feat: add unified IM access policies

This commit is contained in:
xmanrui 2026-09-01 10:45:12 +08:00
parent 075d2713c1
commit 840e5aa857
89 changed files with 5573 additions and 1676 deletions

View file

@ -19,6 +19,10 @@ import { pluginPaths } from '../shared/production.mjs';
import { createHarnessCommandExecutor } from '../../harness-command-executor.mjs';
import { harnessConnection } from '../../harness-connection.mjs';
import { createHarnessSessionExecutors } from '../../harness-session-coordinator.mjs';
import {
accessPolicyProvider,
initialAccessPolicyFor,
} from '../shared/access-policy-production.mjs';
export async function createProductionController(ctx, config = {}, internals = {}) {
if (!ctx?.credentials) throw new TypeError('dsh-im slack requires ctx.credentials');
@ -43,6 +47,7 @@ export async function createProductionController(ctx, config = {}, internals = {
await workspaces.reconcile(configuredBots.map((bot) => bot.botId));
await Promise.all(configuredBots.map((bot) => workspaces.ensure(bot.botId, {
defaultAgentPreset: config.agentPreset,
initialAccessPolicy: initialAccessPolicyFor('slack', bot),
})));
const observedConfigStore = typeof configStore.remove === 'function'
? observeBotWorkspaceRemovals(configStore, { workspaces })
@ -80,7 +85,10 @@ export async function createProductionController(ctx, config = {}, internals = {
...(internals.inspectCredentials ? { inspectCredentials: internals.inspectCredentials } : {}),
createRuntime: async ({ botId, config: botConfig, botToken, appToken }) => {
const state = await stateFor(botId);
await workspaces.ensure(botId, { defaultAgentPreset: config.agentPreset });
await workspaces.ensure(botId, {
defaultAgentPreset: config.agentPreset,
initialAccessPolicy: initialAccessPolicyFor('slack', botConfig),
});
const workspaceScope = createBotWorkspaceScope(harness, {
botId, workspaces, state, agentPresetCatalog,
});
@ -91,6 +99,9 @@ export async function createProductionController(ctx, config = {}, internals = {
harness: workspaceScope.harness,
state: workspaceScope.state,
contextEnhancement: { botId, getSettings: () => workspaces.contextEnhancementFor(botId) },
accessPolicy: accessPolicyProvider(workspaces, botId, {
channel: 'slack', config: botConfig,
}),
replyTimeoutMs: config.replyTimeoutMs ?? 600_000,
connectTimeoutMs: config.connectTimeoutMs ?? 20_000,
logger: {

View file

@ -1,4 +1,5 @@
import { SET_CONTEXT_ENHANCEMENT_ENDPOINT, validContextEnhancementPayload } from '../shared/context-enhancement-rpc.mjs';
import { SET_ACCESS_POLICY_ENDPOINT, validAccessPolicyPayload } from '../shared/access-policy-rpc.mjs';
import { resolveRpcAuthority } from '../../rpc-authority.mjs';
import { publicConnectionTestResult } from '../../../../src/channels/shared/connection-test.mjs';
import {
@ -20,6 +21,7 @@ export const SLACK_ENDPOINTS = Object.freeze({
setWorkspace: SET_WORKSPACE_ENDPOINT,
setAgentPreset: SET_AGENT_PRESET_ENDPOINT,
setContextEnhancement: SET_CONTEXT_ENHANCEMENT_ENDPOINT,
setAccessPolicy: SET_ACCESS_POLICY_ENDPOINT,
});
export const SLACK_RPC_ENDPOINTS = Object.freeze(Object.values(SLACK_ENDPOINTS));
@ -81,6 +83,10 @@ function payloadFailure(endpoint, payload) {
return validContextEnhancementPayload(payload)
? null : '请提交有效的上下文增强设置。';
}
if (endpoint === SLACK_ENDPOINTS.setAccessPolicy) {
return validAccessPolicyPayload(payload)
? null : '请提交有效的访问设置。';
}
return 'Unknown Slack endpoint.';
}
@ -164,6 +170,10 @@ export function createSlackRpcHandler(controller) {
if (typeof controller.updateContextEnhancement !== 'function') throw new Error('Context enhancement update is unavailable');
value = await controller.updateContextEnhancement(payload.botId, payload.config);
}
else if (endpoint === SLACK_ENDPOINTS.setAccessPolicy) {
if (typeof controller.updateAccessPolicy !== 'function') throw new Error('Access policy update is unavailable');
value = await controller.updateAccessPolicy(payload.botId, payload.policy);
}
else if (endpoint === SLACK_ENDPOINTS.setAgentPreset) {
if (typeof controller.updateAgentPreset !== 'function') throw new Error('Agent preset update is unavailable');
value = await controller.updateAgentPreset(payload.botId, payload.agentPreset);