refactor(auth): delegate access control to be-system

Remove Agent Desk users, roles, login sessions, tokens, and local permission persistence. Expose the backend as an embeddable ai-agent module with host-provided subject lookup and operation authorization callbacks, and complete the frontend/backend repository split.
This commit is contained in:
t
2026-08-21 00:41:07 +08:00
parent 3d47227fbd
commit 2bbf42b741
447 changed files with 1901 additions and 8920 deletions
@@ -1,13 +1,15 @@
package services
import (
"context"
"encoding/json"
"strings"
"testing"
"time"
"agent-desk/internal/models"
"agent-desk/internal/pkg/enums"
"code.tczkiot.com/wlw/ai-agent/identity"
"code.tczkiot.com/wlw/ai-agent/internal/models"
"code.tczkiot.com/wlw/ai-agent/internal/pkg/enums"
"github.com/glebarez/sqlite"
"github.com/mlogclub/simple/sqls"
@@ -141,7 +143,6 @@ func setupHumanDispatchRealtimeTestDB(t *testing.T) *gorm.DB {
}
})
if err := db.AutoMigrate(
&models.User{},
&models.Notification{},
&models.Customer{},
&models.CustomerIdentity{},
@@ -200,14 +201,16 @@ func createHumanDispatchRealtimeActiveSchedule(t *testing.T, db *gorm.DB, teamID
func createHumanDispatchRealtimeAgentProfile(t *testing.T, db *gorm.DB, userID, teamID int64) {
t.Helper()
if err := db.Create(&models.User{
ID: userID,
Username: "agent",
Nickname: "客服",
Status: enums.StatusOk,
}).Error; err != nil {
t.Fatalf("create user error = %v", err)
}
SetQuerySubjects(func(_ context.Context, query identity.Query) ([]identity.Subject, error) {
if len(query.IDs) > 0 && query.IDs[0] != userID {
return nil, nil
}
return []identity.Subject{{
Type: identity.SubjectAgent, Category: identity.CategorySystem,
ID: userID, Username: "agent", Name: "客服", Enabled: true,
}}, nil
})
SetAuthorize(func(_ context.Context, _ string) error { return nil })
if err := db.Create(&models.AgentProfile{
UserID: userID,
TeamID: teamID,