docs: integrate account authorization model
This commit is contained in:
1 parent
191c1a1aad
commit
ffda0d5f3f
6 files changed
+108
-6
No files matched your search
@@ -4,6 +4,11 @@
|
||||
|
||||
- `agent设计规范/business-adaptation-registry.md` is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.
|
||||
- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
|
||||
- The platform exposes one fixed deployment scope, not an organization-management product. Accounts use `admin`, `team_lead`, and `user` roles.
|
||||
- Administrators always hold all 18 manual business routes. Team leads and ordinary users start with no task grants, require explicit administrator allowlists, and may use normal task APIs only for their own manual tasks.
|
||||
- A known ungranted route or a non-unique/unresolved route for a non-administrator fails before parsing, plugin dispatch, or ERP execution. Authorization is rechecked for supplemental input, attachments, confirmation, automatic confirmation, and browser claim.
|
||||
- Team leads may read all manual account work only through the operations dashboard's who/instruction/result projection; this does not grant cross-user task mutation, artifacts, SSE, technical payloads, global settings, audit administration, or AgentBus access.
|
||||
- Creator and input-turn attribution are durable, business inputs remain encrypted at rest, denial audit excludes plaintext, and routine task removal uses archive/restore rather than physical purge.
|
||||
- The two passenger-list import routes are Program-only and wait for exactly one `.xls` or `.xlsx` attachment before deterministic normalization.
|
||||
- A WeChat attachment card is transport placeholder text, not file content. Only a structured `payload.attachments[]` entry can resume a roster task; missing metadata fails before ingestion and leaves the original task in `awaiting_attachment` instead of creating a new task.
|
||||
- The trusted internal deployment accepts credential-free HTTPS roster attachment URLs whose host is internal, private/reserved IPv4/IPv6, or localhost. DNS pinning, redirect revalidation, download timeout, byte limits, declared-size checks, and optional SHA-256 verification remain mandatory.
|
||||
@@ -22,4 +27,4 @@
|
||||
|
||||
## Last Reviewed
|
||||
|
||||
2026-08-31
|
||||
2026-09-01
|
||||
Reference in new issue
Block a user