- Added `auth.py` for mock login and JWT issuance. - Introduced `chat.py` for handling chat requests with role-based access control. - Enhanced `main.py` to include new routers and middleware for tracing. - Implemented input validation in `input_guard.py` to prevent SQL injection. - Created repositories for managing agent sessions and audit logs. - Added exception handling for authorization errors. - Updated settings to include JWT configuration. - Introduced tests for authentication and input validation.
68 lines
1.8 KiB
Python
68 lines
1.8 KiB
Python
"""Pydantic 请求/响应模型、AuthContext 等。"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from typing import Any, Literal
|
|
|
|
from pydantic import BaseModel, Field
|
|
|
|
AgentType = Literal["customer", "advisor", "analyst", "risk"]
|
|
TokenType = Literal["customer", "staff", "service"]
|
|
|
|
|
|
class AuthContext(BaseModel):
|
|
"""网关校验后注入业务层的身份上下文。"""
|
|
|
|
sub: str
|
|
token_type: TokenType
|
|
roles: list[str]
|
|
permissions: list[str] = Field(default_factory=list)
|
|
tenant_id: str = "default"
|
|
trace_id: str
|
|
agent_type: AgentType
|
|
jti: str
|
|
customer_id: str | None = None
|
|
|
|
def has_role(self, role: str) -> bool:
|
|
return role in self.roles
|
|
|
|
def has_perm(self, perm: str) -> bool:
|
|
if perm in self.permissions:
|
|
return True
|
|
prefix = perm.split(":")[0]
|
|
return any(p.startswith(f"{prefix}:") and p.endswith(":*") for p in self.permissions)
|
|
|
|
|
|
class LoginRequest(BaseModel):
|
|
actor_id: str = Field(..., description="customer_id 或 staff_id")
|
|
token_type: TokenType = "staff"
|
|
roles: list[str] | None = Field(default=None, description="开发期可覆盖角色,默认按 actor_id 推断")
|
|
|
|
|
|
class LoginResponseData(BaseModel):
|
|
access_token: str
|
|
token_type: str = "Bearer"
|
|
expires_in: int
|
|
sub: str
|
|
roles: list[str]
|
|
|
|
|
|
class ChatRequest(BaseModel):
|
|
message: str = Field(..., min_length=1, max_length=8000)
|
|
session_id: str | None = None
|
|
customer_id: str | None = Field(default=None, description="员工 Agent 查询目标客户时使用")
|
|
|
|
|
|
class ChatResponseData(BaseModel):
|
|
session_id: str
|
|
reply: str
|
|
agent_type: AgentType
|
|
has_disclaimer: bool = False
|
|
|
|
|
|
class ApiResponse(BaseModel):
|
|
code: int = 0
|
|
message: str = "ok"
|
|
data: Any = None
|
|
trace_id: str
|