Add TKMind platform extensions, H5/MindSpace stack, and deployment tooling.
Deploy Documentation / deploy (push) Has been cancelled
Canary / Prepare Version (push) Has been cancelled
Canary / build-cli (push) Has been cancelled
Canary / Upload Install Script (push) Has been cancelled
Canary / bundle-desktop (push) Has been cancelled
Canary / bundle-desktop-intel (push) Has been cancelled
Canary / bundle-desktop-linux (push) Has been cancelled
Canary / bundle-desktop-windows (push) Has been cancelled
Canary / bundle-desktop-windows-cuda (push) Has been cancelled
Canary / Release (push) Has been cancelled
Unused Dependencies / machete (push) Has been cancelled
CI / changes (push) Has been cancelled
CI / Check Rust Code Format (push) Has been cancelled
CI / Build and Test Rust Project (push) Has been cancelled
CI / Build Rust Project on Windows (push) Has been cancelled
CI / Check MSRV (push) Has been cancelled
CI / Lint Rust Code (push) Has been cancelled
CI / Check Generated Schemas are Up-to-Date (push) Has been cancelled
CI / Test and Lint Electron Desktop App (push) Has been cancelled
CI / H5 Plaza Tests and Build (push) Has been cancelled
Live Provider Tests / check-fork (push) Has been cancelled
Live Provider Tests / changes (push) Has been cancelled
Live Provider Tests / Build Binary (push) Has been cancelled
Live Provider Tests / Smoke Tests (push) Has been cancelled
Live Provider Tests / Smoke Tests (Code Execution) (push) Has been cancelled
Live Provider Tests / Compaction Tests (push) Has been cancelled
Live Provider Tests / goose server HTTP integration tests (push) Has been cancelled
Publish Ask AI Bot Docker Image / docker (push) Has been cancelled
Publish Docker Image / docker (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Deploy Documentation / deploy (push) Has been cancelled
Canary / Prepare Version (push) Has been cancelled
Canary / build-cli (push) Has been cancelled
Canary / Upload Install Script (push) Has been cancelled
Canary / bundle-desktop (push) Has been cancelled
Canary / bundle-desktop-intel (push) Has been cancelled
Canary / bundle-desktop-linux (push) Has been cancelled
Canary / bundle-desktop-windows (push) Has been cancelled
Canary / bundle-desktop-windows-cuda (push) Has been cancelled
Canary / Release (push) Has been cancelled
Unused Dependencies / machete (push) Has been cancelled
CI / changes (push) Has been cancelled
CI / Check Rust Code Format (push) Has been cancelled
CI / Build and Test Rust Project (push) Has been cancelled
CI / Build Rust Project on Windows (push) Has been cancelled
CI / Check MSRV (push) Has been cancelled
CI / Lint Rust Code (push) Has been cancelled
CI / Check Generated Schemas are Up-to-Date (push) Has been cancelled
CI / Test and Lint Electron Desktop App (push) Has been cancelled
CI / H5 Plaza Tests and Build (push) Has been cancelled
Live Provider Tests / check-fork (push) Has been cancelled
Live Provider Tests / changes (push) Has been cancelled
Live Provider Tests / Build Binary (push) Has been cancelled
Live Provider Tests / Smoke Tests (push) Has been cancelled
Live Provider Tests / Smoke Tests (Code Execution) (push) Has been cancelled
Live Provider Tests / Compaction Tests (push) Has been cancelled
Live Provider Tests / goose server HTTP integration tests (push) Has been cancelled
Publish Ask AI Bot Docker Image / docker (push) Has been cancelled
Publish Docker Image / docker (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Fork goose with custom MCP widgets, platform extensions (aider, git, web, search), MindSpace H5 backend/frontend, Plaza/Ops UIs, and deploy scripts for tkmind.cn. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
import {
|
||||
catalogKeys,
|
||||
DEFAULT_USER_CAPABILITIES,
|
||||
USER_NON_GRANTABLE_CAPABILITIES,
|
||||
} from './capabilities.mjs';
|
||||
import { DEFAULT_USER_POLICIES, policyKeys } from './policies.mjs';
|
||||
|
||||
export function productionRoleCapabilities() {
|
||||
return {
|
||||
...DEFAULT_USER_CAPABILITIES,
|
||||
context_memory: false,
|
||||
memory_store: false,
|
||||
chat_recall: false,
|
||||
charts: false,
|
||||
todo: false,
|
||||
image_read: true,
|
||||
};
|
||||
}
|
||||
|
||||
export function productionRolePolicies() {
|
||||
return { ...DEFAULT_USER_POLICIES };
|
||||
}
|
||||
|
||||
export async function applyRoleSecurityBaseline(pool, role = 'user') {
|
||||
const now = Date.now();
|
||||
const capabilities = productionRoleCapabilities();
|
||||
for (const key of catalogKeys()) {
|
||||
const allowed = USER_NON_GRANTABLE_CAPABILITIES.has(key)
|
||||
? false
|
||||
: Boolean(capabilities[key]);
|
||||
await pool.query(
|
||||
`INSERT INTO h5_capability_grants (subject_type, subject_id, capability_key, allowed, updated_at)
|
||||
VALUES ('role', ?, ?, ?, ?)
|
||||
ON DUPLICATE KEY UPDATE allowed = VALUES(allowed), updated_at = VALUES(updated_at)`,
|
||||
[role, key, allowed ? 1 : 0, now],
|
||||
);
|
||||
}
|
||||
|
||||
const policies = productionRolePolicies();
|
||||
for (const key of policyKeys()) {
|
||||
await pool.query(
|
||||
`INSERT INTO h5_user_policies (subject_type, subject_id, policy_key, policy_value, updated_at)
|
||||
VALUES ('role', ?, ?, ?, ?)
|
||||
ON DUPLICATE KEY UPDATE policy_value = VALUES(policy_value), updated_at = VALUES(updated_at)`,
|
||||
[role, key, String(policies[key]), now],
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
export async function clearUserPermissionOverrides(pool) {
|
||||
await pool.query(`DELETE FROM h5_capability_grants WHERE subject_type = 'user'`);
|
||||
await pool.query(`DELETE FROM h5_user_policies WHERE subject_type = 'user'`);
|
||||
}
|
||||
|
||||
export async function applyProductionSecurityBaseline(pool) {
|
||||
await applyRoleSecurityBaseline(pool, 'user');
|
||||
await clearUserPermissionOverrides(pool);
|
||||
}
|
||||
Reference in New Issue
Block a user