.id,
parentId: node.parentId,
kind: node.kind,
name: node.name,
description: node.description,
role,
provisionStatus: node.provisionStatus,
independentPermission: settings?.independentPermissionsEnabled ?? false,
createdAt: node.createdAt,
updatedAt: node.updatedAt,
},
};
} catch (error) {
return sendRouteError(reply, error);
}
});
app.patch("/database/api/nodes/:id", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const name = optionalString(body, "name");
const hasParent = Object.prototype.hasOwnProperty.call(body, "parentId");
const hasDesc = Object.prototype.hasOwnProperty.call(body, "description");
if (name === undefined && !hasParent && !hasDesc) {
throw new FileLibError(400, "invalid_request", "nothing to update (name? parentId? description?)");
}
let node;
if (name !== undefined) node = await renameNode(tree, actor, id, name);
if (hasParent) {
const parentId = body["parentId"];
if (parentId !== null && typeof parentId !== "string") {
throw new FileLibError(400, "invalid_request", "parentId must be a string or null");
}
node = await moveNode(tree, actor, id, parentId);
}
if (hasDesc) {
const d = body["description"];
if (d !== null && typeof d !== "string") {
throw new FileLibError(400, "invalid_request", "description must be a string or null");
}
node = await updateNodeDescription(tree, actor, id, typeof d === "string" ? d : null);
}
return { node };
} catch (error) {
return sendRouteError(reply, error);
}
});
app.delete("/database/api/nodes/:id", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
await softDeleteNode(tree, actor, id);
return reply.status(204).send();
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/nodes/:id/breadcrumb", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
return { breadcrumb: await breadcrumb(tree, actor, id) };
} catch (error) {
return sendRouteError(reply, error);
}
});
app.get("/database/api/nodes/:id/effective-permission", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
return { role: await getEffectiveRole(tree, actor, id) };
} catch (error) {
return sendRouteError(reply, error);
}
});
/* ------------------------------------------------------------ 授权 */
app.get("/database/api/nodes/:id/grants", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
return { grants: await listGrants(grantDeps, actor, id) };
} catch (error) {
return sendRouteError(reply, error);
}
});
app.put("/database/api/nodes/:id/grants", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const items = parseGrants(body["grants"]);
if (items === undefined) throw new FileLibError(400, "invalid_request", "missing field: grants");
return await putGrants(grantDeps, actor, id, items);
} catch (error) {
return sendRouteError(reply, error);
}
});
app.delete("/database/api/nodes/:id/grants/:grantId", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id, grantId } = request.params as { id: string; grantId: string };
await revokeGrant(grantDeps, actor, id, grantId);
return reply.status(204).send();
} catch (error) {
return sendRouteError(reply, error);
}
});
// D19 高危通道:网站管理员凭 id 强制调整,全部留 admin.force_adjust 审计。
app.put("/database/api/admin/nodes/:id/grants", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
const items = parseGrants(body["grants"]);
if (items === undefined) throw new FileLibError(400, "invalid_request", "missing field: grants");
return await forceAdjustGrants(grantDeps, actor, id, items);
} catch (error) {
return sendRouteError(reply, error);
}
});
app.put("/database/api/projects/:id/independent-permission", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const { id } = request.params as { id: string };
const body = bodyObject(request.body);
if (typeof body["enabled"] !== "boolean") {
throw new FileLibError(400, "invalid_request", "enabled must be a boolean");
}
return await setIndependentPermission(grantDeps, actor, id, body["enabled"]);
} catch (error) {
return sendRouteError(reply, error);
}
});
/* ------------------------------------------------------------ Group 搜索(过渡) */
// 过渡实现:读 hub Team(C2 /groups/search 由 Group 团队交付后切换)。
app.get("/database/api/groups/search", async (request, reply) => {
const actor = await actorOrNull(request, reply, deps);
if (actor === null) return reply;
try {
const q = ((request.query as { q?: string }).q ?? "").trim();
const teams = await deps.prisma.team.findMany({
where: {
organizationId: deps.organizationId,
archivedAt: null,
...(q === "" ? {} : { name: { contains: q, mode: "insensitive" as const } }),
},
take: 20,
orderBy: { name: "asc" },
select: { id: true, name: true },
});
return { groups: teams.map((t) => ({ id: t.id, name: t.name, breadcrumb: t.name })) };
} catch (error) {
return sendRouteError(reply, error);
}
});
}
function parseGrants(raw: unknown): InitialGrant[] | undefined {
if (raw === undefined) return undefined;
if (!Array.isArray(raw)) throw new FileLibError(400, "invalid_request", "grants must be an array");
return raw.map((item) => {
if (typeof item !== "object" || item === null) {
throw new FileLibError(400, "invalid_request", "grant entries must be objects");
}
const grant = item as Record<string, unknown>;
const principalType = grant["principalType"];
if (principalType !== "USER" && principalType !== "GROUP") {
throw new FileLibError(400, "invalid_request", "grant.principalType must be USER or GROUP");
}
const role = grant["role"];
if (role !== "VIEW" && role !== "EDIT" && role !== "MANAGE") {
throw new FileLibError(400, "invalid_request", "grant.role must be VIEW, EDIT or MANAGE");
}
if (typeof grant["principalId"] !== "string" || grant["principalId"] === "") {
throw new FileLibError(400, "invalid_request", "grant.principalId must be a non-empty string");
}
return { principalType, principalId: grant["principalId"], role };
});
}
+596
View File
@@ -0,0 +1,596 @@
/**
* 管理员后台「文件库」页内浏览器区块(树 | 内容 | 预览三栏,含授权管理)。
*
* renderLibraryBrowser() 返回可嵌入任意后台布局的 HTML+JS 片段:
* 以 #lib-root 为根、内部用 q() 作用域选择器,不与宿主页其他元素冲突。
* 与独立页版浏览器的区别:去掉了自己的 wordmark/用户栏(由后台外壳提供),
* 保留管理员工具(根目录创建、授权面板、独立权限开关)。
*/
export function renderLibraryBrowser(): string {
return `
<div id="lib-root" style="display:flex;height:100%;min-height:0">
<!-- 左:目录树 -->
<div style="width:250px;flex-shrink:0;border-right:1px solid var(--border-soft);display:flex;flex-direction:column;background:var(--sidebar)">
<div style="display:flex;align-items:center;justify-content:space-between;padding:12px 14px;border-bottom:1px solid var(--border-soft)">
<span style="font-size:13px;font-weight:600;color:var(--text)">文件库</span>
<button id="lib-btn-new-root" class="btn hidden" style="padding:3px 10px;font-size:11px" title="新建根目录">+ 根目录</button>
</div>
<div id="lib-tree" style="flex:1;overflow-y:auto;padding:8px 8px 16px;font-size:13px"></div>
</div>
<!-- 中:节点内容 -->
<div id="lib-main" style="flex:1;overflow-y:auto;min-width:0">
<div class="lib-empty-hint">从左侧选择一个文件夹或项目</div>
</div>
<!-- 右:预览/编辑(选中文件时出现) -->
<div id="lib-preview" style="display:none;width:44%;min-width:380px;flex-shrink:0;overflow-y:auto;border-left:1px solid var(--border-soft);padding:16px"></div>
<div id="lib-modal-root"></div>
<div id="lib-toast-root" style="position:fixed;bottom:16px;right:16px;z-index:50;display:flex;flex-direction:column;gap:8px"></div>
</div>
<style>
#lib-root .lib-empty-hint { height:100%;display:flex;align-items:center;justify-content:center;color:var(--text-3);font-size:13px; }
#lib-root .tree-item { display:flex;align-items:center;gap:4px;padding:4px 6px;border-radius:6px;cursor:pointer;color:var(--text);transition:background 120ms ease;user-select:none; }
#lib-root .tree-item:hover { background:var(--hover); }
#lib-root .tree-item.selected { background:var(--selected); }
#lib-root .tree-children { border-left:1px solid var(--guide);margin-left:15px;padding-left:3px; }
#lib-root .tree-icon { width:16px;height:16px;flex-shrink:0;display:flex;align-items:center;justify-content:center; }
#lib-root .tree-caret { color:var(--text-3); }
#lib-root .tree-badge { margin-left:auto;padding-right:4px;font-size:10px;color:var(--text-3);font-family:var(--mono); }
#lib-root .tree-empty { padding:24px 12px;text-align:center;font-size:12px;color:var(--text-3); }
#lib-root .lib-toast { border-radius:8px;padding:8px 14px;font-size:12px;color:#fff;background:#333230;max-width:320px; }
#lib-root .lib-toast-err { background:#7E2C26; }
#lib-root .modal-mask { position:fixed;inset:0;z-index:40;background:rgba(26,26,24,.3);display:flex;align-items:center;justify-content:center;padding:16px; }
#lib-root .modal-card { width:100%;max-width:440px;background:var(--panel);border:1px solid var(--border);border-radius:12px;padding:22px; }
#lib-root pre.diff { white-space:pre-wrap;font-family:var(--mono);font-size:12px;line-height:1.7;background:var(--panel);border:1px solid var(--border);border-radius:8px;padding:10px;margin:0; }
#lib-root pre.diff .add { display:block;color:var(--diff-add-text);background:var(--diff-add-bg); }
#lib-root pre.diff .del { display:block;color:var(--diff-del-text);background:var(--diff-del-bg); }
#lib-root .meta-grid { display:grid;grid-template-columns:1fr 1fr;gap:10px 24px;font-size:13px;color:var(--text-2); }
#lib-root .meta-grid b { color:var(--text);font-weight:600; }
#lib-root .conflict-panel { margin-top:14px;border:1px solid #E8E2C8;background:#FCFBF4;border-radius:10px;padding:14px 16px; }
#lib-root .conflict-title { font-size:13px;font-weight:600;color:#6E6329;margin-bottom:8px; }
#lib-root .conflict-note { font-size:11px;color:#8A8059;margin-top:8px; }
#lib-root .export-status { font-size:11px;color:var(--text-3);font-family:var(--mono); }
</style>
<script>
(function () {
const libRoot = document.getElementById("lib-root");
if (!libRoot) return;
const $ = (sel) => libRoot.querySelector(sel);
const $$ = (sel) => [...libRoot.querySelectorAll(sel)];
const esc = (s) => String(s).replace(/&/g,"&amp;").replace(/</g,"&lt;").replace(/>/g,"&gt;").replace(/"/g,"&quot;");
async function api(path, opts = {}) {
const res = await fetch(path, {
credentials: "same-origin",
headers: opts.body ? { "Content-Type": "application/json" } : undefined,
...opts,
body: opts.body ? JSON.stringify(opts.body) : undefined,
});
if (res.status === 401) { location.href = "/database/admin"; throw new Error("unauthenticated"); }
if (res.status === 204) return null;
const text = await res.text();
const data = text ? JSON.parse(text) : null;
if (!res.ok) {
const err = (data && data.error) || { code: "unknown", message: res.statusText };
const e = new Error(err.message); e.code = err.code; e.status = res.status; Object.assign(e, err);
throw e;
}
return data;
}
function toast(msg, kind = "info") {
const el = document.createElement("div");
el.className = "lib-toast" + (kind === "err" ? " lib-toast-err" : "");
el.textContent = msg;
$("#lib-toast-root").appendChild(el);
setTimeout(() => el.remove(), 3600);
}
const ok = (m) => toast(m, "ok");
const fail = (e) => toast(e.message || String(e), "err");
function modal(html) {
const root = $("#lib-modal-root");
root.innerHTML = '<div class="modal-mask"><div class="modal-card">' + html + "</div></div>";
root.firstElementChild.addEventListener("click", (e) => { if (e.target === e.currentTarget) closeModal(); });
}
function closeModal() { $("#lib-modal-root").innerHTML = ""; }
let me = { userId: null, isWebsiteAdmin: false };
let current = null;
const expanded = new Set();
let currentFile = null;
const ICONS = {
caretRight: '<svg width="10" height="10" viewBox="0 0 24 24" fill="currentColor"><path d="M9 6l6 6-6 6z"/></svg>',
caretDown: '<svg width="10" height="10" viewBox="0 0 24 24" fill="currentColor"><path d="M6 9l6 6 6-6z"/></svg>',
folder: '<svg width="16" height="16" viewBox="0 0 24 24" fill="currentColor"><path d="M3 7a2 2 0 0 1 2-2h4l2 2h8a2 2 0 0 1 2 2v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V7Z"/></svg>',
project: '<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="M20 7l-8-4-8 4m16 0l-8 4m8-4v10l-8 4m0-10L4 7m8 4v10M4 7v10l8 4"/></svg>',
};
async function loadChildren(parentId) {
const q = parentId === null ? "" : "?parentId=" + encodeURIComponent(parentId);
return (await api("/database/api/nodes" + q)).nodes;
}
async function renderTree() {
const tree = $("#lib-tree");
tree.innerHTML = "";
try {
const roots = await loadChildren(null);
if (roots.length === 0) {
tree.innerHTML = '<div class="tree-empty">空文件库' +
(me.isWebsiteAdmin ? " · 点上方「+ 根目录」开始" : "") + "</div>";
return;
}
for (const node of roots) tree.appendChild(await treeItem(node, 0));
} catch (e) { tree.innerHTML = '<div class="tree-empty">' + esc(e.message) + "</div>"; }
}
async function treeItem(node, depth) {
const wrap = document.createElement("div");
const row = document.createElement("div");
row.className = "tree-item" + (current && current.id === node.id ? " selected" : "");
const caret = document.createElement("span");
caret.className = "tree-icon tree-caret";
if (node.kind === "FOLDER") {
caret.innerHTML = expanded.has(node.id) ? ICONS.caretDown : ICONS.caretRight;
caret.onclick = (e) => { e.stopPropagation(); toggleExpand(node.id); };
}
row.appendChild(caret);
const iconSpan = document.createElement("span");
iconSpan.className = "tree-icon";
iconSpan.style.color = node.kind === "PROJECT" ? "#1A1A18" : "#9C9B96";
iconSpan.innerHTML = node.kind === "PROJECT" ? ICONS.project : ICONS.folder;
row.appendChild(iconSpan);
const nameSpan = document.createElement("span");
nameSpan.className = "truncate";
nameSpan.textContent = node.name;
row.appendChild(nameSpan);
if (node.role !== "MANAGE") {
const badge = document.createElement("span");
badge.className = "tree-badge";
badge.textContent = node.role;
row.appendChild(badge);
}
row.onclick = () => {
if (node.kind === "FOLDER") {
if (expanded.has(node.id)) expanded.delete(node.id); else expanded.add(node.id);
}
selectNode(node.id);
};
wrap.appendChild(row);
if (node.kind === "FOLDER" && expanded.has(node.id)) {
wrap.appendChild(await childrenBlock(node.id, depth));
}
