Harden auth scopes, SQL/WebCRT gates, and per-install JWT secrets.

Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-02 16:24:34 +08:00
parent cb8e0d23c5
commit 633a9d55bd
38 changed files with 1808 additions and 452 deletions

View file

@ -13,6 +13,8 @@ export type ModuleDefinition = {
descKey?: string;
iconTone: ModuleIconTone;
titleKey: string;
/** Required capability scope to show in workbench (admin bypasses). */
requiredScope?: string;
adminOnly?: boolean;
/** Hide from workbench launcher; still used for module window registration. */
workbenchHidden?: boolean;
@ -63,6 +65,7 @@ export const MODULES: readonly ModuleDefinition[] = [
descKey: "workbench.cards.webcrtDesc",
iconTone: "slate",
titleKey: "layout.titleWebcrt",
requiredScope: "webcrt:session",
},
{
moduleId: "port-traffic-wall",