模块 2 · 平台鉴权

get_platform_auth_context:
只要 JWT,不要 X-Agent-Type

对话线(/api/chat)必须带 X-Agent-Type; 平台读 API 故意不要——App 和仪表盘只证明「你是谁」,不声明「你在敲哪扇 Agent 窗」。

和 chat 鉴权的对照表

场景函数X-Agent-Type归属断言
平台 RESTget_platform_auth_context不要assert_platform_customer_access
对话 / 风控 RESTget_auth_context必须assert_customer_access + 准入矩阵
指挥 AI 接前端时: apiFetch 读持仓只带 Bearer;若误加 X-Agent-Type: customer,平台路由会忽略,但混进 chat 路由就会多一层校验甚至 401。

群聊:前端问「张三持仓多少」

理财师工作台发 GET 持仓——只走平台三层,不进 LangGraph。

deps.py
def get_platform_auth_context(request: Request) -> AuthContext:
    """平台 API 鉴权:JWT 通道 **不要求** X-Agent-Type。"""
    auth_header = request.headers.get("Authorization", "")
    if auth_header[:7].lower() == "bearer ":
        claims = verify_token(token)
        return _bind_state(request, _claims_to_auth(claims))
    # dev:X-Debug-Role / X-Debug-Actor 兜底
白话

函数名就写死:平台鉴权,不读 X-Agent-Type。

有 Bearer 就验 JWT,解析出 actor_id 和 roles。

本地开发没 JWT 时,可用 debug 头冒充身份(仅 development)。

和 get_auth_context 不同:后者在 JWT 通道会强制校验 X-Agent-Type + 准入矩阵。

分析员「问数工作台」调 /api/analyst/chat,要带 X-Agent-Type: analyst 吗?