return wrap;
}
async function childrenBlock(parentId, depth) {
const block = document.createElement("div");
block.className = "tree-children";
const kids = await loadChildren(parentId);
for (const kid of kids) block.appendChild(await treeItem(kid, depth + 1));
return block;
}
async function toggleExpand(id) {
if (expanded.has(id)) expanded.delete(id); else expanded.add(id);
await renderTree();
}
async function selectNode(id) {
try {
const [{ node }, { breadcrumb }] = await Promise.all([
api("/database/api/nodes/" + id),
api("/database/api/nodes/" + id + "/breadcrumb"),
]);
current = node; current.breadcrumb = breadcrumb;
closePreview();
await renderTree();
renderMain();
} catch (e) { fail(e); }
}
function crumbsHtml() {
return current.breadcrumb.map((c) =>
c.name === null ? "<span>…</span>" : "<span>" + esc(c.name) + "</span>"
).join('<span style="margin:0 4px;color:var(--border)">/</span>');
}
function renderMain() {
const n = current;
const canManage = n.role === "MANAGE";
const canEdit = canManage || n.role === "EDIT";
const tabs = [];
tabs.push(["detail", "概览"]);
if (n.kind === "PROJECT") tabs.push(["files", "文件"]);
if (canManage) tabs.push(["grants", "授权"]);
current.tab = current.tab && tabs.some(t => t[0] === current.tab) ? current.tab : "detail";
$("#lib-main").innerHTML =
'<div style="max-width:860px;margin:0 auto;padding:28px 28px 56px">' +
'<div style="font-size:12px;color:var(--text-3);margin-bottom:6px">' + crumbsHtml() + "</div>" +
'<div style="display:flex;align-items:center;justify-content:space-between;margin-bottom:18px">' +
'<div style="font-size:17px;font-weight:600;color:var(--text);display:flex;align-items:center;gap:8px">' + esc(n.name) +
'<span class="tag">' + n.kind + "</span>" +
'<span class="tag tag-role">' + n.role + "</span>" +
"</div>" +
'<div style="display:flex;gap:6px">' +
(canEdit && n.kind === "FOLDER" ? '<button class="btn" onclick="window.__lib.createChild()">+ 新建子节点</button>' : "") +
(canManage ? '<button class="btn" onclick="window.__lib.renameCurrent()">重命名</button>' : "") +
(canManage ? '<button class="btn btn-danger" onclick="window.__lib.deleteCurrent()">删除</button>' : "") +
"</div>" +
"</div>" +
'<div class="tabs">' +
tabs.map(([id, label]) =>
'<button onclick="window.__lib.switchTab(\\'' + id + '\\')" class="tab' +
(current.tab === id ? " active" : "") + '">' + label + "</button>").join("") +
"</div>" +
'<div id="lib-tab-body"></div>' +
"</div>";
renderTab();
}
function renderTab() {
const body = $("#lib-tab-body");
if (current.tab === "files") return renderFilesTab(body);
if (current.tab === "grants") return renderGrantsTab(body);
let extra = "";
if (current.kind === "PROJECT") {
extra =
'<div class="divider"></div>' +
'<div class="inline-form" style="justify-content:flex-start">' +
'<span class="quiet">独立权限</span>' +
'<b style="font-size:13px">' + (current.independentPermission ? "开启" : "关闭") + "</b>" +
(current.role === "MANAGE"
? '<button class="btn" onclick="window.__lib.toggleIndependent()">' + (current.independentPermission ? "关闭" : "开启") + "</button>"
: "") +
'<span class="quiet">关闭时仅继承父级权限(创建者除外)</span>' +
"</div>" +
'<div class="divider"></div>' +
'<div class="section-title">导出</div>' +
'<div class="inline-form">' +
'<select id="lib-x-target" class="select" style="width:auto"><option value="manifest">manifest(stub)</option></select>' +
'<button class="btn" onclick="window.__lib.submitExport()">开始导出</button>' +
'<span id="lib-x-status" class="export-status"></span>' +
"</div>";
}
body.innerHTML =
'<div class="panel">' +
'<div class="meta-grid">' +
"<div>类型 <b>" + current.kind + "</b></div>" +
"<div>我的权限 <b>" + current.role + "</b></div>" +
"<div>创建时间 " + new Date(current.createdAt).toLocaleString("zh-CN") + "</div>" +
"<div>更新时间 " + new Date(current.updatedAt).toLocaleString("zh-CN") + "</div>" +
"</div>" + extra +
"</div>";
pollExport();
}
/* ---------------- 节点操作 ---------------- */
function createDialog(parentId) {
modal(
'<div class="modal-title">' + (parentId ? "新建子节点" : "新建根目录") + "</div>" +
'<div class="form-row"><label class="form-label">名称</label>' +
'<input id="lib-f-name" class="input" placeholder="例如:物理必修一"/></div>' +
'<div class="form-row"><label class="form-label">类型</label>' +
'<select id="lib-f-kind" class="select">' +
'<option value="FOLDER">文件夹</option><option value="PROJECT">项目(Git 仓库)</option>' +
"</select></div>" +
'<div class="modal-actions">' +
'<button class="btn" onclick="window.__lib.closeModal()">取消</button>' +
'<button class="btn btn-primary" onclick="window.__lib.submitCreate(\\'' + (parentId ?? "") + '\\')">创建</button>' +
"</div>"
);
}
async function submitCreate(parentId) {
try {
await api("/database/api/nodes", { method: "POST", body: {
parentId: parentId === "" ? null : parentId,
kind: $("#lib-f-kind").value, name: $("#lib-f-name").value,
}});
closeModal(); ok("已创建");
if (parentId) expanded.add(parentId);
await renderTree();
} catch (e) { fail(e); }
}
/* ---------------- 授权 ---------------- */
async function renderGrantsTab(body) {
try {
const { grants } = await api("/database/api/nodes/" + current.id + "/grants");
const rows = grants.map((g) =>
"<tr>" +
"<td>" + (g.principalType === "USER" ? "👤" : "👥") + " " + esc(g.principalId) +
(g.isCreatorGrant ? ' <span class="quiet">(创建者)</span>' : "") + "</td>" +
'<td class="file-meta">' + g.role + "</td>" +
"<td style='text-align:right'>" + (g.isCreatorGrant ? "" :
'<button class="link-danger" onclick="window.__lib.revokeGrant(\\'' + g.id + '\\')">收回</button>') + "</td>" +
"</tr>").join("");
body.innerHTML =
'<div class="panel">' +
'<table class="list"><thead><tr><th>主体</th><th>级别</th><th></th></tr></thead>' +
"<tbody>" + rows + "</tbody></table>" +
'<div class="divider"></div>' +
'<div class="section-title">新增授权</div>' +
'<div class="inline-form">' +
'<select id="lib-g-type" class="select" style="width:110px" onchange="window.__lib.gTypeChanged()">' +
'<option value="USER">用户</option><option value="GROUP">Group</option></select>' +
'<input id="lib-g-principal" class="input" placeholder="用户 id"/>' +
'<select id="lib-g-group" class="select hidden"></select>' +
'<select id="lib-g-role" class="select" style="width:110px">' +
'<option value="VIEW">VIEW</option><option value="EDIT">EDIT</option><option value="MANAGE">MANAGE</option></select>' +
'<button class="btn btn-primary" onclick="window.__lib.addGrant()">授予</button>' +
"</div>" +
'<div class="section-note">MANAGE 仅创建者可授;创建者授权不可动(契约 8.1)</div>' +
"</div>";
} catch (e) { body.innerHTML = '<div class="panel quiet">' + esc(e.message) + "</div>"; }
}
/* ---------------- 文件 ---------------- */
async function renderFilesTab(body) {
try {
const { files } = await api("/database/api/projects/" + current.id + "/files");
const rows = files.map((f) =>
'<tr class="file-row" onclick="window.__lib.openFile(\\'' + esc(f.path) + '\\')">' +
'<td class="file-path">' + esc(f.path) + "</td>" +
'<td class="file-meta" style="text-align:right">' + f.size + " B</td></tr>").join("");
body.innerHTML =
'<div class="panel">' +
'<div class="inline-form" style="justify-content:space-between;margin-bottom:6px">' +
'<div class="section-title" style="margin:0">项目文件(' + files.length + ")</div>" +
(current.role !== "VIEW"
? '<div class="inline-form" style="gap:6px">' +
'<button class="btn" onclick="window.__lib.newFileDialog()">+ 新建文件</button>' +
'<button class="btn btn-primary" onclick="document.getElementById(\\'lib-upload-input\\').click()">上传文件</button>' +
'<input id="lib-upload-input" type="file" class="hidden"/>' +
"</div>"
: "") +
"</div>" +
(files.length === 0 ? '<div class="quiet" style="padding:20px 0;text-align:center">空仓库 · 可新建或上传文件</div>'
: '<table class="list">' + rows + "</table>") +
"</div>";
const up = $("#lib-upload-input");
if (up) up.onchange = (e) => doUpload(e.target);
} catch (e) { body.innerHTML = '<div class="panel quiet">' + esc(e.message) + "</div>"; }
}
function newFileDialog() {
modal(
'<div class="modal-title">新建文件</div>' +
'<div class="form-row"><label class="form-label">路径</label>' +
'<input id="lib-nf-path" class="input" style="font-family:var(--mono)" placeholder="docs/intro.md"/></div>' +
'<div class="form-row"><label class="form-label">内容</label>' +
'<textarea id="lib-nf-content" rows="8" class="textarea" placeholder="内容…"></textarea></div>' +
'<div class="modal-actions"><button class="btn" onclick="window.__lib.closeModal()">取消</button>' +
'<button class="btn btn-primary" onclick="window.__lib.submitNewFile()">创建</button></div>'
);
}
async function submitNewFile() {
try {
await api("/database/api/projects/" + current.id + "/file", { method: "PUT", body: {
path: $("#lib-nf-path").value, content: $("#lib-nf-content").value,
}});
closeModal(); ok("已创建"); renderTab();
} catch (e) { fail(e); }
}
function u8ToBase64(bytes) {
let bin = "";
const CHUNK = 0x8000;
for (let i = 0; i < bytes.length; i += CHUNK) {
bin += String.fromCharCode.apply(null, bytes.subarray(i, i + CHUNK));
}
return btoa(bin);
}
async function doUpload(input) {
const file = input.files && input.files[0];
input.value = "";
if (!file) return;
if (file.size > 10 * 1024 * 1024) return toast("文件超过 10MB 上限", "err");
const targetPath = prompt("保存到路径(可含目录):", "材料/" + file.name);
if (!targetPath) return;
const bytes = new Uint8Array(await file.arrayBuffer());
const isBinary = bytes.includes(0);
const body = isBinary
? { path: targetPath, content: u8ToBase64(bytes), encoding: "base64" }
: { path: targetPath, content: new TextDecoder("utf-8").decode(bytes), encoding: "utf8" };
try {
await api("/database/api/projects/" + current.id + "/file", { method: "PUT", body });
ok("已上传 " + file.name);
renderTab();
} catch (e) { fail(e); }
}
async function openFile(path) {
try {
const f = await api("/database/api/projects/" + current.id + "/file?path=" + encodeURIComponent(path));
currentFile = f;
const canEdit = current.role !== "VIEW";
const prev = $("#lib-preview");
prev.style.display = "block";
prev.innerHTML =
'<div class="panel">' +
'<div class="inline-form" style="justify-content:space-between;margin-bottom:10px">' +
'<span class="file-meta">' + esc(f.path) + " @ " + esc(f.version) + "</span>" +
'<div class="inline-form" style="gap:6px">' +
'<a class="btn" href="/database/api/projects/' + current.id + '/file/raw?path=' +
encodeURIComponent(f.path) + '" download>下载</a>' +
'<button class="btn" onclick="window.__lib.showHistory()">历史</button>' +
(canEdit ? '<button class="btn btn-danger" onclick="window.__lib.deleteFile()">删除文件</button>' : "") +
'<button class="btn" onclick="window.__lib.closePreview()" title="关闭预览">✕</button>' +
"</div>" +
"</div>" +
(f.encoding === "base64"
? '<div class="quiet">二进制文件(' + f.size + " B),不支持在线编辑</div>"
: '<textarea id="lib-ef-content" rows="16" class="textarea" ' + (canEdit ? "" : "readonly") +
">" + esc(f.content) + "</textarea>") +
(canEdit && f.encoding !== "base64"
? '<div class="modal-actions"><button class="btn btn-primary" onclick="window.__lib.saveFile()">提交修改</button></div>'
: "") +
'<div id="lib-conflict-zone"></div>' +
"</div>";
} catch (e) { fail(e); }
}
function closePreview() {
const prev = $("#lib-preview");
if (prev) { prev.style.display = "none"; prev.innerHTML = ""; }
currentFile = null;
}
async function saveFile() {
try {
const r = await api("/database/api/projects/" + current.id + "/file/commits", { method: "POST", body: {
path: currentFile.path, baseVersion: currentFile.version, content: $("#lib-ef-content").value,
}});
ok("已提交 " + r.version); await openFile(currentFile.path);
} catch (e) {
if (e.status === 409 && e.currentVersion) return showConflict(e.currentVersion);
fail(e);
}
}
async function showConflict(currentVersion) {
const { diff } = await api("/database/api/projects/" + current.id + "/file/diff?path=" +
encodeURIComponent(currentFile.path) + "&from=" + encodeURIComponent(currentFile.version) +
"&to=" + encodeURIComponent(currentVersion));
$("#lib-conflict-zone").innerHTML =
'<div class="conflict-panel">' +
'<div class="conflict-title">冲突:他人已提交 ' + esc(currentVersion) + ",差异如下(你的基版 → 最新版)</div>" +
'<pre class="diff">' + esc(diff)
.replace(/^\\+(.*)$/gm, '<span class="add">+$1</span>')
.replace(/^-(.*)$/gm, '<span class="del">-$1</span>') + "</pre>" +
'<div class="conflict-note">请人工合并后,以最新内容为全文重新提交(基版将更新为 ' + esc(currentVersion) + ")</div>" +
'<div class="modal-actions"><button class="btn" onclick="window.__lib.acceptLatest()">载入最新内容</button></div>' +
"</div>";
currentFile.version = currentVersion;
}
async function deleteFile() {
if (!confirm("删除文件 " + currentFile.path + "?")) return;
try {
await api("/database/api/projects/" + current.id + "/file?path=" + encodeURIComponent(currentFile.path),
{ method: "DELETE", body: { baseVersion: currentFile.version } });
ok("已删除"); closePreview(); renderTab();
} catch (e) { fail(e); }
}
async function showHistory() {
const { history } = await api("/database/api/projects/" + current.id + "/file/history?path=" +
encodeURIComponent(currentFile.path));
modal(
'<div class="modal-title">版本历史</div>' +
'<div style="max-height:320px;overflow-y:auto">' +
history.map((v) =>
'<div style="border-top:1px solid #F5F5F4;padding:8px 0;font-size:12px">' +
'<span class="file-meta" style="color:var(--accent)">' + esc(v.version) + "</span> " + esc(v.message) +
'<div class="quiet">' + new Date(v.committedAt).toLocaleString("zh-CN") +
(v.author ? " · " + esc(v.author) : "") + "</div></div>").join("") +
"</div>" +
'<div class="modal-actions"><button class="btn" onclick="window.__lib.closeModal()">关闭</button></div>'
);
}
/* ---------------- 导出 ---------------- */
let exportJobId = null;
async function submitExport() {
try {
const r = await api("/database/api/projects/" + current.id + "/exports", { method: "POST", body: { target: $("#lib-x-target").value } });
exportJobId = r.jobId;
$("#lib-x-status").textContent = "任务 " + r.jobId.slice(0, 8) + "… 排队中";
pollExport();
} catch (e) { fail(e); }
}
async function pollExport() {
if (!exportJobId) return;
try {
const job = await api("/database/api/exports/" + exportJobId);
const el = $("#lib-x-status");
if (!el) return;
if (job.status === "DONE") {
el.innerHTML = '完成 · <a href="/database/api/exports/' + exportJobId + '/download">下载</a>';
} else if (job.status === "FAILED") {
el.textContent = "失败:" + (job.error || "");
} else {
el.textContent = "状态:" + job.status + "…";
setTimeout(pollExport, 1000);
}
} catch { /* ignore */ }
}
/* ---------------- 暴露给内联 onclick 的操作表 ---------------- */
window.__lib = {
createChild() { createDialog(current.id); },
async renameCurrent() {
const name = prompt("新名称", current.name);
if (name === null) return;
try {
await api("/database/api/nodes/" + current.id, { method: "PATCH", body: { name } });
ok("已重命名"); await selectNode(current.id);
} catch (e) { fail(e); }
},
async deleteCurrent() {
if (!confirm("确认删除「" + current.name + "」?软删除后不可见。")) return;
try {
await api("/database/api/nodes/" + current.id, { method: "DELETE" });
ok("已删除"); current = null; await renderTree();
$("#lib-main").innerHTML = '<div class="lib-empty-hint">从左侧选择一个文件夹或项目</div>';
closePreview();
} catch (e) { fail(e); }
},
switchTab(id) { current.tab = id; renderMain(); },
async toggleIndependent() {
try {
await api("/database/api/projects/" + current.id + "/independent-permission", {
method: "PUT", body: { enabled: !current.independentPermission },
});
ok("已切换"); await selectNode(current.id);
} catch (e) { fail(e); }
},
async gTypeChanged() {
const isGroup = $("#lib-g-type").value === "GROUP";
$("#lib-g-principal").classList.toggle("hidden", isGroup);
$("#lib-g-group").classList.toggle("hidden", !isGroup);
if (isGroup && $("#lib-g-group").options.length === 0) {
const { groups } = await api("/database/api/groups/search?q=");
$("#lib-g-group").innerHTML = groups.map((g) => '<option value="' + esc(g.id) + '">' + esc(g.name) + "</option>").join("");
}
},
async addGrant() {
const type = $("#lib-g-type").value;
const principalId = type === "GROUP" ? $("#lib-g-group").value : $("#lib-g-principal").value.trim();
if (!principalId) return toast("请填写主体", "err");
try {
await api("/database/api/nodes/" + current.id + "/grants", { method: "PUT", body: {
grants: [{ principalType: type, principalId, role: $("#lib-g-role").value }],
}});
ok("已授予"); renderTab();
} catch (e) { fail(e); }
},
async revokeGrant(grantId) {
try {
await api("/database/api/nodes/" + current.id + "/grants/" + grantId, { method: "DELETE" });
ok("已收回"); renderTab();
} catch (e) { fail(e); }
},
newFileDialog, submitNewFile, openFile, closePreview, saveFile, deleteFile, showHistory,
acceptLatest() { openFile(currentFile.path); toast("已载入最新内容,请在此基础上合并", "info"); },
submitExport, closeModal,
};
/* ---------------- 初始化 ---------------- */
(async function init() {
try {
me = await api("/database/api/me");
if (me.isWebsiteAdmin) {
const btn = $("#lib-btn-new-root");
btn.classList.remove("hidden");
btn.onclick = () => createDialog(null);
}
} catch (e) { /* 401 已由 api 处理跳转 */ }
await renderTree();
})();
})();
</script>`;
}
+801
View File
@@ -0,0 +1,801 @@
/**
* /database/library —— 文件库浏览页(管理员后台的文件工具)。
*
* 服务端渲染外壳 + 浏览器端 JS 调 /database/api/*(同源 session cookie)。
* 设计令牌与全局 UI 主题(uiTheme.ts)一致。能力面全部由 API 的 404/403 表达(D8)。
*/
import type { FastifyInstance } from "fastify";
import type { PrismaClient } from "@prisma/client";
import { SESSION_COOKIE_NAME, verifySession } from "../../admin/auth/session.js";
export interface LibraryPageConfig {
readonly prisma: PrismaClient;
readonly sessionSecret: string;
}
export async function registerLibraryPage(
app: FastifyInstance,
config: LibraryPageConfig,
): Promise<void> {
app.get("/database/library", async (request, reply) => {
const raw = request.cookies[SESSION_COOKIE_NAME];
const session = raw === undefined || raw === "" ? null : verifySession(raw, config.sessionSecret);
if (session === null) return reply.redirect("/database/admin");
const user = await config.prisma.user.findUnique({
where: { id: session.userId },
select: { displayName: true },
});
if (user === null) return reply.redirect("/database/admin");
return reply.type("text/html").send(renderLibraryPage(user.displayName));
});
}
function renderLibraryPage(displayName: string): string {
const initial = displayName.slice(0, 1).replace(/[&<>"']/, "U");
return `<!doctype html>
<html lang="zh-CN">
<head>
<meta charset="utf-8"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<title>文件库</title>
<link rel="preconnect" href="https://fonts.googleapis.com"/>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600&display=swap" rel="stylesheet"/>
<style>
/* 设计令牌:与全局 UI 主题(uiTheme.ts)保持一致。 */
:root {
--bg: #FCFCFB;
--panel: #FFFFFF;
--sidebar: #F7F7F5;
--text: #1A1A18;
--text-2: #6B6A66;
--text-3: #9C9B96;
--border: #ECECE8;
--border-soft: #F1F1EE;
--accent: #1A1A18;
--accent-hover: #333330;
--selected: #EBEBE7;
--hover: #F4F4F1;
--danger: #A13A33;
--guide: #E9E9E5;
--diff-add-bg: #F3F6F2;
--diff-add-text: #4A6741;
--diff-del-bg: #F8F2F1;
--diff-del-text: #A13A33;
--mono: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
}
* { box-sizing: border-box; }
html, body { margin: 0; height: 100%; }
body {
font-family: 'Inter', -apple-system, 'Segoe UI', 'PingFang SC', 'Microsoft YaHei', sans-serif;
background: var(--bg); color: var(--text);
font-size: 14px; line-height: 1.6;
-webkit-font-smoothing: antialiased;
}
.hidden { display: none !important; }
/* 布局 */
.shell { display: flex; height: 100vh; }
.sidebar {
width: 292px; flex-shrink: 0; background: var(--sidebar);
border-right: 1px solid var(--border);
display: flex; flex-direction: column;
}
.sidebar-head {
display: flex; align-items: center; justify-content: space-between;
padding: 14px 16px; border-bottom: 1px solid var(--border);
}
.wordmark { font-size: 14px; font-weight: 600; color: var(--text); }
.sidebar-actions { display: flex; gap: 6px; }
.tree { flex: 1; overflow-y: auto; padding: 8px 8px 16px; font-size: 13px; }
.sidebar-user {
margin: 0; padding: 10px 16px;
border-top: 1px solid var(--border);
display: flex; align-items: center; gap: 8px;
font-size: 12px; color: var(--text-2);
}
.avatar {
width: 24px; height: 24px; border-radius: 50%;
background: var(--accent); color: #fff;
display: flex; align-items: center; justify-content: center;
font-size: 11px; font-weight: 600; flex-shrink: 0;
}
.main { flex: 1; overflow-y: auto; }
.main-inner { max-width: 860px; margin: 0 auto; padding: 32px 32px 64px; }
.empty-hint {
height: 100%; display: flex; align-items: center; justify-content: center;
color: var(--text-3); font-size: 13px;
}
/* 树 */
.tree-item {
display: flex; align-items: center; gap: 4px;
padding: 4px 6px; border-radius: 6px; cursor: pointer;
color: var(--text); transition: background 120ms ease;
user-select: none;
}
.tree-item:hover { background: var(--hover); }
.tree-item.selected { background: var(--selected); color: #1C1917; }
.tree-children { border-left: 1px solid var(--guide); margin-left: 15px; padding-left: 3px; }
.tree-icon { width: 16px; height: 16px; flex-shrink: 0; display: flex; align-items: center; justify-content: center; }
.tree-caret { color: var(--text-3); }
.tree-badge { margin-left: auto; padding-right: 4px; font-size: 10px; color: var(--text-3); font-family: var(--mono); }
.tree-empty { padding: 24px 12px; text-align: center; font-size: 12px; color: var(--text-3); }
/* 按钮 */
.btn {
display: inline-flex; align-items: center; gap: 4px;
padding: 5px 12px; border-radius: 8px;
border: 1px solid var(--border); background: var(--panel);
color: var(--accent); font-size: 12px; font-weight: 500;
cursor: pointer; transition: all 120ms ease; text-decoration: none;
}
.btn:hover { background: var(--hover); border-color: #D6D3D1; }
.btn-primary {
background: var(--accent); border-color: var(--accent); color: #fff;
}
.btn-primary:hover { background: var(--accent-hover); border-color: var(--accent-hover); }
.btn-danger {
border-color: transparent; background: transparent; color: var(--danger);
}
.btn-danger:hover { background: var(--diff-del-bg); border-color: transparent; }
/* 内容区 */
.crumbs { font-size: 12px; color: var(--text-3); margin-bottom: 6px; }
.crumbs span + span::before { content: " / "; color: var(--border); }
.node-head { display: flex; align-items: center; justify-content: space-between; margin-bottom: 18px; }
.node-title { font-size: 17px; font-weight: 600; color: var(--text); display: flex; align-items: center; gap: 8px; }
.tag {
font-size: 10px; font-weight: 500; font-family: var(--mono);
padding: 2px 7px; border-radius: 999px;
border: 1px solid var(--border); color: var(--text-2); background: var(--panel);
}
.tag-role { color: var(--accent); border-color: #D6D3D1; }
.node-actions { display: flex; gap: 6px; }
.tabs { display: flex; gap: 2px; border-bottom: 1px solid var(--border); margin-bottom: 18px; }
.tab {
padding: 8px 14px; font-size: 13px; color: var(--text-2);
border: none; background: none; cursor: pointer;
border-bottom: 2px solid transparent; margin-bottom: -1px;
transition: color 120ms ease;
}
.tab:hover { color: var(--text); }
.tab.active { color: var(--text); font-weight: 600; border-bottom-color: var(--accent); }
.panel {
background: var(--panel); border: 1px solid var(--border);
border-radius: 10px; padding: 20px 22px;
}
.panel + .panel, .panel + #file-editor { margin-top: 14px; }
.meta-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 10px 24px; font-size: 13px; color: var(--text-2); }
.meta-grid b { color: var(--text); font-weight: 600; }
.section-title { font-size: 13px; font-weight: 600; color: var(--text); margin-bottom: 10px; }
.section-note { font-size: 11px; color: var(--text-3); margin-top: 6px; }
/* 表格 */
table.list { width: 100%; border-collapse: collapse; font-size: 13px; }
table.list th { text-align: left; font-size: 11px; font-weight: 500; color: var(--text-3); padding: 4px 0; }
table.list td { padding: 7px 0; border-top: 1px solid #F5F5F4; }
table.list tr:first-child td { border-top: none; }
.file-row { cursor: pointer; }
.file-row:hover td { background: var(--hover); }
.file-path { font-family: var(--mono); font-size: 12px; color: var(--text); }
.file-meta { font-size: 11px; color: var(--text-3); font-family: var(--mono); }
.link-danger { color: var(--danger); font-size: 12px; background: none; border: none; cursor: pointer; padding: 0; }
.link-danger:hover { text-decoration: underline; }
/* 表单 */
.input, .select, .textarea {
width: 100%; padding: 7px 10px; border-radius: 8px;
border: 1px solid var(--border); background: var(--panel);
font-size: 13px; color: var(--text); font-family: inherit;
outline: none; transition: border-color 120ms ease;
}
.input:focus, .select:focus, .textarea:focus { border-color: var(--accent); }
.textarea { font-family: var(--mono); font-size: 12px; line-height: 1.7; resize: vertical; }
.form-label { display: block; font-size: 11px; color: var(--text-2); margin-bottom: 4px; }
.form-row { margin-bottom: 12px; }
.inline-form { display: flex; gap: 8px; align-items: center; }
.inline-form .input { flex: 1; }
/* 弹层 */
.modal-mask {
position: fixed; inset: 0; z-index: 40;
background: rgba(26, 26, 24, .3);
display: flex; align-items: center; justify-content: center; padding: 16px;
}
.modal-card {
width: 100%; max-width: 440px; background: var(--panel);
border: 1px solid var(--border); border-radius: 12px; padding: 22px;
}
.modal-title { font-size: 15px; font-weight: 600; margin-bottom: 14px; }
.modal-actions { display: flex; justify-content: flex-end; gap: 8px; margin-top: 16px; }
.toast {
border-radius: 8px; padding: 8px 14px; font-size: 12px; color: #fff;
background: #333230; max-width: 320px;
}
.toast-ok { background: #333230; }
.toast-err { background: #7E2C26; }
#toast-root { position: fixed; bottom: 16px; right: 16px; z-index: 50; display: flex; flex-direction: column; gap: 8px; }
/* 冲突与 diff */
.conflict-panel {
margin-top: 14px; border: 1px solid #E8E2C8; background: #FCFBF4;
border-radius: 10px; padding: 14px 16px;
}
.conflict-title { font-size: 13px; font-weight: 600; color: #6E6329; margin-bottom: 8px; }
.conflict-note { font-size: 11px; color: #8A8059; margin-top: 8px; }
pre.diff {
white-space: pre-wrap; font-family: var(--mono); font-size: 12px; line-height: 1.7;
background: var(--panel); border: 1px solid var(--border); border-radius: 8px; padding: 10px;
margin: 0;
}
pre.diff .add { display: block; color: var(--diff-add-text); background: var(--diff-add-bg); }
pre.diff .del { display: block; color: var(--diff-del-text); background: var(--diff-del-bg); }
.divider { border-top: 1px solid var(--border); margin: 14px 0; }
.quiet { color: var(--text-3); font-size: 12px; }
.export-status { font-size: 11px; color: var(--text-3); font-family: var(--mono); }
.export-status a { color: var(--accent); }
</style>
</head>
<body>
<div class="shell">
<aside class="sidebar">
<div class="sidebar-head">
<span class="wordmark">文件库</span>
<div class="sidebar-actions">
<button id="btn-new-root" class="btn hidden" title="新建根目录">+ 根目录</button>
<a class="btn" href="/database/dashboard">后台</a>
</div>
</div>
<div id="tree" class="tree"></div>
<div class="sidebar-user">
<div class="avatar">${initial}</div>
<span style="flex:1;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;color:var(--text)">${displayName}</span>
<button id="btn-logout" class="btn" style="padding:3px 10px;font-size:11px" title="退出登录">退出</button>
</div>
</aside>
<main class="main" id="main">
<div class="empty-hint">从左侧选择一个文件夹或项目</div>
</main>
</div>
<div id="modal-root"></div>
<div id="toast-root"></div>
<script>
/* ---------------- 基础设施 ---------------- */
const $ = (sel) => document.querySelector(sel);
const esc = (s) => String(s).replace(/&/g,"&amp;").replace(/</g,"&lt;").replace(/>/g,"&gt;").replace(/"/g,"&quot;");
async function api(path, opts = {}) {
const res = await fetch(path, {
credentials: "same-origin",
headers: opts.body ? { "Content-Type": "application/json" } : undefined,
...opts,
