角色与访问控制

wesgine 的 Token 作用域体系与请求鉴权模型。


Token 层次

Admin Token

Hypervisor 级签发,用于管理所有 Cell。

hyp.Tokens().IssueAdminToken(ttl) string
hyp.Tokens().RevokeAdminToken(id) error

HTTP 端点:

Cell Token

Cell 级签发,用于操作单个 Cell。

cell.Tokens().Issue(ttl) string
cell.Tokens().Revoke(id) error

HTTP 端点:


Scope 体系

Cell Token 签发时指定 scope:

Scope含义
cell:read只读访问
cell:chat对话与会话变更
cell:adminCell 级管理操作

defaultCellRequiredScope

Gateway 中间件根据请求路径自动映射所需 scope。

/memory 非 GET 一律需要 cell:admin(INV-MEM-45)。

/observe/evidence 和 /audit/* 需要 cell:admin(INV-OBS-09),且必须排在 /observe 泛前缀之前。


Actor 与 Token 的关系

Admin Token 的空 actor 表示管理视图。

Cell Token 携带 actor 信息,actorFromRequestOrContext(req) 提取: