79 lines
2.5 KiB
Python
Raw Permalink Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

#!/usr/bin/env python3
"""RBAC path registration for pipeline-bidding module.
与平台惯例一致:静态资源 → any免登录页面/CRUD/API → logined。
在宿主应用根目录执行set_role_perm.py 位于宿主根):
cd <APP_ROOT> && py3/bin/python pkgs/pipeline-bidding/scripts/load_path.py
"""
import os
import subprocess
import sys
MOD = "pipeline-bidding"
# set_role_perm.py 在宿主应用根目录(本脚本位于 <APP_ROOT>/pkgs/pipeline-bidding/scripts/
APP_ROOT = os.path.abspath(os.path.join(os.path.dirname(__file__), "..", "..", ".."))
TABLES = [
"bid_tenders", "bid_members", "bid_tender_files",
"bid_scoring_items", "bid_qualifications", "bid_doc_requirements",
"bid_qc_reviews",
"bid_chapters", "bid_reviews", "bid_scores", "bid_kb_docs", "bid_documents",
]
PATHS_ANY = [
"/imgs/node-expand.svg",
"/imgs/node-collapse.svg",
"/imgs/open-folder.svg",
"/imgs/close-folder.svg",
]
PATHS_LOGINED = [
"/%s" % MOD,
"/%s/index.ui" % MOD,
# 多 session 会话入口agent 目录 + 页面,菜单 open_tab 指向 /pipeline-bidding/agent
"/%s/agent" % MOD,
"/%s/agent/index.ui" % MOD,
"/%s/bid_task_tree_popup.ui" % MOD,
]
for t in TABLES:
PATHS_LOGINED += [
"/%s/%s/index.ui" % (MOD, t),
"/%s/%s/get_%s.dspy" % (MOD, t, t),
"/%s/%s/add_%s.dspy" % (MOD, t, t),
"/%s/%s/update_%s.dspy" % (MOD, t, t),
"/%s/%s/delete_%s.dspy" % (MOD, t, t),
]
# 产线业务 API RBAC 精确 path 匹配:/api/ 前缀不覆盖具体 dspy逐个显式注册
PATHS_LOGINED += [
"/%s/api/" % MOD,
"/%s/api/bid_probe.dspy" % MOD,
"/%s/api/bid_task_tree.dspy" % MOD,
"/%s/api/bid_task_io.dspy" % MOD,
"/%s/api/tech_template_confirm.dspy" % MOD,
"/%s/api/bid_delivery_reject.dspy" % MOD,
]
def _run(role, path):
r = subprocess.run([sys.executable, os.path.join(APP_ROOT, "set_role_perm.py"), role, path],
capture_output=True, text=True, cwd=APP_ROOT)
if r.returncode != 0:
print(" FAIL [%s] %s: %s" % (role, path, (r.stderr or "").strip()[:120]))
return r.returncode == 0
def main():
print("=== %s RBAC registration ===" % MOD)
n = 0
for p in PATHS_ANY:
n += _run("any", p)
print(" any: %s" % p)
for p in PATHS_LOGINED:
n += _run("logined", p)
print(" logined: %s" % p)
print("Done. %d/%d paths registered" % (n, len(PATHS_ANY) + len(PATHS_LOGINED)))
if __name__ == "__main__":
main()