body: opts.body ? JSON.stringify(opts.body) : undefined,
});
if (res.status === 401) { location.href = "/database/admin"; throw new Error("unauthenticated"); }
if (res.status === 204) return null;
const text = await res.text();
const data = text ? JSON.parse(text) : null;
if (!res.ok) {
const err = (data && data.error) || { code: "unknown", message: res.statusText };
const e = new Error(err.message); e.code = err.code; e.status = res.status; Object.assign(e, err);
throw e;
}
return data;
}
function toast(msg, kind = "info") {
const el = document.createElement("div");
el.className = "toast " + (kind === "err" ? "toast-err" : "toast-ok");
el.textContent = msg;
$("#toast-root").appendChild(el);
setTimeout(() => el.remove(), 3600);
}
const ok = (m) => toast(m, "ok");
const fail = (e) => toast(e.message || String(e), "err");
function modal(html) {
const root = $("#modal-root");
root.innerHTML = '<div class="modal-mask"><div class="modal-card">' + html + "</div></div>";
root.firstElementChild.addEventListener("click", (e) => { if (e.target === e.currentTarget) closeModal(); });
}
function closeModal() { $("#modal-root").innerHTML = ""; }
/* ---------------- 状态 ---------------- */
let me = { userId: null, isWebsiteAdmin: false };
let current = null;
const expanded = new Set();
/* ---------------- 目录树 ---------------- */
/* 图标统一用固定尺寸的 inline SVG。每行几何一致:[16px 箭头槽][16px 图标槽][名称]。 */
const ICONS = {
caretRight: '<svg width="10" height="10" viewBox="0 0 24 24" fill="currentColor"><path d="M9 6l6 6-6 6z"/></svg>',
caretDown: '<svg width="10" height="10" viewBox="0 0 24 24" fill="currentColor"><path d="M6 9l6 6 6-6z"/></svg>',
folder: '<svg width="16" height="16" viewBox="0 0 24 24" fill="currentColor"><path d="M3 7a2 2 0 0 1 2-2h4l2 2h8a2 2 0 0 1 2 2v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V7Z"/></svg>',
project: '<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="M20 7l-8-4-8 4m16 0l-8 4m8-4v10l-8 4m0-10L4 7m8 4v10M4 7v10l8 4"/></svg>',
};
async function loadChildren(parentId) {
const q = parentId === null ? "" : "?parentId=" + encodeURIComponent(parentId);
return (await api("/database/api/nodes" + q)).nodes;
}
async function renderTree() {
const tree = $("#tree");
tree.innerHTML = "";
try {
const roots = await loadChildren(null);
if (roots.length === 0) {
tree.innerHTML = '<div class="tree-empty">空文件库' +
(me.isWebsiteAdmin ? " · 点上方「+ 根目录」开始" : "") + "</div>";
return;
}
for (const node of roots) tree.appendChild(await treeItem(node, 0));
} catch (e) { tree.innerHTML = '<div class="tree-empty">' + esc(e.message) + "</div>"; }
}
async function treeItem(node, depth) {
const wrap = document.createElement("div");
const row = document.createElement("div");
row.className = "tree-item" + (current && current.id === node.id ? " selected" : "");
const caret = document.createElement("span");
caret.className = "tree-icon tree-caret";
if (node.kind === "FOLDER") {
caret.innerHTML = expanded.has(node.id) ? ICONS.caretDown : ICONS.caretRight;
caret.onclick = (e) => { e.stopPropagation(); toggleExpand(node.id, wrap, depth); };
}
row.appendChild(caret);
const iconSpan = document.createElement("span");
iconSpan.className = "tree-icon";
iconSpan.style.color = node.kind === "PROJECT" ? "#1A1A18" : "#9C9B96";
iconSpan.innerHTML = node.kind === "PROJECT" ? ICONS.project : ICONS.folder;
row.appendChild(iconSpan);
const nameSpan = document.createElement("span");
nameSpan.className = "truncate";
nameSpan.textContent = node.name;
row.appendChild(nameSpan);
if (node.role !== "MANAGE") {
const badge = document.createElement("span");
badge.className = "tree-badge";
badge.textContent = node.role;
row.appendChild(badge);
}
row.onclick = () => {
if (node.kind === "FOLDER") {
if (expanded.has(node.id)) expanded.delete(node.id); else expanded.add(node.id);
}
selectNode(node.id);
};
wrap.appendChild(row);
if (node.kind === "FOLDER" && expanded.has(node.id)) {
wrap.appendChild(await childrenBlock(node.id, depth));
}
return wrap;
}
async function childrenBlock(parentId, depth) {
const block = document.createElement("div");
block.className = "tree-children";
const kids = await loadChildren(parentId);
for (const kid of kids) block.appendChild(await treeItem(kid, depth + 1));
return block;
}
async function toggleExpand(id, wrap, depth) {
if (expanded.has(id)) expanded.delete(id); else expanded.add(id);
await renderTree();
}
/* ---------------- 节点详情 ---------------- */
async function selectNode(id) {
try {
const [{ node }, { breadcrumb }] = await Promise.all([
api("/database/api/nodes/" + id),
api("/database/api/nodes/" + id + "/breadcrumb"),
]);
current = node; current.breadcrumb = breadcrumb;
await renderTree();
renderMain();
} catch (e) { fail(e); }
}
function crumbsHtml() {
return current.breadcrumb.map((c) =>
c.name === null ? "<span>…</span>" : "<span>" + esc(c.name) + "</span>"
).join("");
}
function renderMain() {
const n = current;
const canManage = n.role === "MANAGE";
const canEdit = canManage || n.role === "EDIT";
const tabs = [];
tabs.push(["detail", "概览"]);
if (n.kind === "PROJECT") tabs.push(["files", "文件"]);
if (canManage) tabs.push(["grants", "授权"]);
current.tab = current.tab && tabs.some(t => t[0] === current.tab) ? current.tab : "detail";
$("#main").innerHTML =
'<div class="main-inner">' +
'<div class="crumbs">' + crumbsHtml() + "</div>" +
'<div class="node-head">' +
'<div class="node-title">' + esc(n.name) +
'<span class="tag">' + n.kind + "</span>" +
'<span class="tag tag-role">' + n.role + "</span>" +
"</div>" +
'<div class="node-actions">' +
(canEdit && n.kind === "FOLDER" ? '<button class="btn" onclick="createChild()">+ 新建子节点</button>' : "") +
(canManage ? '<button class="btn" onclick="renameCurrent()">重命名</button>' : "") +
(canManage ? '<button class="btn btn-danger" onclick="deleteCurrent()">删除</button>' : "") +
"</div>" +
"</div>" +
'<div class="tabs">' +
tabs.map(([id, label]) =>
'<button onclick="switchTab(\\'' + id + '\\')" class="tab' +
(current.tab === id ? " active" : "") + '">' + label + "</button>").join("") +
"</div>" +
'<div id="tab-body"></div>' +
"</div>";
renderTab();
}
function switchTab(id) { current.tab = id; renderMain(); }
async function renderTab() {
const body = $("#tab-body");
if (current.tab === "files") return renderFilesTab(body);
if (current.tab === "grants") return renderGrantsTab(body);
let extra = "";
if (current.kind === "PROJECT") {
extra =
'<div class="divider"></div>' +
'<div class="inline-form" style="justify-content:flex-start">' +
'<span class="quiet">独立权限</span>' +
'<b style="font-size:13px">' + (current.independentPermission ? "开启" : "关闭") + "</b>" +
(current.role === "MANAGE"
? '<button class="btn" onclick="toggleIndependent()">' + (current.independentPermission ? "关闭" : "开启") + "</button>"
: "") +
'<span class="quiet">关闭时仅继承父级权限(创建者除外)</span>' +
"</div>" +
'<div class="divider"></div>' +
'<div class="section-title">导出</div>' +
'<div class="inline-form">' +
'<select id="x-target" class="select" style="width:auto"><option value="manifest">manifest(stub)</option></select>' +
'<button class="btn" onclick="submitExport()">开始导出</button>' +
'<span id="x-status" class="export-status"></span>' +
"</div>";
}
body.innerHTML =
'<div class="panel">' +
'<div class="meta-grid">' +
"<div>类型 <b>" + current.kind + "</b></div>" +
"<div>我的权限 <b>" + current.role + "</b></div>" +
"<div>创建时间 " + new Date(current.createdAt).toLocaleString("zh-CN") + "</div>" +
"<div>更新时间 " + new Date(current.updatedAt).toLocaleString("zh-CN") + "</div>" +
"</div>" + extra +
"</div>";
pollExport();
}
/* ---------------- 节点操作 ---------------- */
async function createChild() {
createDialog(current.id);
}
function createDialog(parentId) {
modal(
'<div class="modal-title">' + (parentId ? "新建子节点" : "新建根目录") + "</div>" +
'<div class="form-row"><label class="form-label">名称</label>' +
'<input id="f-name" class="input" placeholder="例如:物理必修一"/></div>' +
'<div class="form-row"><label class="form-label">类型</label>' +
'<select id="f-kind" class="select">' +
'<option value="FOLDER">文件夹</option><option value="PROJECT">项目(Git 仓库)</option>' +
"</select></div>" +
'<div class="modal-actions">' +
'<button class="btn" onclick="closeModal()">取消</button>' +
'<button class="btn btn-primary" onclick="submitCreate(\\'' + (parentId ?? "") + '\\')">创建</button>' +
"</div>"
);
}
async function submitCreate(parentId) {
try {
await api("/database/api/nodes", { method: "POST", body: {
parentId: parentId === "" ? null : parentId,
kind: $("#f-kind").value, name: $("#f-name").value,
}});
closeModal(); ok("已创建");
if (parentId) expanded.add(parentId);
await renderTree();
} catch (e) { fail(e); }
}
async function renameCurrent() {
const name = prompt("新名称", current.name);
if (name === null) return;
try {
await api("/database/api/nodes/" + current.id, { method: "PATCH", body: { name } });
ok("已重命名"); await selectNode(current.id);
} catch (e) { fail(e); }
}
async function deleteCurrent() {
if (!confirm("确认删除「" + current.name + "」?软删除后不可见。")) return;
try {
await api("/database/api/nodes/" + current.id, { method: "DELETE" });
ok("已删除"); current = null; await renderTree();
$("#main").innerHTML = '<div class="empty-hint">从左侧选择一个文件夹或项目</div>';
} catch (e) { fail(e); }
}
async function toggleIndependent() {
try {
await api("/database/api/projects/" + current.id + "/independent-permission", {
method: "PUT", body: { enabled: !current.independentPermission },
});
ok("已切换"); await selectNode(current.id);
} catch (e) { fail(e); }
}
/* ---------------- 授权 ---------------- */
async function renderGrantsTab(body) {
try {
const { grants } = await api("/database/api/nodes/" + current.id + "/grants");
const rows = grants.map((g) =>
"<tr>" +
"<td>" + (g.principalType === "USER" ? "👤" : "👥") + " " + esc(g.principalId) +
(g.isCreatorGrant ? ' <span class="quiet">(创建者)</span>' : "") + "</td>" +
'<td class="file-meta">' + g.role + "</td>" +
"<td style='text-align:right'>" + (g.isCreatorGrant ? "" :
'<button class="link-danger" onclick="revokeGrant(\\'' + g.id + '\\')">收回</button>') + "</td>" +
"</tr>").join("");
body.innerHTML =
'<div class="panel">' +
'<table class="list"><thead><tr><th>主体</th><th>级别</th><th></th></tr></thead>' +
"<tbody>" + rows + "</tbody></table>" +
'<div class="divider"></div>' +
'<div class="section-title">新增授权</div>' +
'<div class="inline-form">' +
'<select id="g-type" class="select" style="width:110px" onchange="gTypeChanged()">' +
'<option value="USER">用户</option><option value="GROUP">Group</option></select>' +
'<input id="g-principal" class="input" placeholder="用户 id"/>' +
'<select id="g-group" class="select hidden"></select>' +
'<select id="g-role" class="select" style="width:110px">' +
'<option value="VIEW">VIEW</option><option value="EDIT">EDIT</option><option value="MANAGE">MANAGE</option></select>' +
'<button class="btn btn-primary" onclick="addGrant()">授予</button>' +
"</div>" +
'<div class="section-note">MANAGE 仅创建者可授;创建者授权不可动(契约 8.1)</div>' +
"</div>";
} catch (e) { body.innerHTML = '<div class="panel quiet">' + esc(e.message) + "</div>"; }
}
async function gTypeChanged() {
const isGroup = $("#g-type").value === "GROUP";
$("#g-principal").classList.toggle("hidden", isGroup);
$("#g-group").classList.toggle("hidden", !isGroup);
if (isGroup && $("#g-group").options.length === 0) {
const { groups } = await api("/database/api/groups/search?q=");
$("#g-group").innerHTML = groups.map((g) => '<option value="' + esc(g.id) + '">' + esc(g.name) + "</option>").join("");
}
}
async function addGrant() {
const type = $("#g-type").value;
const principalId = type === "GROUP" ? $("#g-group").value : $("#g-principal").value.trim();
if (!principalId) return toast("请填写主体", "err");
try {
await api("/database/api/nodes/" + current.id + "/grants", { method: "PUT", body: {
grants: [{ principalType: type, principalId, role: $("#g-role").value }],
}});
ok("已授予"); renderTab();
} catch (e) { fail(e); }
}
async function revokeGrant(grantId) {
try {
await api("/database/api/nodes/" + current.id + "/grants/" + grantId, { method: "DELETE" });
ok("已收回"); renderTab();
} catch (e) { fail(e); }
}
/* ---------------- 文件 ---------------- */
let currentFile = null;
async function renderFilesTab(body) {
try {
const { files } = await api("/database/api/projects/" + current.id + "/files");
const rows = files.map((f) =>
'<tr class="file-row" onclick=\\'openFile("' + esc(f.path) + '")\\'>' +
'<td class="file-path">' + esc(f.path) + "</td>" +
'<td class="file-meta" style="text-align:right">' + f.size + " B</td></tr>").join("");
body.innerHTML =
'<div class="panel">' +
'<div class="inline-form" style="justify-content:space-between;margin-bottom:6px">' +
'<div class="section-title" style="margin:0">项目文件(' + files.length + ")</div>" +
(current.role !== "VIEW"
? '<div class="inline-form" style="gap:6px">' +
'<button class="btn" onclick="newFileDialog()">+ 新建文件</button>' +
'<button class="btn btn-primary" onclick="document.getElementById(\\'upload-input\\').click()">上传文件</button>' +
'<input id="upload-input" type="file" class="hidden" onchange="doUpload(this)"/>' +
"</div>"
: "") +
"</div>" +
(files.length === 0 ? '<div class="quiet" style="padding:20px 0;text-align:center">空仓库 · 可新建或上传文件</div>'
: '<table class="list">' + rows + "</table>") +
"</div>" +
'<div id="file-editor"></div>';
} catch (e) { body.innerHTML = '<div class="panel quiet">' + esc(e.message) + "</div>"; }
}
async function newFileDialog() {
modal(
'<div class="modal-title">新建文件</div>' +
'<div class="form-row"><label class="form-label">路径</label>' +
'<input id="nf-path" class="input" style="font-family:var(--mono)" placeholder="docs/intro.md"/></div>' +
'<div class="form-row"><label class="form-label">内容</label>' +
'<textarea id="nf-content" rows="8" class="textarea" placeholder="内容…"></textarea></div>' +
'<div class="modal-actions"><button class="btn" onclick="closeModal()">取消</button>' +
'<button class="btn btn-primary" onclick="submitNewFile()">创建</button></div>'
);
}
/* 磁盘文件上传:文本走 utf8,含 NUL 字节判为二进制走 base64(与服务端一致)。 */
function u8ToBase64(bytes) {
let bin = "";
const CHUNK = 0x8000;
for (let i = 0; i < bytes.length; i += CHUNK) {
bin += String.fromCharCode.apply(null, bytes.subarray(i, i + CHUNK));
}
return btoa(bin);
}
async function doUpload(input) {
const file = input.files && input.files[0];
input.value = "";
if (!file) return;
if (file.size > 10 * 1024 * 1024) return toast("文件超过 10MB 上限", "err");
const targetPath = prompt("保存到路径(可含目录):", "材料/" + file.name);
if (!targetPath) return;
const bytes = new Uint8Array(await file.arrayBuffer());
const isBinary = bytes.includes(0);
const body = isBinary
? { path: targetPath, content: u8ToBase64(bytes), encoding: "base64" }
: { path: targetPath, content: new TextDecoder("utf-8").decode(bytes), encoding: "utf8" };
try {
await api("/database/api/projects/" + current.id + "/file", { method: "PUT", body });
ok("已上传 " + file.name);
renderTab();
} catch (e) { fail(e); }
}
async function submitNewFile() {
try {
await api("/database/api/projects/" + current.id + "/file", { method: "PUT", body: {
path: $("#nf-path").value, content: $("#nf-content").value,
}});
closeModal(); ok("已创建"); renderTab();
} catch (e) { fail(e); }
}
async function openFile(path) {
try {
const f = await api("/database/api/projects/" + current.id + "/file?path=" + encodeURIComponent(path));
currentFile = f;
const canEdit = current.role !== "VIEW";
$("#file-editor").innerHTML =
'<div class="panel">' +
'<div class="inline-form" style="justify-content:space-between;margin-bottom:10px">' +
'<span class="file-meta">' + esc(f.path) + " @ " + esc(f.version) + "</span>" +
'<div class="inline-form" style="gap:6px">' +
'<a class="btn" href="/database/api/projects/' + current.id + '/file/raw?path=' +
encodeURIComponent(f.path) + '" download>下载</a>' +
'<button class="btn" onclick="showHistory()">历史</button>' +
(canEdit ? '<button class="btn btn-danger" onclick="deleteFile()">删除文件</button>' : "") +
"</div>" +
"</div>" +
(f.encoding === "base64"
? '<div class="quiet">二进制文件(' + f.size + " B),不支持在线编辑</div>"
: '<textarea id="ef-content" rows="14" class="textarea" ' + (canEdit ? "" : "readonly") +
">" + esc(f.content) + "</textarea>") +
(canEdit && f.encoding !== "base64"
? '<div class="modal-actions"><button class="btn btn-primary" onclick="saveFile()">提交修改</button></div>'
: "") +
'<div id="conflict-zone"></div>' +
"</div>";
} catch (e) { fail(e); }
}
async function saveFile() {
try {
const r = await api("/database/api/projects/" + current.id + "/file/commits", { method: "POST", body: {
path: currentFile.path, baseVersion: currentFile.version, content: $("#ef-content").value,
}});
ok("已提交 " + r.version); await openFile(currentFile.path);
} catch (e) {
if (e.status === 409 && e.currentVersion) return showConflict(e.currentVersion);
fail(e);
}
}
async function showConflict(currentVersion) {
const { diff } = await api("/database/api/projects/" + current.id + "/file/diff?path=" +
encodeURIComponent(currentFile.path) + "&from=" + encodeURIComponent(currentFile.version) +
"&to=" + encodeURIComponent(currentVersion));
$("#conflict-zone").innerHTML =
'<div class="conflict-panel">' +
'<div class="conflict-title">冲突:他人已提交 ' + esc(currentVersion) + ",差异如下(你的基版 → 最新版)</div>" +
'<pre class="diff">' + esc(diff)
.replace(/^\\+(.*)$/gm, '<span class="add">+$1</span>')
.replace(/^-(.*)$/gm, '<span class="del">-$1</span>') + "</pre>" +
'<div class="conflict-note">请人工合并后,以最新内容为全文重新提交(基版将更新为 ' + esc(currentVersion) + ")</div>" +
'<div class="modal-actions"><button class="btn" onclick="acceptLatest(\\'' + esc(currentVersion) + '\\')">载入最新内容</button></div>' +
"</div>";
currentFile.version = currentVersion;
}
async function acceptLatest() { await openFile(currentFile.path); toast("已载入最新内容,请在此基础上合并", "info"); }
async function deleteFile() {
if (!confirm("删除文件 " + currentFile.path + "?")) return;
try {
await api("/database/api/projects/" + current.id + "/file?path=" + encodeURIComponent(currentFile.path),
{ method: "DELETE", body: { baseVersion: currentFile.version } });
ok("已删除"); currentFile = null; renderTab();
} catch (e) { fail(e); }
}
async function showHistory() {
const { history } = await api("/database/api/projects/" + current.id + "/file/history?path=" +
encodeURIComponent(currentFile.path));
modal(
'<div class="modal-title">版本历史</div>' +
'<div style="max-height:320px;overflow-y:auto">' +
history.map((v) =>
'<div style="border-top:1px solid #F5F5F4;padding:8px 0;font-size:12px">' +
'<span class="file-meta" style="color:var(--accent)">' + esc(v.version) + "</span> " + esc(v.message) +
'<div class="quiet">' + new Date(v.committedAt).toLocaleString("zh-CN") +
(v.author ? " · " + esc(v.author) : "") + "</div></div>").join("") +
"</div>" +
'<div class="modal-actions"><button class="btn" onclick="closeModal()">关闭</button></div>'
);
}
/* ---------------- 导出 ---------------- */
let exportJobId = null;
async function submitExport() {
try {
const r = await api("/database/api/projects/" + current.id + "/exports", { method: "POST", body: { target: $("#x-target").value } });
exportJobId = r.jobId;
$("#x-status").textContent = "任务 " + r.jobId.slice(0, 8) + "… 排队中";
pollExport();
} catch (e) { fail(e); }
}
async function pollExport() {
if (!exportJobId) return;
try {
const job = await api("/database/api/exports/" + exportJobId);
const el = $("#x-status");
if (!el) return;
if (job.status === "DONE") {
el.innerHTML = '完成 · <a href="/database/api/exports/' + exportJobId + '/download">下载</a>';
} else if (job.status === "FAILED") {
el.textContent = "失败:" + (job.error || "");
} else {
el.textContent = "状态:" + job.status + "…";
setTimeout(pollExport, 1000);
}
} catch { /* job 可能属于别的项目 */ }
}
/* ---------------- 启动 ---------------- */
(async function init() {
const logoutBtn = $("#btn-logout");
if (logoutBtn) {
logoutBtn.addEventListener("click", async () => {
try { await fetch("/auth/logout", { method: "POST", credentials: "same-origin" }); } catch {}
location.href = "/database/admin";
});
}
try {
me = await api("/database/api/me");
if (me.isWebsiteAdmin) {
const btn = $("#btn-new-root");
btn.classList.remove("hidden");
btn.onclick = () => createDialog(null);
}
} catch (e) { /* 401 已由 api 处理跳转 */ }
await renderTree();
})();
</script>
</body>
</html>`;
}
+129
View File
@@ -0,0 +1,129 @@
/**
* 老师端用户前端托管(标准前后端分离):
* GET /app/* — filelib-web(Svelte SPA)构建产物静态托管 + SPA 回退
* GET /database/api/login-info — 登录页配置(org slug / dev 开关)
* GET /app/dev-login{,-teacher} — DEV ONLY 一键登录(管理员 / 普通老师)
*
* 服务端不再渲染老师端页面;页面由独立前端工程 hub/filelib-web 产出。
*/
import fs from "node:fs";
import path from "node:path";
import fastifyStatic from "@fastify/static";
import type { FastifyInstance } from "fastify";
import type { PrismaClient } from "@prisma/client";
import { SESSION_COOKIE_NAME, signSession } from "../../admin/auth/session.js";
export interface TeacherAppConfig {
readonly prisma: PrismaClient;
readonly sessionSecret: string;
/** 飞书 OAuth 链接按 silo org slug 构造。 */
readonly siloOrganizationSlug: string;
/** DEV ONLY(双重门禁,见 database/plugin.ts):一键登录端点与按钮同进同退。 */
readonly allowDevLoginBypass: boolean;
}
export async function registerTeacherApp(
app: FastifyInstance,
config: TeacherAppConfig,
): Promise<void> {
// 登录页配置(公开;org slug 本就在 OAuth URL 中,不构成敏感信息)。
app.get("/database/api/login-info", async () => ({
orgSlug: config.siloOrganizationSlug,
devLoginEnabled: config.allowDevLoginBypass,
}));
// 标准分离:静态托管 SPA 构建产物;非文件路径回退 index.html 交给前端。
const distDir = path.resolve(import.meta.dirname, "../../../filelib-web/dist");
if (fs.existsSync(path.join(distDir, "index.html"))) {
await app.register(fastifyStatic, { root: distDir, prefix: "/app/", decorateReply: true });
app.setNotFoundHandler((request, reply) => {
if (request.url.startsWith("/app")) {
return reply.sendFile("index.html", distDir);
}
return reply.status(404).send({ error: { code: "not_found", message: "not found" } });
});
} else {
app.log.warn({ distDir }, "filelib-web dist not found; build it with `npm run build --prefix filelib-web`");
app.get("/app", async (_request, reply) =>
reply
.status(503)
.type("text/plain")
.send("filelib-web 未构建。请先运行 npm run build --prefix hub/filelib-web"),
);
}
if (!config.allowDevLoginBypass) return;
registerDevLogins(app, config);
}
/** DEV ONLY:普通老师一键登录端点(双重门禁见 plugin.ts)。
* 老师端不提供管理员登录 —— 管理员从 /database/admin 进。 */
function registerDevLogins(app: FastifyInstance, config: TeacherAppConfig): void {
app.get("/app/dev-login-teacher", async (_request, reply) => {
const prisma = config.prisma;
const organization = await prisma.organization.findFirst({
where: { status: "ACTIVE" },
select: { id: true },
});
if (organization === null) {
return reply.status(404).send({ error: { code: "no_org", message: "no active organization" } });
}
let membership = await prisma.organizationMembership.findFirst({
where: { organizationId: organization.id, role: "MEMBER", revokedAt: null },
select: { userId: true, organizationId: true },
});
if (membership === null) {
const teacher = await prisma.user.upsert({
where: { feishuOpenId: "ou_dev_teacher" },
update: {},
create: { feishuOpenId: "ou_dev_teacher", displayName: "测试老师" },
});
await prisma.organizationMembership.create({
data: { organizationId: organization.id, userId: teacher.id, role: "MEMBER" },
});
membership = { userId: teacher.id, organizationId: organization.id };
}
const connection = await prisma.organizationFeishuApplicationConnection.findFirst({
where: { organizationId: membership.organizationId, status: "ACTIVE" },
select: { id: true, organizationId: true },
});
if (connection === null) {
return reply.status(404).send({ error: { code: "no_connection", message: "no active Feishu connection for org" } });
}
let identity = await prisma.feishuUserIdentity.findFirst({
where: { userId: membership.userId, connectionId: connection.id },
select: { id: true, connectionId: true },
});
if (identity === null) {
identity = await prisma.feishuUserIdentity.create({
data: { connectionId: connection.id, userId: membership.userId, openId: "ou_dev_teacher" },
select: { id: true, connectionId: true },
});
}
setSessionCookie(reply, config.sessionSecret, membership.userId, identity.id, identity.connectionId, connection.organizationId);
reply.log.warn({ userId: membership.userId }, "DEV teacher-app login bypass (regular teacher) used");
return reply.redirect("/app");
});
}
function setSessionCookie(
reply: { setCookie: (name: string, value: string, opts: Record<string, unknown>) => void },
secret: string,
userId: string,
feishuIdentityId: string,
feishuConnectionId: string,
feishuOrganizationId: string,
): void {
const token = signSession({ userId, feishuIdentityId, feishuConnectionId, feishuOrganizationId }, secret);
reply.setCookie(SESSION_COOKIE_NAME, token, {
path: "/",
httpOnly: true,
sameSite: "lax",
secure: false,
maxAge: 7 * 24 * 60 * 60,
});
}
+138
View File
@@ -0,0 +1,138 @@
/**
* 全局共享 UI 主题(老师端 /app、管理员后台 /database、文件页 /database/library)。
*
* 方向:高级简约、零视觉疲劳 —— 暖白底、发丝边框、近黑主按钮(唯一强调色)、
* 无渐变、无彩色、无阴影(弹层仅一丝)、Inter 全界面、克制的动效。
* 所有页面的设计令牌收敛于此,调色只改这里。
*/
export const UI_HEAD_FONTS = `
<link rel="preconnect" href="https://fonts.googleapis.com"/>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600&display=swap" rel="stylesheet"/>
`;
export const UI_THEME_CSS = `
:root {
--bg: #FCFCFB;
--panel: #FFFFFF;
--sidebar: #F7F7F5;
--text: #1A1A18;
--text-2: #6B6A66;
--text-3: #9C9B96;
--border: #ECECE8;
--border-soft: #F1F1EE;
--hover: #F4F4F1;
--selected: #EBEBE7;
--accent: #1A1A18;
--accent-hover: #333330;
--danger: #A13A33;
--guide: #E9E9E5;
--diff-add-bg: #F3F6F2;
--diff-add-text: #4A6741;
--diff-del-bg: #F8F2F1;
--diff-del-text: #A13A33;
--sans: 'Inter', -apple-system, 'Segoe UI', 'PingFang SC', 'Microsoft YaHei', sans-serif;
--mono: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
--shadow-pop: 0 4px 20px rgba(26,26,24,.07);
}
* { box-sizing: border-box; }
html, body { margin: 0; height: 100%; }
body {
font-family: var(--sans);
background: var(--bg); color: var(--text);
font-size: 14px; line-height: 1.65;
-webkit-font-smoothing: antialiased;
}
.hidden { display: none !important; }
h1, h2, h3 { margin: 0; }
a { color: var(--text); text-decoration: none; }
a:hover { text-decoration: underline; }
/* 按钮:近黑实心(主)/ 发丝边幽灵(次)/ 文字型(危险) */
.btn {
display: inline-flex; align-items: center; gap: 5px;
padding: 6px 14px; border-radius: 8px;
border: 1px solid var(--border); background: var(--panel);
color: var(--text); font-size: 12.5px; font-weight: 500;
cursor: pointer; transition: all 120ms ease; text-decoration: none;
}
.btn:hover { background: var(--hover); text-decoration: none; }
.btn-primary {
background: var(--accent); border-color: var(--accent); color: #fff;
}
.btn-primary:hover { background: var(--accent-hover); border-color: var(--accent-hover); }
.btn-danger { border-color: transparent; background: transparent; color: var(--danger); }
.btn-danger:hover { background: #A13A3312; }
/* 面板与标签 */
.panel {
background: var(--panel); border: 1px solid var(--border-soft);
border-radius: 10px; padding: 20px 22px;
}
.tag {
font-size: 10.5px; font-weight: 500; font-family: var(--mono);
padding: 2px 8px; border-radius: 999px;
border: 1px solid var(--border-soft); color: var(--text-3); background: var(--panel);
}
.tag-role { color: var(--text-2); border-color: var(--border); }
/* 页签 */
.tabs { display: flex; gap: 2px; border-bottom: 1px solid var(--border-soft); margin-bottom: 18px; }
.tab {
padding: 8px 14px; font-size: 13px; color: var(--text-3);
border: none; background: none; cursor: pointer;
border-bottom: 2px solid transparent; margin-bottom: -1px;
transition: color 120ms ease;
}
.tab:hover { color: var(--text); }
.tab.active { color: var(--text); font-weight: 600; border-bottom-color: var(--accent); }
/* 表单 */
.input, .select, .textarea {
width: 100%; padding: 7px 11px; border-radius: 8px;
border: 1px solid var(--border); background: var(--panel);
font-size: 13px; color: var(--text); font-family: inherit;
outline: none; transition: border-color 120ms ease;
}
.input:focus, .select:focus, .textarea:focus { border-color: var(--accent); }
.textarea { font-family: var(--mono); font-size: 12.5px; line-height: 1.75; resize: vertical; }
.form-label { display: block; font-size: 11.5px; color: var(--text-3); margin-bottom: 4px; }
.form-row { margin-bottom: 12px; }
.inline-form { display: flex; gap: 8px; align-items: center; }
.inline-form .input { flex: 1; }
/* 表格 */
table.list { width: 100%; border-collapse: collapse; font-size: 13px; }
table.list th { text-align: left; font-size: 11.5px; font-weight: 500; color: var(--text-3); padding: 4px 0; }
table.list td { padding: 8px 0; border-top: 1px solid var(--border-soft); }
table.list tr:first-child td { border-top: none; }
/* 弹层 */
.modal-mask {
position: fixed; inset: 0; z-index: 40;
background: rgba(26,26,24,.3);
display: flex; align-items: center; justify-content: center; padding: 16px;
}
.modal-card {
width: 100%; max-width: 430px; background: var(--panel);
border: 1px solid var(--border-soft); border-radius: 14px; padding: 22px;
box-shadow: var(--shadow-pop);
}
.modal-title { font-size: 15px; font-weight: 600; margin-bottom: 14px; }
.modal-actions { display: flex; justify-content: flex-end; gap: 8px; margin-top: 16px; }
.toast {
border-radius: 8px; padding: 8px 16px; font-size: 12.5px; color: #fff;
background: #333230; max-width: 330px;
}
.toast-err { background: #7E2C26; }
#toast-root { position: fixed; bottom: 18px; right: 18px; z-index: 50; display: flex; flex-direction: column; gap: 8px; }
.quiet { color: var(--text-3); font-size: 12.5px; }
.divider { border-top: 1px solid var(--border-soft); margin: 14px 0; }
.section-title { font-size: 13px; font-weight: 600; margin-bottom: 10px; }
.section-note { font-size: 11.5px; color: var(--text-3); margin-top: 6px; }
.file-path { font-family: var(--mono); font-size: 12.5px; color: var(--text); }
.file-meta { font-size: 11px; color: var(--text-3); font-family: var(--mono); }
.link-danger { color: var(--danger); font-size: 12.5px; background: none; border: none; cursor: pointer; padding: 0; }
.link-danger:hover { text-decoration: underline; }
`;
+227
View File
@@ -0,0 +1,227 @@
/**
* 文件库 HTTP 端点集成测试(真实 Postgres + Fastify inject)。
* 覆盖:401 门禁、D8(404/403)、8.1 授权矩阵、文件冲突流(409+审计)、导出状态机。
* 运行前提:本地 PG 且已 migrate(同 filelib-tree.test.ts)。
*/
import { afterAll, beforeEach, describe, expect, it } from "vitest";
import Fastify, { type FastifyInstance } from "fastify";
import fastifyCookie from "@fastify/cookie";
import { prisma, resetDb, DEFAULT_ORG_ID } from "./helpers.js";
import { signSession, SESSION_COOKIE_NAME } from "../../src/admin/auth/session.js";
import { registerFileLibRoutes } from "../../src/database/routes/filelibRoutes.js";
import { registerFileRoutes } from "../../src/database/routes/fileRoutes.js";
import { createStaticGroupResolver } from "../../src/database/filelib/groupResolver.js";
import { createInMemoryVersionStore } from "../../src/database/filelib/versionStore.js";
import { createManifestStubAdapter } from "../../src/database/filelib/exportService.js";
import type { FileLibRouteDeps } from "../../src/database/filelib/routeShared.js";
const SECRET = "filelib-test-secret";
let app: FastifyInstance;
let deps: FileLibRouteDeps;
function cookie(userId: string, openId: string): string {
return `${SESSION_COOKIE_NAME}=${signSession({ userId, feishuOpenId: openId }, SECRET)}`;
}
const ADMIN_COOKIE = () => cookie("u_admin", "ou_admin");
const ALICE_COOKIE = () => cookie("u_alice", "ou_alice");
const BOB_COOKIE = () => cookie("u_bob", "ou_bob");
async function seedUsers(): Promise<void> {
await prisma.user.create({ data: { id: "u_admin", feishuOpenId: "ou_admin", displayName: "Admin" } });
await prisma.user.create({ data: { id: "u_alice", feishuOpenId: "ou_alice", displayName: "Alice" } });
await prisma.user.create({ data: { id: "u_bob", feishuOpenId: "ou_bob", displayName: "Bob" } });
await prisma.organizationMembership.create({
data: { organizationId: DEFAULT_ORG_ID, userId: "u_admin", role: "OWNER" },
});
await prisma.organizationMembership.create({
data: { organizationId: DEFAULT_ORG_ID, userId: "u_alice", role: "MEMBER" },
});
await prisma.organizationMembership.create({
data: { organizationId: DEFAULT_ORG_ID, userId: "u_bob", role: "MEMBER" },
});
}
beforeEach(async () => {
await resetDb();
await seedUsers();
const versionStore = createInMemoryVersionStore();
deps = {
prisma,
sessionSecret: SECRET,
organizationId: DEFAULT_ORG_ID,
storageRoot: "/tmp/filelib-it",
groupResolver: createStaticGroupResolver({}),
versionStore,
exportAdapters: [createManifestStubAdapter(versionStore)],
};
app = Fastify({ logger: false });
await app.register(fastifyCookie);
await registerFileLibRoutes(app, deps);
await registerFileRoutes(app, deps);
await app.ready();
});
afterAll(async () => {
await app?.close();
});
async function createRoot(cookieHeader: string, name = "物理"): Promise<string> {
const res = await app.inject({
method: "POST", url: "/database/api/nodes",
headers: { cookie: cookieHeader },
payload: { parentId: null, kind: "FOLDER", name },
});
expect(res.statusCode).toBe(201);
return res.json().node.id as string;
}
describe("filelib http · 门禁与 D8", () => {
it("无 session → 401", async () => {
const res = await app.inject({ method: "GET", url: "/database/api/nodes" });
expect(res.statusCode).toBe(401);
});
it("/me:OWNER → isWebsiteAdmin=true;MEMBER → false", async () => {
const admin = await app.inject({ method: "GET", url: "/database/api/me", headers: { cookie: ADMIN_COOKIE() } });
expect(admin.json().isWebsiteAdmin).toBe(true);
const alice = await app.inject({ method: "GET", url: "/database/api/me", headers: { cookie: ALICE_COOKIE() } });
expect(alice.json().isWebsiteAdmin).toBe(false);
});
it("root 创建:MEMBER 403;无权限节点 GET 404、VIEW 越权 DELETE 403", async () => {
const forbidden = await app.inject({
method: "POST", url: "/database/api/nodes",
headers: { cookie: ALICE_COOKIE() },
payload: { parentId: null, kind: "FOLDER", name: "越权" },
});
expect(forbidden.statusCode).toBe(403);
const rootId = await createRoot(ADMIN_COOKIE());
const notFound = await app.inject({ method: "GET", url: `/database/api/nodes/${rootId}`, headers: { cookie: BOB_COOKIE() } });
expect(notFound.statusCode).toBe(404);
await app.inject({
method: "PUT", url: `/database/api/nodes/${rootId}/grants`,
headers: { cookie: ADMIN_COOKIE() },
payload: { grants: [{ principalType: "USER", principalId: "u_alice", role: "VIEW" }] },
});
const visible = await app.inject({ method: "GET", url: `/database/api/nodes/${rootId}`, headers: { cookie: ALICE_COOKIE() } });
expect(visible.statusCode).toBe(200);
expect(visible.json().node.role).toBe("VIEW");
const denied = await app.inject({ method: "DELETE", url: `/database/api/nodes/${rootId}`, headers: { cookie: ALICE_COOKIE() } });
expect(denied.statusCode).toBe(403);
});
});
describe("filelib http · 8.1 授权矩阵", () => {
it("非创建者的 MANAGE 授 MANAGE → 403;创建者可授;creator grant 不可收回", async () => {
const rootId = await createRoot(ADMIN_COOKIE());
// admin(创建者)授 alice MANAGE → 允许
const put1 = await app.inject({
method: "PUT", url: `/database/api/nodes/${rootId}/grants`,
headers: { cookie: ADMIN_COOKIE() },
payload: { grants: [{ principalType: "USER", principalId: "u_alice", role: "MANAGE" }] },
});
expect(put1.statusCode).toBe(200);
// alice(MANAGE 但非创建者)授 bob MANAGE → 403
const put2 = await app.inject({
method: "PUT", url: `/database/api/nodes/${rootId}/grants`,
headers: { cookie: ALICE_COOKIE() },
payload: { grants: [{ principalType: "USER", principalId: "u_bob", role: "MANAGE" }] },
});
expect(put2.statusCode).toBe(403);
expect(put2.json().error.code).toBe("only_creator_can_grant_manage");
// alice 授 bob EDIT → 允许
const put3 = await app.inject({
method: "PUT", url: `/database/api/nodes/${rootId}/grants`,
headers: { cookie: ALICE_COOKIE() },
payload: { grants: [{ principalType: "USER", principalId: "u_bob", role: "EDIT" }] },
});
expect(put3.statusCode).toBe(200);
// creator grant 不可收回
const list = await app.inject({ method: "GET", url: `/database/api/nodes/${rootId}/grants`, headers: { cookie: ADMIN_COOKIE() } });
const creatorGrant = list.json().grants.find((g: { isCreatorGrant: boolean }) => g.isCreatorGrant);
const revoke = await app.inject({
method: "DELETE", url: `/database/api/nodes/${rootId}/grants/${creatorGrant.id}`,
headers: { cookie: ADMIN_COOKIE() },
});
expect(revoke.statusCode).toBe(403);
expect(revoke.json().error.code).toBe("cannot_touch_creator");
});
});
describe("filelib http · 文件冲突流", () => {
it("上传→读→提交→409 冲突→conflict 审计落库", async () => {
const res = await app.inject({
method: "POST", url: "/database/api/nodes",
headers: { cookie: ADMIN_COOKIE() },
payload: { parentId: null, kind: "PROJECT", name: "TH-141" },
});
const projectId = res.json().node.id as string;
const up = await app.inject({
method: "PUT", url: `/database/api/projects/${projectId}/file`,
headers: { cookie: ADMIN_COOKIE() },
payload: { path: "docs/a.md", content: "第一版" },
});
expect(up.statusCode).toBe(201);
const read = await app.inject({
method: "GET", url: `/database/api/projects/${projectId}/file?path=docs/a.md`,
headers: { cookie: ADMIN_COOKIE() },
});
expect(read.json().content).toBe("第一版");
const v1 = read.json().version as string;
const commit = await app.inject({
method: "POST", url: `/database/api/projects/${projectId}/file/commits`,
headers: { cookie: ADMIN_COOKIE() },
payload: { path: "docs/a.md", baseVersion: v1, content: "第二版" },
});
expect(commit.statusCode).toBe(200);
const conflict = await app.inject({
method: "POST", url: `/database/api/projects/${projectId}/file/commits`,
headers: { cookie: ADMIN_COOKIE() },
payload: { path: "docs/a.md", baseVersion: v1, content: "幽灵版" },
});
expect(conflict.statusCode).toBe(409);
expect(conflict.json().error.currentVersion).toBe(commit.json().version);
const audit = await prisma.auditEntry.findFirst({
where: { organizationId: DEFAULT_ORG_ID, action: "file.conflict_detected" },
});
expect(audit).not.toBeNull();
});
});
describe("filelib http · 导出状态机", () => {
it("提交 → 轮询 DONE → 下载 manifest", async () => {
const res = await app.inject({
method: "POST", url: "/database/api/nodes",
headers: { cookie: ADMIN_COOKIE() },
payload: { parentId: null, kind: "PROJECT", name: "导出源" },
});
const projectId = res.json().node.id as string;
const submit = await app.inject({
method: "POST", url: `/database/api/projects/${projectId}/exports`,
headers: { cookie: ADMIN_COOKIE() },
payload: { target: "manifest" },
});
expect(submit.statusCode).toBe(202);
const jobId = submit.json().jobId as string;
let job: { status: string } = { status: "QUEUED" };
for (let i = 0; i < 50 && job.status !== "DONE" && job.status !== "FAILED"; i += 1) {
await new Promise((r) => setTimeout(r, 50));
const poll = await app.inject({ method: "GET", url: `/database/api/exports/${jobId}`, headers: { cookie: ADMIN_COOKIE() } });
job = poll.json();
}
expect(job.status).toBe("DONE");
const download = await app.inject({ method: "GET", url: `/database/api/exports/${jobId}/download`, headers: { cookie: ADMIN_COOKIE() } });
expect(download.statusCode).toBe(200);
expect(download.body).toContain("manifest");
});
});
+183
View File
@@ -0,0 +1,183 @@
/**
* 文件库树服务集成测试(真实 Postgres)。
* 覆盖:root 创建规则、父级 EDIT+ 创建、D8(404/403)、D11 toggle 冻结、
* D12 move(环拒绝/目标授权/并发对移)、D14 兄弟名冲突、D15 祖先删除整支隐藏、
* D17 breadcrumb 占位、provisioning 状态机、审计落库。
* 运行前提:本地 PG(paradigm:paradigm@127.0.0.1:5432/cph_hub_test)且已 migrate。
*/
import { beforeEach, describe, expect, it } from "vitest";
import { prisma, resetDb, DEFAULT_ORG_ID } from "./helpers.js";
import {
createNode,
renameNode,
moveNode,
softDeleteNode,
breadcrumb,
getEffectiveRole,
listChildren,
type FileLibActor,
type TreeServiceDeps,
} from "../../src/database/filelib/treeService.js";
import { createStaticGroupResolver } from "../../src/database/filelib/groupResolver.js";
import { createInMemoryVersionStore } from "../../src/database/filelib/versionStore.js";
import { FileLibError } from "../../src/database/filelib/model.js";
const ADMIN: FileLibActor = { userId: "u_admin", isWebsiteAdmin: true };
const ALICE: FileLibActor = { userId: "u_alice", isWebsiteAdmin: false };
const BOB: FileLibActor = { userId: "u_bob", isWebsiteAdmin: false };
function deps(): TreeServiceDeps {
return {
prisma,
groupResolver: createStaticGroupResolver({ u_bob: ["g_physics"] }),
versionStore: createInMemoryVersionStore(),
organizationId: DEFAULT_ORG_ID,
storageRoot: "/tmp/filelib-test",
};
}
async function seedUsers(): Promise<void> {
for (const [id, openId] of [["u_admin", "ou_admin"], ["u_alice", "ou_alice"], ["u_bob", "ou_bob"]] as const) {
await prisma.user.create({ data: { id, feishuOpenId: openId, displayName: id } });
}
}
beforeEach(async () => {
await resetDb();
await seedUsers();
});
describe("treeService · 创建规则", () => {
it("root 仅网站管理员可建;创建者自动 MANAGE", async () => {
await expect(createNode(deps(), ALICE, { parentId: null, kind: "FOLDER", name: "根" }))
.rejects.toMatchObject({ statusCode: 403 });
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
expect(await getEffectiveRole(deps(), ADMIN, root.id)).toBe("MANAGE");
});
it("非 root:父级无权限 404、仅 VIEW 403、EDIT+ 可建;项目下禁止子节点", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
await expect(createNode(deps(), BOB, { parentId: root.id, kind: "FOLDER", name: "必修一" }))
.rejects.toMatchObject({ statusCode: 404 });
await createNode(deps(), ADMIN, {
parentId: null, kind: "FOLDER", name: "化学",
grants: [{ principalType: "USER", principalId: "u_alice", role: "VIEW" }],
});
await expect(createNode(deps(), ALICE, { parentId: (await listChildren(deps(), ALICE, null))[0]!.id, kind: "FOLDER", name: "x" }))
.rejects.toMatchObject({ statusCode: 403 });
const child = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "必修一" });
const project = await createNode(deps(), ADMIN, { parentId: child.id, kind: "PROJECT", name: "TH-141" });
expect(project.provisionStatus).toBe("READY"); // provisioning 状态机:mock init 后 READY
expect(project.storageDir).toContain(project.id);
await expect(createNode(deps(), ADMIN, { parentId: project.id, kind: "FOLDER", name: "非法" }))
.rejects.toMatchObject({ statusCode: 400, code: "invalid_parent" });
});
it("D14:活跃兄弟名大小写不敏感唯一 → 409", async () => {
await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "Physics" });
await expect(createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "physics" }))
.rejects.toMatchObject({ statusCode: 409, code: "name_conflict" });
});
});
describe("treeService · D11 独立权限开关", () => {
it("关闭时项目级非创建者 grant 冻结,创建者仍 MANAGE", async () => {
const project = await createNode(deps(), ADMIN, {
parentId: null, kind: "PROJECT", name: "TH-141",
grants: [{ principalType: "USER", principalId: "u_alice", role: "EDIT" }],
});
await expect(getEffectiveRole(deps(), ALICE, project.id))
.rejects.toMatchObject({ statusCode: 404 }); // 冻结 = 无权限 = D8 不可见
expect(await getEffectiveRole(deps(), ADMIN, project.id)).toBe("MANAGE");
await prisma.fileLibProjectSettings.update({
where: { nodeId: project.id },
data: { independentPermissionsEnabled: true },
});
expect(await getEffectiveRole(deps(), ALICE, project.id)).toBe("EDIT"); // 恢复
});
});
describe("treeService · rename / move / delete", () => {
it("rename 需 MANAGE;兄弟名冲突 409", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "必修一" });
const other = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "必修二" });
await expect(renameNode(deps(), ADMIN, other.id, "必修一"))
.rejects.toMatchObject({ statusCode: 409 });
await expect(renameNode(deps(), BOB, other.id, "改名"))
.rejects.toMatchObject({ statusCode: 404 });
expect((await renameNode(deps(), ADMIN, other.id, "选修")).name).toBe("选修");
});
it("move:拒绝移入自己的子树;目标父需 EDIT+;Group 授权链路生效", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
const a = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "A" });
const b = await createNode(deps(), ADMIN, { parentId: a.id, kind: "FOLDER", name: "B" });
await expect(moveNode(deps(), ADMIN, a.id, b.id))
.rejects.toMatchObject({ statusCode: 400, code: "move_into_own_subtree" });
// bob 在 g_physics 组;组在 root 上有 EDIT → bob 可把 B 移到 root(D12:本节点 MANAGE + 目标父 EDIT)
await createNode(deps(), ADMIN, {
parentId: null, kind: "FOLDER", name: "共享区",
grants: [{ principalType: "GROUP", principalId: "g_physics", role: "EDIT" }],
});
const shared = (await listChildren(deps(), ADMIN, null)).find((n) => n.name === "共享区")!;
await expect(moveNode(deps(), BOB, b.id, shared.id))
.rejects.toMatchObject({ statusCode: 404 }); // bob 对 B 无 MANAGE → 404
await prisma.fileLibGrant.create({
data: { organizationId: DEFAULT_ORG_ID, nodeId: b.id, principalType: "GROUP", principalId: "g_physics", role: "MANAGE" },
});
const moved = await moveNode(deps(), BOB, b.id, shared.id);
expect(moved.parentId).toBe(shared.id);
const sharedRow = await prisma.fileLibNode.findUnique({ where: { id: shared.id } });
expect(moved.pathIds).toBe(`${sharedRow!.pathIds}/${b.id}`);
});
it("move 到 root 需网站管理员", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
const a = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "A" });
await createNode(deps(), ADMIN, {
parentId: null, kind: "FOLDER", name: "给爱丽丝",
grants: [{ principalType: "USER", principalId: "u_alice", role: "MANAGE" }],
});
await expect(moveNode(deps(), ALICE, a.id, null))
.rejects.toMatchObject({ statusCode: 404 }); // ALICE 对 a 无权限
await expect(moveNode(deps(), ADMIN, a.id, null)).resolves.toMatchObject({ parentId: null });
});
it("D15:祖先删除 → 整支后代不可见(404)", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
const a = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "A" });
await softDeleteNode(deps(), ADMIN, root.id);
await expect(getEffectiveRole(deps(), ADMIN, a.id)).rejects.toMatchObject({ statusCode: 404 });
await expect(renameNode(deps(), ADMIN, a.id, "B")).rejects.toMatchObject({ statusCode: 404 });
});
});
describe("treeService · D17 breadcrumb", () => {
it("无 View 的祖先只给占位,不泄露名字", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
const a = await createNode(deps(), ADMIN, { parentId: root.id, kind: "FOLDER", name: "A" });
await prisma.fileLibGrant.create({
data: { organizationId: DEFAULT_ORG_ID, nodeId: a.id, principalType: "USER", principalId: "u_alice", role: "VIEW" },
});
const crumbs = await breadcrumb(deps(), ALICE, a.id);
expect(crumbs).toHaveLength(2);
expect(crumbs[0]).toMatchObject({ id: null, name: null }); // root 对 ALICE 不可见
expect(crumbs[1]).toMatchObject({ id: a.id, name: "A" });
});
});
describe("treeService · 审计落库(C3)", () => {
it("创建/改名/移动/删除均写 AuditEntry", async () => {
const root = await createNode(deps(), ADMIN, { parentId: null, kind: "FOLDER", name: "物理" });
await renameNode(deps(), ADMIN, root.id, "物理学");
await softDeleteNode(deps(), ADMIN, root.id);
const actions = (await prisma.auditEntry.findMany({
where: { organizationId: DEFAULT_ORG_ID },
select: { action: true },
orderBy: { createdAt: "asc" },
})).map((e) => e.action);
expect(actions).toEqual(["folder.create", "folder.rename", "folder.delete"]);
});
});
+40
View File
@@ -0,0 +1,40 @@
/**
* 文件路径安全单测(Metis 安全红线:穿越/.git/分隔符/深度)。
*/
import { describe, expect, it } from "vitest";
import { validateFilePath, FILE_PATH_MAX_DEPTH, FILE_PATH_MAX_LENGTH } from "../../src/database/filelib/fileService.js";
import { FileLibError } from "../../src/database/filelib/model.js";
describe("validateFilePath · 路径安全", () => {
it("正常相对路径通过(含 CJK 与多级)", () => {
expect(validateFilePath("a.md")).toBe("a.md");
expect(validateFilePath("docs/讲义/第一课.md")).toBe("docs/讲义/第一课.md");
expect(validateFilePath("a/b/c/d.txt")).toBe("a/b/c/d.txt");
});
it("拒绝穿越:.. 段、绝对路径", () => {
expect(() => validateFilePath("../x")).toThrowError(FileLibError);
expect(() => validateFilePath("a/../../x")).toThrowError(FileLibError);
expect(() => validateFilePath("/etc/passwd")).toThrowError(FileLibError);
});
it("拒绝 .git 段与点段", () => {
expect(() => validateFilePath(".git")).toThrowError(FileLibError);
expect(() => validateFilePath("a/.git/config")).toThrowError(FileLibError);
expect(() => validateFilePath("./a.md")).toThrowError(FileLibError);
});
it("拒绝反斜杠、控制字符、空段(双斜杠/尾斜杠)", () => {
expect(() => validateFilePath("a\\b.md")).toThrowError(FileLibError);
expect(() => validateFilePath("a\nb.md")).toThrowError(FileLibError);
expect(() => validateFilePath("a//b.md")).toThrowError(FileLibError);
expect(() => validateFilePath("a/b/")).toThrowError(FileLibError);
});
it("拒绝空路径、超长、超深", () => {
expect(() => validateFilePath("")).toThrowError(FileLibError);
expect(() => validateFilePath("a".repeat(FILE_PATH_MAX_LENGTH + 1))).toThrowError(FileLibError);
expect(() => validateFilePath(Array(FILE_PATH_MAX_DEPTH + 1).fill("d").join("/"))).toThrowError(FileLibError);
expect(validateFilePath(Array(FILE_PATH_MAX_DEPTH).fill("d").join("/"))).toContain("d/");
});
});
+49
View File
@@ -0,0 +1,49 @@
/**
* 命名规则(D14)单测。
*/
import { describe, expect, it } from "vitest";
import { FileLibError, nameKey, normalizeNodeName, NODE_NAME_MAX_LENGTH } from "../../src/database/filelib/model.js";
describe("normalizeNodeName · D14", () => {
it("trim 空白", () => {
expect(normalizeNodeName(" 物理必修一 ")).toBe("物理必修一");
});
it("NFC 归一化(分解形式 → 合成形式)", () => {
expect(normalizeNodeName("é")).toBe("é");
});
it("CJK 与常见字符原样通过", () => {
expect(normalizeNodeName("TH-141 表面张力 (上)")).toBe("TH-141 表面张力 (上)");
});
it("空名/全空白 → invalid_name", () => {
expect(() => normalizeNodeName("")).toThrowError(FileLibError);
expect(() => normalizeNodeName(" ")).toThrowError(FileLibError);
});
it("超长 → invalid_name", () => {
expect(() => normalizeNodeName("a".repeat(NODE_NAME_MAX_LENGTH + 1))).toThrowError(FileLibError);
expect(normalizeNodeName("a".repeat(NODE_NAME_MAX_LENGTH))).toHaveLength(NODE_NAME_MAX_LENGTH);
});
it("拒绝斜杠与反斜杠", () => {
expect(() => normalizeNodeName("a/b")).toThrowError(FileLibError);
expect(() => normalizeNodeName("a\\b")).toThrowError(FileLibError);
});
it("拒绝控制字符", () => {
expect(() => normalizeNodeName("a\nb")).toThrowError(FileLibError);
expect(() => normalizeNodeName("a\tb")).toThrowError(FileLibError);
expect(() => normalizeNodeName("a\0b")).toThrowError(FileLibError);
});
});
describe("nameKey · 大小写不敏感比较键", () => {
it("ASCII 折叠", () => {
expect(nameKey("Physics")).toBe("physics");
});
it("CJK 不变", () => {
expect(nameKey("物理")).toBe("物理");
});
});
+159
View File
@@ -0,0 +1,159 @@
/**
* 纯权限 reducer 单测(契约 P6 / D11 / 2.3)。
* 矩阵覆盖:个人/Group/祖先继承/max 取最高/不降权/空权限/toggle 冻结;
* 外加确定性随机化不变量(单调性:任何可用 grant 都不超过 effective)。
*/
import { describe, expect, it } from "vitest";
import { checkAccess, effectiveRole, type EffectiveRoleInput, type FileLibGrantFact } from "../../src/database/filelib/permission.js";
const base: EffectiveRoleInput = {
nodeId: "N",
nodeKind: "FOLDER",
ancestorIds: ["A", "R"], // N ⊂ A ⊂ R
independentPermissionsEnabled: false,
userId: "u1",
groupIds: ["g1"],
grants: [],
};
function grant(partial: Partial<FileLibGrantFact>): FileLibGrantFact {
return {
nodeId: "N",
principalType: "USER",
principalId: "u1",
role: "VIEW",
isCreatorGrant: false,
...partial,
};
}
describe("effectiveRole · 契约 P6 矩阵", () => {
it("无任何 grant → null(无权限)", () => {
expect(effectiveRole(base)).toBeNull();
});
it("个人直接 grant 在 self 上 → 生效", () => {
expect(effectiveRole({ ...base, grants: [grant({ role: "EDIT" })] })).toBe("EDIT");
});
it("Group grant 且用户在组内 → 生效", () => {
expect(effectiveRole({ ...base, grants: [grant({ principalType: "GROUP", principalId: "g1", role: "MANAGE" })] })).toBe("MANAGE");
});
it("Group grant 但用户不在组内 → null", () => {
expect(effectiveRole({ ...base, grants: [grant({ principalType: "GROUP", principalId: "g9" })] })).toBeNull();
});
it("祖先链上的 grant 向下继承", () => {
expect(effectiveRole({ ...base, grants: [grant({ nodeId: "A", role: "EDIT" })] })).toBe("EDIT");
expect(effectiveRole({ ...base, grants: [grant({ nodeId: "R", role: "VIEW" })] })).toBe("VIEW");
});
it("取最高:个人低权限 + Group 高权限 → 高权限(个人不能降权)", () => {
const grants = [
grant({ role: "VIEW" }),
grant({ principalType: "GROUP", principalId: "g1", role: "MANAGE" }),
];
expect(effectiveRole({ ...base, grants })).toBe("MANAGE");
});
it("取最高:链上多处 grant,最高者胜", () => {
const grants = [
grant({ nodeId: "R", role: "MANAGE" }),
grant({ nodeId: "A", role: "VIEW" }),
grant({ nodeId: "N", role: "EDIT" }),
];
expect(effectiveRole({ ...base, grants })).toBe("MANAGE");
});
it("链外节点的 grant 不参与", () => {
expect(effectiveRole({ ...base, grants: [grant({ nodeId: "X", role: "MANAGE" })] })).toBeNull();
});
it("他人的个人 grant 不参与", () => {
expect(effectiveRole({ ...base, grants: [grant({ principalId: "u2", role: "MANAGE" })] })).toBeNull();
});
});
describe("effectiveRole · D11 独立权限开关", () => {
const project: EffectiveRoleInput = { ...base, nodeKind: "PROJECT", nodeId: "P" };
it("开关关闭:项目级非创建者 grant 冻结", () => {
const grants = [grant({ nodeId: "P", role: "EDIT" })];
expect(effectiveRole({ ...project, grants })).toBeNull();
});
it("开关关闭:创建者 grant 仍生效", () => {
const grants = [grant({ nodeId: "P", role: "MANAGE", isCreatorGrant: true })];
expect(effectiveRole({ ...project, grants })).toBe("MANAGE");
});
it("开关关闭:祖先链 grant 不受影响", () => {
const grants = [
grant({ nodeId: "P", role: "MANAGE" }), // 冻结
grant({ nodeId: "A", role: "VIEW" }), // 生效
];
expect(effectiveRole({ ...project, grants })).toBe("VIEW");
});
it("开关开启:项目级 grant 恢复参与", () => {
const grants = [grant({ nodeId: "P", role: "EDIT" })];
expect(effectiveRole({ ...project, independentPermissionsEnabled: true, grants })).toBe("EDIT");
});
it("文件夹忽略开关(self grant 照常参与)", () => {
const grants = [grant({ nodeId: "N", role: "EDIT" })];
expect(effectiveRole({ ...base, grants })).toBe("EDIT");
});
});
describe("effectiveRole · 随机化不变量", () => {
// 确定性 LCG,替代 property-based 框架(不新增依赖)。
function lcg(seed: number): () => number {
let s = seed;
return () => {
s = (s * 1103515245 + 12345) % 2147483648;
return s / 2147483648;
};
}
const roles = ["VIEW", "EDIT", "MANAGE"] as const;
it("effective 恰为所有可用 grant 的最高秩(单调、顺序无关)", () => {
const rand = lcg(42);
for (let round = 0; round < 200; round += 1) {
const nodes = ["N", "A", "R", "X"];
const principals = ["u1", "u2", "g1", "g9"];
const grants: FileLibGrantFact[] = Array.from({ length: Math.floor(rand() * 12) }, () => {
const principalId = principals[Math.floor(rand() * principals.length)]!;
return grant({
nodeId: nodes[Math.floor(rand() * nodes.length)]!,
principalType: principalId.startsWith("g") ? "GROUP" : "USER",
principalId,
role: roles[Math.floor(rand() * roles.length)]!,
});
});
const input: EffectiveRoleInput = { ...base, grants };
const applicableRanks = grants
.filter((g) => ["N", "A", "R"].includes(g.nodeId))
.filter((g) => (g.principalType === "USER" ? g.principalId === "u1" : g.principalId === "g1"))
.map((g) => ({ VIEW: 1, EDIT: 2, MANAGE: 3 })[g.role]);
const expected = applicableRanks.length === 0 ? 0 : Math.max(...applicableRanks);
const actual = effectiveRole(input);
expect(actual === null ? 0 : { VIEW: 1, EDIT: 2, MANAGE: 3 }[actual]).toBe(expected);
// 顺序无关
expect(effectiveRole({ ...input, grants: [...grants].reverse() })).toBe(actual);
}
});
});
describe("checkAccess · D8 语义", () => {
it("无权限 → not_found(404 不泄露)", () => {
expect(checkAccess(null, "VIEW")).toEqual({ allowed: false, reason: "not_found" });
});
it("权限不足 → forbidden(403)", () => {
expect(checkAccess("VIEW", "EDIT")).toEqual({ allowed: false, reason: "forbidden" });
});
it("权限足够 → allowed 并带回实际角色", () => {
expect(checkAccess("MANAGE", "EDIT")).toEqual({ allowed: true, role: "MANAGE" });
});
});
+120
View File
@@ -0,0 +1,120 @@
/**
* InMemory VersionStore 语义单测(契约 C1:S1/S2/S7 + 计划 D16/S4)。
* mock 必须如实表达:冲突走返回值、baseVersion=null 表新建、init 幂等、
* 文件级版本互不影响、同仓库写操作串行。
*/
import { describe, expect, it } from "vitest";
import { createInMemoryVersionStore } from "../../src/database/filelib/versionStore.js";
import { FileLibError } from "../../src/database/filelib/model.js";
const DIR = "/repos/p1";
describe("InMemoryVersionStore · C1 语义", () => {
it("init 幂等(S7);未 init 的仓库操作报 repo_not_found", async () => {
const store = createInMemoryVersionStore();
await expect(store.head(DIR, "a.md")).rejects.toThrowError(FileLibError);
await store.init(DIR);
await store.init(DIR); // 幂等,不报错、不重建
await store.commit(DIR, "a.md", { baseVersion: null, content: "hello" });
await store.init(DIR); // 已有内容后再 init 也不清空
expect(await store.head(DIR, "a.md")).toBe("v1");
});
it("新建(baseVersion null)→ ok;head/read 命中", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
const r = await store.commit(DIR, "a.md", { baseVersion: null, content: "v1 内容", author: "u1" });
expect(r).toEqual({ status: "ok", version: "v1" });
expect((await store.read(DIR, "a.md")).toString()).toBe("v1 内容");
});
it("对已存在文件再次『新建』 → conflict(S2)", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "1" });
const r = await store.commit(DIR, "a.md", { baseVersion: null, content: "2" });
expect(r).toEqual({ status: "conflict", currentVersion: "v1" });
});
it("baseVersion 落后于当前 → conflict 并带 currentVersion(S1)", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "1" });
const ok = await store.commit(DIR, "a.md", { baseVersion: "v1", content: "2" });
expect(ok.status).toBe("ok");
const stale = await store.commit(DIR, "a.md", { baseVersion: "v1", content: "3" });
expect(stale).toEqual({ status: "conflict", currentVersion: "v2" });
});
it("正确 base 连续提交;旧版本仍可读", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "一" });
await store.commit(DIR, "a.md", { baseVersion: "v1", content: "二" });
expect((await store.read(DIR, "a.md", "v1")).toString()).toBe("一");
expect((await store.read(DIR, "a.md")).toString()).toBe("二");
});
it("D16 文件级版本:文件 A 的提交不影响文件 B 的 base", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "A1" });
const b1 = await store.commit(DIR, "b.md", { baseVersion: null, content: "B1" });
await store.commit(DIR, "a.md", { baseVersion: "v1", content: "A2" }); // A 前进到 v3
// B 仍以自己的 head 为 base,不受 A 推进影响
const b2 = await store.commit(DIR, "b.md", {
baseVersion: b1.status === "ok" ? b1.version : "",
content: "B2",
});
expect(b2.status).toBe("ok");
});
it("remove:正确 base → ok;head 随后 404;stale base → conflict", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "1" });
await store.commit(DIR, "a.md", { baseVersion: "v1", content: "2" });
expect(await store.remove(DIR, "a.md", "v1")).toEqual({ status: "conflict", currentVersion: "v2" });
expect((await store.remove(DIR, "a.md", "v2")).status).toBe("ok");
await expect(store.head(DIR, "a.md")).rejects.toThrowError(FileLibError);
await expect(store.remove(DIR, "a.md", "v3")).rejects.toThrowError(FileLibError);
});
it("history 新→旧,支持 limit;list 排除已删并按前缀过滤", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "docs/a.md", { baseVersion: null, content: "1", message: "初版" });
await store.commit(DIR, "docs/a.md", { baseVersion: "v1", content: "2", message: "二版" });
await store.commit(DIR, "other/b.md", { baseVersion: null, content: "x" });
const h = await store.history(DIR, "docs/a.md");
expect(h.map((v) => v.message)).toEqual(["二版", "初版"]);
expect((await store.history(DIR, "docs/a.md", 1)).map((v) => v.message)).toEqual(["二版"]);
expect((await store.list(DIR)).map((f) => f.path)).toEqual(["docs/a.md", "other/b.md"]);
expect((await store.list(DIR, "docs/")).map((f) => f.path)).toEqual(["docs/a.md"]);
await store.remove(DIR, "other/b.md", "v3");
expect((await store.list(DIR)).map((f) => f.path)).toEqual(["docs/a.md"]);
});
it("S4 同仓库写串行:并发同 base 提交,恰好一成一冲突", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "1" });
const [r1, r2] = await Promise.all([
store.commit(DIR, "a.md", { baseVersion: "v1", content: "x" }),
store.commit(DIR, "a.md", { baseVersion: "v1", content: "y" }),
]);
const statuses = [r1.status, r2.status].sort();
expect(statuses).toEqual(["conflict", "ok"]);
});
it("diff 输出含增删行", async () => {
const store = createInMemoryVersionStore();
await store.init(DIR);
await store.commit(DIR, "a.md", { baseVersion: null, content: "keep\nold" });
await store.commit(DIR, "a.md", { baseVersion: "v1", content: "keep\nnew" });
const d = await store.diff(DIR, "a.md", "v1", "v2");
expect(d).toContain("-old");
expect(d).toContain("+new");
expect(d).toContain(" keep");
});
});
+304
View File
@@ -0,0 +1,304 @@
# 文件库系统 · 接口契约与决策(v0.1 我方提案)
> **读者**:版本团队、Group 团队、审计团队、平台方、编辑团队、产品。
> **用法**:本文档是我方(文件库)提出的对齐基线。所有决策带 `D-x` 编号、所有契约带 `C-x` 编号,评审时请按编号引用("D5 我们不同意,建议……")。评审通过后本文件冻结,各方照此实现;任何变更走文档修订,不接受口头对齐。
> **状态**:v0.1 提案,未冻结。
---
## 1. 系统边界与分工
| 子系统 | 负责方 | 与我方关系 |
|---|---|---|
| 文件库(目录树 / 权限引擎 / 内容存储 / 对外 API / 前端) | **我方** | — |
| 版本能力(git 化、commit、diff、历史) | 版本团队 | 交付 **npm 工具包**,我方在自有存储上集成(见 C1) |
| Group 系统(全局嵌套组) | Group 团队 | 我方**实时消费**其查询接口(见 C2) |
| 审计系统(存储 / 查询 / 保留) | 审计团队 | 我方**上报事件**(见 C3);查询界面归审计方 |
| 平台身份(登录 / 角色) | 平台方 | 我方验签消费角色(见 C4) |
| 在线编辑与冲突合并 UI(需求 2.5) | 编辑团队 | **消费我方文件 API**(见第 9 节) |
| 导出工具 | 已有工具 | 我方按需传参调用(参数清单 OPEN-6) |
**内容归属**:文件内容(git 仓库)物理存储在文件库自己的服务器上,由我方管理;版本团队不持有任何数据,只交付代码。
## 2. 总体架构
```
编辑团队(2.5 UI) ──┐
其他消费方 ──┤ HTTP + JWT
┌─────────────────────┐
│ 文件库服务(我方) │
│ 目录树 + 权限引擎 │──── 实时查询 ──▶ Group 系统(C2)
│ 文件 API + 授权 API │──── 验签 JWT ──▶ 平台身份(C4)
└─────────┬───────────┘
│ import(函数调用)
┌─────────────────────┐ outbox 中继(at-least-once)
│ 版本工具包(C1,npm) │ ┌──────────────────────▶ 审计系统(C3)
│ 操作我方磁盘上的 │ │
│ git 仓库(内容归我方)│ ▼
└─────────────────────┘ 我方 DB:业务表 + outbox 表(同事务)
```
## 3. 决策总表
| 编号 | 决策 | 一句话理由 | 影响方 |
|---|---|---|---|
| D1 | 文件库后端 TypeScript + Fastify + Prisma(PostgreSQL);前端 React | 与平台技术心智一致 | 我方 |
| D2 | 文件内容物理存储在文件库服务器,版本能力以 npm 包交付 | 需求 2.1"项目初始化为 Git 仓库",仓库是项目的存储 | 版本团队 |
| D3 | 版本包冲突用**返回值**表达,异常仅用于系统错误 | 冲突是正常业务流,不是故障 | 版本、编辑 |
| D4 | Group 查询**实时调用、不缓存** | 需求 3.3"成员变更实时生效" | Group |
| D5 | 审计走"本地 outbox + 后台中继"满足"同事务或可靠消息" | 跨服务做不到真同事务,outbox 是最简单的可靠方案 | 审计 |
| D6 | 平台身份用 JWT(RS256)验签,平台角色 `platform.admin` 映射网站管理员 | 无状态、无需每次回调平台 | 平台 |
| D7 | 权限管理规则按第 8 节补齐(2.4 空洞的我方版本) | 需求 2.4 为空,必须先有规则才能写码 | 产品确认 |
| D8 | 无 View 权限时 API 返回 **404**(不泄露存在性);有 View 但操作越权返回 403 | 防资源探测 | 所有消费方 |
| D9 | 软删除:删除即打标隐藏,所有 API 默认不可见 | 需求 2.6/3.3 | 我方 |
| D10 | 导出为**异步任务**(提交返回 job,轮询取结果) | 导出耗时不确定,同步会超时 | 编辑/前端 |
---
## 4. C1 · 版本工具包契约(给版本团队)
**交付形态**npm 包(TypeScript,自带类型定义),运行在文件库后端进程内。实现技术(isomorphic-git / nodegit / 其他)由版本团队自选,**本契约只约束接口与语义**。
### 4.1 接口签名
```typescript
export type VersionId = string; // 不透明字符串,调用方不得解析(当前为 git commit hash)
export interface CommitRequest {
/** 编辑的起始版本;null 表示新建文件 */
baseVersion: VersionId | null;
content: string | Buffer; // 文本用 string(UTF-8),二进制用 Buffer
message?: string; // 缺省由包自动生成
author?: string; // 操作者标识,写入版本记录
}
export type CommitResult =
| { status: "ok"; version: VersionId }
| { status: "conflict"; currentVersion: VersionId };
export interface VersionInfo {
version: VersionId;
message: string;
author?: string;
committedAt: string; // ISO 8601
}
export interface FileEntry { path: string; size: number; }
export interface VersionStore {
init(projectDir: string): Promise<void>; // S7: 幂等
list(projectDir: string, prefix?: string): Promise<FileEntry[]>;
head(projectDir: string, filePath: string): Promise<VersionId>; // 文件不存在 → FileNotFoundError
read(projectDir: string, filePath: string, at?: VersionId): Promise<Buffer>; // 缺省读最新
commit(projectDir: string, filePath: string, req: CommitRequest): Promise<CommitResult>;
remove(projectDir: string, filePath: string, baseVersion: VersionId): Promise<CommitResult>;
diff(projectDir: string, filePath: string, from: VersionId, to: VersionId): Promise<string>; // unified diff
history(projectDir: string, filePath: string, limit?: number): Promise<VersionInfo[]>;
}
```
### 4.2 语义规则
| 编号 | 规则 |
|---|---|
| S1 | **冲突不是异常**`baseVersion` 落后于当前版本时返回 `{status:"conflict"}`;异常仅用于 IO 故障、仓库损坏等系统错误 |
| S2 | `baseVersion: null` = 新建;路径已存在时返回 conflict |
| S3 | 二进制文件与文本同样版本化;`diff` 仅保证对文本有意义,二进制可返回占位说明 |
| S4 | 包必须保证**同一 projectDir 的写操作(commit/remove)串行化**,调用方可并发调用 |
| S5 | 存储布局不透明:我方不直接读写仓库目录,一切经包接口 |
| S6 | 在线编辑仅针对文本文件(需求 2.5);二进制材料走上传/下载 |
| S7 | `init` 幂等,重复调用不报错、不重建 |
| S8 | 规模假设:单项目文件数千级、单文件 10MB 以内,超出另行对齐 |
---
## 5. C2 · Group 查询契约(给 Group 团队)
**形态**:HTTP + JSON。我方只读,不写 Group 系统任何数据(需求 3.3)。
### 5.1 接口
```
GET /groups/resolve-member-groups?userId={userId}
→ { "groupIds": ["g1","g2",...] }
# 权限计算专用:用户直接所属的全部 group + 这些 group 的所有祖先 group,去重。
# 方向是"向祖先"收集(需求 3.2:权限沿 group 树向下传递)。
GET /groups/search?q={keyword}&limit={n}
→ [{ "id":"g1","name":"物理教研组","breadcrumb":"总部 / 教研 / 物理" }]
# 前端授权选择器用。
GET /groups/{groupId}
→ { "id":"g1","name":"物理教研组","parentId":"g0","status":"active" }
```
### 5.2 语义规则
| 编号 | 规则 |
|---|---|
| G1 | `groupId` 为不透明、全局唯一字符串 |
| G2 | resolve 只含**祖先方向**,不含子孙;用户无所属时返回空数组 |
| G3 | 软删除的 group 不出现在任何接口结果中 |
| G4 | **实时性**:我方每次权限计算都实时调用 resolve,不缓存;Group 方成员变更须即刻在 resolve 结果中可见(需求 3.3 |
| G5 | 文件夹/项目的授权记录只存在文件库,Group 系统不感知(需求 3.3) |
| G6 | 可用性:resolve 位于我方**每一次受保护请求**的权限计算路径上,其可用性即文件库可用性 → 需要 Group 方给出延迟与可用性承诺(OPEN-1) |
---
## 6. C3 · 审计上报契约(给审计团队)
### 6.1 机制(满足需求 5.1"同事务或可靠消息"
1. 我方在每个关键写操作的**同一数据库事务**内,向本地 `audit_outbox` 表写入事件;
2. 后台中继进程读取 outbox,POST 到审计系统 `POST /audit/events`**at-least-once**,失败重试;
3. 审计系统按 `eventId` **幂等去重**
4. 中继只负责送达,业务操作不因审计系统不可用而失败(但事件绝不丢)。
### 6.2 事件信封(补齐需求 5.3 空缺的字段定义)
```json
{
"eventId": "01J…", // 我方生成的唯一 id,幂等键
"schemaVersion": 1,
"occurredAt": "2026-07-21T10:00:00.000Z",
"sourceService": "filelib",
"actor": { "userId": "u123", "platformRole": "teacher" },
"action": "permission.grant", // 见 6.3 词汇表
"object": { "type": "folder", "id": "n456", "path": "/物理/必修一" },
"result": "success", // success | failure
"errorCode": null,
"detail": { /* action , grant {principalType, principalId, role} */ }
}
```
### 6.3 action 词汇表(文件库范围,对照需求 5.2)
| action | 需求 5.2 对应 |
|---|---|
| `folder.create` / `folder.rename` / `folder.move` / `folder.delete` | 创建/删除/移动/重命名文件夹 |
| `project.create` / `project.rename` / `project.move` / `project.delete` | 同上(项目) |
| `permission.grant` / `permission.update` / `permission.revoke` | 权限变更(detail 含个人/Group、Manage/Edit/View |
| `project.independent_permission.enable` / `.disable` / `.change` | 项目独立权限开启/关闭/变更 |
| `file.upload` / `file.rename` / `file.delete` | 材料文件管理 |
| `file.commit` | 文件编辑提交(含冲突合并后提交;编辑经我方 API 落盘,故由我方上报) |
| `file.conflict_detected` | 冲突检测发生(detail 含起始版本与冲突版本) |
| `export.run` | 导出操作 |
| `admin.force_adjust` | 网站管理员强制权限调整(高危) |
Group 相关动作(创建/删除/成员变更/嵌套变更)由 **Group 系统自行上报**;归档类动作待归档功能定案后补充(OPEN-4)。
### 6.4 边界
- 审计的存储、防篡改、保留策略(需求 5.5 ≥180 天)、查询接口与查询界面,全部归审计系统;
- 文件库前端**不内嵌**审计查询页(若产品要求嵌入,OPEN-8 再议)。
---
## 7. C4 · 平台身份契约(给平台方)
1. 调用方在 `Authorization: Bearer <JWT>` 中携带平台签发的令牌(RS256);平台通过 JWKS endpoint 分发公钥,我方只做验签 + 过期检查,**不回调平台、不建用户表**;
2. claims 约定:`sub`(用户 id,全局唯一)、`roles`(平台角色数组)、`exp``iss`
3. **角色映射**`roles``platform.admin` → 文件库"网站管理员";其余合法令牌 → 普通用户;无令牌/验签失败/过期 → `401`
4. 网站管理员权限范围:创建根目录、强制权限调整(必审计)、以及平台方赋予的其他高危操作;**不隐式穿透**各节点的业务权限(要管理某子树须被显式授权或走强制调整并留痕);
5. 前端登录跳转平台 SSO,具体流程由前端与平台方另行对齐。
---
## 8. 权限规则 · 2.4 补齐版(D7,产品确认后冻结)
### 8.1 创建者与授权矩阵
| 角色 | 能授/改/收的级别 | 限制 |
|---|---|---|
| **节点创建者** | Manage / Edit / View | 自身 Manage 不可被收回(转让 OPEN-3 |
| **Manage 持有者** | Edit / View | **不可**授予 Manage;**不可**修改/收回创建者的任何权限 |
| **Edit / View** | 无授权能力 | — |
| **网站管理员** | 任意(走 `admin.force_adjust`,必审计) | 不属于日常授权路径 |
### 8.2 各级别能力清单
| 能力 | View | Edit | Manage |
|---|:---:|:---:|:---:|
| 浏览树 / 读文件 / 下载 | ✓ | ✓ | ✓ |
| 导出 | ✓ | ✓ | ✓ |
| 创建子文件夹/项目(需求:父级 Edit+) | | ✓ | ✓ |
| 编辑文本文件 / 上传 / 删改项目内材料 | | ✓ | ✓ |
| 重命名 / 移动 / 删除**本节点** | | | ✓ |
| 授权管理(按 8.1 矩阵) | | | ✓ |
| 项目独立权限开关 | | | ✓ |
### 8.3 其余规则
- **P3 根目录**:仅网站管理员可创建;创建时必须指定 ≥1 名 Manage 持有者(可以不是创建者本人),保证每棵子树都有权限链起点;
- **P4 空权限创建**:允许;此时仅创建者可见可用;
- **P5 项目独立权限**:默认关闭(仅继承父链);开启后项目级授权参与 max 计算;关闭时项目级授权**冻结不删除**,重新开启即恢复;
- **P6 计算规则**(与需求 2.3 一致的形式化):
`effective(user, R) = max { grant.role | grant ∈ grants(s, r), s ∈ {user} resolveGroups(user), r ∈ {R} ancestors(R) }`,无 grant → 无权限。个人低权限**不构成降权**(只取最高,不做减法);
- **P7 可见性**:对某节点无任何权限的用户,该节点对其不可见(API 行为见 D8)。
---
## 9. 文件库对外 API(消费方:编辑团队及其他)
**约定**REST + JSON + JWTC4);统一错误信封 `{ "error": { "code", "message", "details?" } }`;D8 可见性语义(无 View → 404;越权操作 → 403)。
### 9.1 树与节点
```
GET /nodes?parentId={id} # 列子节点(缺省列根);仅返回有 View 的
POST /nodes # 创建文件夹/项目 {parentId, type, name, grants?[]}
# parentId=null 仅网站管理员;type=project 时自动调 C1.init
GET /nodes/{id} # 节点详情 + 我的 effective 权限 + breadcrumb
PATCH /nodes/{id} # 重命名/移动 {name?, parentId?} (需本节点 Manage)
DELETE /nodes/{id} # 软删除(需 Manage)
```
### 9.2 授权
```
GET /nodes/{id}/grants # 授权列表(需 Manage)
PUT /nodes/{id}/grants # 批量授予/修改 [{principalType:user|group, principalId, role}]
DELETE /nodes/{id}/grants/{grantId} # 收回
GET /nodes/{id}/effective-permission # 当前用户在此节点的生效权限(自查)
PUT /projects/{id}/independent-permission # {enabled: bool} 独立权限开关
```
### 9.3 文件内容(编辑团队的主接口)
```
GET /projects/{id}/files?prefix= # 文件清单
GET /projects/{id}/files/{path} # → {content, version} 编辑起手式:拿到起始版本
PUT /projects/{id}/files/{path} # 新建/上传 {content} (需 Edit)
POST /projects/{id}/files/{path}/commits # 提交编辑 {baseVersion, content, message?}
# → 200 {version} | 409 {currentVersion}
GET /projects/{id}/files/{path}/diff?from=&to= # 冲突时取差异(unified diff)
GET /projects/{id}/files/{path}/history # 版本历史
DELETE /projects/{id}/files/{path} # {baseVersion} (需 Edit)
```
**冲突合并流程(配合编辑团队 2.5)**:编辑 UI 用 `GET files/{path}` 记录 `version` → 用户编辑 → `POST commits``baseVersion` → 若 `409`UI 用 `diff?from=base&to=current` 拉取差异,展示三方合并区 → 用户写出最终内容后再次 `POST commits`baseVersion 换为 currentVersion)。
### 9.4 导出
```
POST /projects/{id}/exports {target, params} → {jobId} # D10 异步
GET /exports/{jobId} → {status, downloadUrl?}
```
---
## 10. OPEN 清单(需对方/产品确认,不阻塞我方开工)
| 编号 | 事项 | 等谁 |
|---|---|---|
| OPEN-1 | Group resolve 的延迟/可用性 SLA 数值 | Group 团队 |
| OPEN-2 | 审计事件投递的 endpoint、鉴权方式、保留期确认(需求建议 ≥180 天) | 审计团队 |
| OPEN-3 | 创建者离职/转让后 Manage 链如何处理 | 产品 |
| OPEN-4 | 归档功能(需求已划线"暂时未定") | 产品 |
| OPEN-5 | 二进制材料的大小上限与在线预览诉求 | 产品 |
| OPEN-6 | 导出工具的参数清单(需求原文"待对接时确认") | 导出工具方 |
| OPEN-7 | 软删除的恢复入口、"后台标签"管理界面归属 | 产品 |
| OPEN-8 | 网站管理员强制调整的前端入口(我方做还是平台做)、审计查询页是否嵌入文件库前端 | 产品 |