refactor(auth): delegate access control to be-system

Remove Agent Desk users, roles, login sessions, tokens, and local permission persistence. Expose the backend as an embeddable ai-agent module with host-provided subject lookup and operation authorization callbacks, and complete the frontend/backend repository split.
This commit is contained in:
t
2026-08-21 00:41:07 +08:00
parent 3d47227fbd
commit 2bbf42b741
447 changed files with 1901 additions and 8920 deletions
-13
View File
@@ -17,11 +17,6 @@ logger:
format: text
addSource: false
auth:
tokenTTLHours: 24
maxFailedAttempts: 5
credentialLockMinute: 30
storage:
default: local
maxUploadSizeMB: 5
@@ -58,11 +53,3 @@ mcp:
wxWork:
enabled: false
oidc:
enabled: false
customerSession:
secret: change-me
ttlMinutes: 120
refreshThresholdMinutes: 30
-24
View File
@@ -21,16 +21,6 @@ logger:
format: text
addSource: false
auth:
tokenTTLHours: 12
maxFailedAttempts: 5
credentialLockMinute: 15
customerSession:
secret: replace-with-a-random-secret
ttlMinutes: 120
refreshThresholdMinutes: 30
storage:
default: local
maxUploadSizeMB: 20
@@ -70,8 +60,6 @@ wxWork:
corpId: ""
corpSecret: ""
agentId: ""
oauthRedirect: ""
stateSecret: ""
rsaPrivateKey: ""
token: ""
encodingAESKey: ""
@@ -81,15 +69,3 @@ wxWork:
safe: false
enableDuplicateCheck: true
duplicateCheckInterval: 1800
oidc:
enabled: false
issuer: ""
clientId: ""
clientSecret: ""
redirectUrl: http://127.0.0.1:8083/api/auth/oidc_callback
stateSecret: ""
scopes:
- openid
- profile
- email
-12
View File
@@ -22,16 +22,6 @@ logger:
format: text
addSource: false
auth:
tokenTTLHours: 12
maxFailedAttempts: 5
credentialLockMinute: 15
customerSession:
secret: replace-with-a-random-secret
ttlMinutes: 120
refreshThresholdMinutes: 30
storage:
default: local
maxUploadSizeMB: 20
@@ -72,8 +62,6 @@ wxWork:
corpId: ""
corpSecret: ""
agentId: ""
oauthRedirect: ""
stateSecret: ""
rsaPrivateKey: ""
token: ""
encodingAESKey: ""