Files
tkmind_go/ui/h5/security-baseline.mjs
john 4e21ca937a
Deploy Documentation / deploy (push) Has been cancelled
Canary / Prepare Version (push) Has been cancelled
Canary / build-cli (push) Has been cancelled
Canary / Upload Install Script (push) Has been cancelled
Canary / bundle-desktop (push) Has been cancelled
Canary / bundle-desktop-intel (push) Has been cancelled
Canary / bundle-desktop-linux (push) Has been cancelled
Canary / bundle-desktop-windows (push) Has been cancelled
Canary / bundle-desktop-windows-cuda (push) Has been cancelled
Canary / Release (push) Has been cancelled
Unused Dependencies / machete (push) Has been cancelled
CI / changes (push) Has been cancelled
CI / Check Rust Code Format (push) Has been cancelled
CI / Build and Test Rust Project (push) Has been cancelled
CI / Build Rust Project on Windows (push) Has been cancelled
CI / Check MSRV (push) Has been cancelled
CI / Lint Rust Code (push) Has been cancelled
CI / Check Generated Schemas are Up-to-Date (push) Has been cancelled
CI / Test and Lint Electron Desktop App (push) Has been cancelled
CI / H5 Plaza Tests and Build (push) Has been cancelled
Live Provider Tests / check-fork (push) Has been cancelled
Live Provider Tests / changes (push) Has been cancelled
Live Provider Tests / Build Binary (push) Has been cancelled
Live Provider Tests / Smoke Tests (push) Has been cancelled
Live Provider Tests / Smoke Tests (Code Execution) (push) Has been cancelled
Live Provider Tests / Compaction Tests (push) Has been cancelled
Live Provider Tests / goose server HTTP integration tests (push) Has been cancelled
Publish Ask AI Bot Docker Image / docker (push) Has been cancelled
Publish Docker Image / docker (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Add TKMind platform extensions, H5/MindSpace stack, and deployment tooling.
Fork goose with custom MCP widgets, platform extensions (aider, git, web, search),
MindSpace H5 backend/frontend, Plaza/Ops UIs, and deploy scripts for tkmind.cn.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-14 21:30:20 +08:00

59 lines
1.8 KiB
JavaScript

import {
catalogKeys,
DEFAULT_USER_CAPABILITIES,
USER_NON_GRANTABLE_CAPABILITIES,
} from './capabilities.mjs';
import { DEFAULT_USER_POLICIES, policyKeys } from './policies.mjs';
export function productionRoleCapabilities() {
return {
...DEFAULT_USER_CAPABILITIES,
context_memory: false,
memory_store: false,
chat_recall: false,
charts: false,
todo: false,
image_read: true,
};
}
export function productionRolePolicies() {
return { ...DEFAULT_USER_POLICIES };
}
export async function applyRoleSecurityBaseline(pool, role = 'user') {
const now = Date.now();
const capabilities = productionRoleCapabilities();
for (const key of catalogKeys()) {
const allowed = USER_NON_GRANTABLE_CAPABILITIES.has(key)
? false
: Boolean(capabilities[key]);
await pool.query(
`INSERT INTO h5_capability_grants (subject_type, subject_id, capability_key, allowed, updated_at)
VALUES ('role', ?, ?, ?, ?)
ON DUPLICATE KEY UPDATE allowed = VALUES(allowed), updated_at = VALUES(updated_at)`,
[role, key, allowed ? 1 : 0, now],
);
}
const policies = productionRolePolicies();
for (const key of policyKeys()) {
await pool.query(
`INSERT INTO h5_user_policies (subject_type, subject_id, policy_key, policy_value, updated_at)
VALUES ('role', ?, ?, ?, ?)
ON DUPLICATE KEY UPDATE policy_value = VALUES(policy_value), updated_at = VALUES(updated_at)`,
[role, key, String(policies[key]), now],
);
}
}
export async function clearUserPermissionOverrides(pool) {
await pool.query(`DELETE FROM h5_capability_grants WHERE subject_type = 'user'`);
await pool.query(`DELETE FROM h5_user_policies WHERE subject_type = 'user'`);
}
export async function applyProductionSecurityBaseline(pool) {
await applyRoleSecurityBaseline(pool, 'user');
await clearUserPermissionOverrides(pool);
}