mirror of
https://github.com/hansjone/dsh-im-ops.git
synced 2026-10-09 09:05:46 +08:00
feat: add unified IM access policies
This commit is contained in:
parent
075d2713c1
commit
840e5aa857
89 changed files with 5573 additions and 1676 deletions
|
|
@ -24,6 +24,10 @@ import {
|
|||
} from '../../../../src/channels/shared/bot-workspace-store.mjs';
|
||||
import { listAgentPresetCatalog } from '../../../../src/channels/shared/agent-preset.mjs';
|
||||
import { createDeliveryAdapter } from '../../delivery-adapter.mjs';
|
||||
import {
|
||||
accessPolicyProvider,
|
||||
initialAccessPolicyFor,
|
||||
} from '../shared/access-policy-production.mjs';
|
||||
|
||||
// The WebSocket agent built here is only used for the Feishu long connection,
|
||||
// whose endpoint is open.feishu.cn (Feishu) or open.larksuite.com (Lark).
|
||||
|
|
@ -120,6 +124,7 @@ export async function createProductionController(ctx, config = {}, internals = {
|
|||
}
|
||||
await Promise.all(configuredBots.map((bot) => workspaces.ensure(bot.id, {
|
||||
defaultAgentPreset: config.agentPreset,
|
||||
initialAccessPolicy: initialAccessPolicyFor('feishu', bot),
|
||||
})));
|
||||
const observedConfigStore = typeof configStore.removeBot === 'function'
|
||||
? observeBotWorkspaceRemovals(configStore, {
|
||||
|
|
@ -181,7 +186,10 @@ export async function createProductionController(ctx, config = {}, internals = {
|
|||
createRuntime: async ({ botId, config: botConfig, appSecret, repair }) => {
|
||||
const state = await stateFor(botConfig);
|
||||
const id = botId ?? botConfig.id ?? botConfig.appId;
|
||||
await workspaces.ensure(id, { defaultAgentPreset: config.agentPreset });
|
||||
await workspaces.ensure(id, {
|
||||
defaultAgentPreset: config.agentPreset,
|
||||
initialAccessPolicy: initialAccessPolicyFor('feishu', botConfig),
|
||||
});
|
||||
const workspaceScope = createBotWorkspaceScope(harness, {
|
||||
botId: id, workspaces, state, agentPresetCatalog,
|
||||
});
|
||||
|
|
@ -198,6 +206,9 @@ export async function createProductionController(ctx, config = {}, internals = {
|
|||
harness: workspaceScope.harness,
|
||||
state: workspaceScope.state,
|
||||
contextEnhancement: { botId: id, getSettings: () => workspaces.contextEnhancementFor(id) },
|
||||
accessPolicy: accessPolicyProvider(workspaces, id, {
|
||||
channel: 'feishu', config: botConfig,
|
||||
}),
|
||||
replyTimeoutMs: config.replyTimeoutMs ?? 600_000,
|
||||
slashCommands: config.slashCommands !== false,
|
||||
...(wsAgent ? { wsAgent } : {}),
|
||||
|
|
|
|||
|
|
@ -5,21 +5,27 @@ import {
|
|||
} from '../../../../src/channels/shared/agent-preset.mjs';
|
||||
import { publicConnectionTestResult } from '../../../../src/channels/shared/connection-test.mjs';
|
||||
import { publicMessageFailure } from '../../../../src/channels/shared/message-failure.mjs';
|
||||
import { normalizeAccessPolicy } from '../../../../src/channels/shared/access-policy.mjs';
|
||||
import { resolveRpcAuthority } from '../../rpc-authority.mjs';
|
||||
import { publicWorkspaceError, validWorkspacePayload } from '../shared/workspace-rpc.mjs';
|
||||
import { validAgentPresetPayload } from '../shared/agent-preset-rpc.mjs';
|
||||
import { validContextEnhancementPayload } from '../shared/context-enhancement-rpc.mjs';
|
||||
import { SET_ACCESS_POLICY_ENDPOINT, validAccessPolicyPayload } from '../shared/access-policy-rpc.mjs';
|
||||
import { normalizeContextEnhancementConfig } from '../../../../src/channels/shared/context-enhancement.mjs';
|
||||
import {
|
||||
isFeishuGroupResponseMode,
|
||||
normalizeFeishuGroupResponseMode,
|
||||
} from '../../../../src/channels/feishu/group-response-mode.mjs';
|
||||
import {
|
||||
FEISHU_ENDPOINTS,
|
||||
FEISHU_ENDPOINTS as FEISHU_CLIENT_ENDPOINTS,
|
||||
FEISHU_RPC_CHANNEL,
|
||||
} from '../../../client/channels/feishu/api.js';
|
||||
|
||||
export { FEISHU_ENDPOINTS, FEISHU_RPC_CHANNEL };
|
||||
export const FEISHU_ENDPOINTS = Object.freeze({
|
||||
...FEISHU_CLIENT_ENDPOINTS,
|
||||
setAccessPolicy: SET_ACCESS_POLICY_ENDPOINT,
|
||||
});
|
||||
export { FEISHU_RPC_CHANNEL };
|
||||
export const FEISHU_MULTI_ENDPOINTS = Object.freeze({
|
||||
reconnectBot: 'bot.reconnect',
|
||||
disconnectBot: 'bot.disconnect',
|
||||
|
|
@ -279,6 +285,7 @@ function publicBotEntry(entry) {
|
|||
configured: source.configured === true,
|
||||
agentPreset: normalizeAgentPresetId(source.agentPreset),
|
||||
contextEnhancement: normalizeContextEnhancementConfig(source.contextEnhancement),
|
||||
accessPolicy: normalizeAccessPolicy(source.accessPolicy),
|
||||
groupResponseMode: normalizeFeishuGroupResponseMode(source.groupResponseMode),
|
||||
groupMessagePermissionGranted: source.groupMessagePermissionGranted === true,
|
||||
bot: publicBot(source.bot),
|
||||
|
|
@ -422,6 +429,10 @@ function validPayload(endpoint, payload) {
|
|||
return validContextEnhancementPayload(payload)
|
||||
? null : '请提交有效的上下文增强设置。';
|
||||
}
|
||||
if (endpoint === FEISHU_ENDPOINTS.setAccessPolicy) {
|
||||
return validAccessPolicyPayload(payload)
|
||||
? null : '请提交有效的访问设置。';
|
||||
}
|
||||
if (endpoint === FEISHU_ENDPOINTS.setGroupResponseMode) {
|
||||
return hasOnlyKeys(payload, new Set(['botId', 'groupResponseMode']))
|
||||
&& safeOpaqueId(payload.botId)
|
||||
|
|
@ -679,6 +690,12 @@ export function createFeishuRpcHandler(controller, { encodeQr = qrCodeDataUrl }
|
|||
payload.botId, payload.config,
|
||||
(status) => toPublicFeishuStatus(status, { encodeQr: cachedEncodeQr }),
|
||||
);
|
||||
} else if (endpoint === FEISHU_ENDPOINTS.setAccessPolicy) {
|
||||
if (typeof controller.updateAccessPolicy !== 'function') throw new Error('Access policy update is unavailable');
|
||||
value = await controller.updateAccessPolicy(
|
||||
payload.botId, payload.policy,
|
||||
(status) => toPublicFeishuStatus(status, { encodeQr: cachedEncodeQr }),
|
||||
);
|
||||
} else if (endpoint === FEISHU_ENDPOINTS.setAgentPreset) {
|
||||
if (typeof controller.updateAgentPreset !== 'function') throw new Error('Agent preset update is unavailable');
|
||||
value = await toPublicFeishuStatus(
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue