Harden auth scopes, SQL/WebCRT gates, and per-install JWT secrets.

Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-02 16:24:34 +08:00
parent cb8e0d23c5
commit 633a9d55bd
38 changed files with 1808 additions and 452 deletions

View file

@ -8,7 +8,7 @@ const SECTIONS: WorkbenchSection[] = ["monitoring", "operations", "system"];
export function WorkbenchPage() {
const { t } = useI18n();
const { isAdmin } = useAuth();
const { isAdmin, hasScope } = useAuth();
return (
<div className="workbench">
@ -19,6 +19,7 @@ export function WorkbenchPage() {
{modulesInSection(section)
.filter((mod) => !mod.workbenchHidden)
.filter((mod) => !mod.adminOnly || isAdmin)
.filter((mod) => !mod.requiredScope || hasScope(mod.requiredScope) || isAdmin)
.map((mod) => (
<button
key={mod.moduleId}