feat: harden data access and simplify user management
This commit is contained in:
1 parent
3dd5731751
commit
adb780bc82
51 files changed
+3239
-2121
No files matched your search
+35
-20
@@ -372,6 +372,7 @@ export type InterfaceSummary = {
|
||||
active_policies: number;
|
||||
calls_24h: number;
|
||||
errors_24h: number;
|
||||
active_dbeaver_grants?: number;
|
||||
data_engine: string;
|
||||
public_base_path: string;
|
||||
direct_database_access: string;
|
||||
@@ -382,7 +383,12 @@ export type InterfaceSummary = {
|
||||
ssh_tunnel_required?: boolean;
|
||||
ssh_host?: string;
|
||||
ssh_port?: number;
|
||||
ssh_username?: string;
|
||||
ssh_auth_method?: string;
|
||||
managed_access_enabled?: boolean;
|
||||
ssh_key_auto_install?: boolean;
|
||||
account_provisioning_ready?: boolean;
|
||||
ssh_host_key_fingerprint?: string;
|
||||
database_host?: string;
|
||||
database_port?: number;
|
||||
database_account_policy?: string;
|
||||
@@ -396,6 +402,28 @@ export type InterfaceSummary = {
|
||||
backup_retention_days?: number;
|
||||
};
|
||||
|
||||
export type DbeaverAccessGrant = {
|
||||
id: string;
|
||||
display_name: string;
|
||||
mysql_username: string;
|
||||
mysql_password?: string;
|
||||
password_shown_once?: boolean;
|
||||
database_id: string;
|
||||
database_name: string;
|
||||
permission_level: "read" | "write";
|
||||
ssh_key_type: string;
|
||||
ssh_key_fingerprint: string;
|
||||
ssh_host?: string;
|
||||
ssh_port?: number;
|
||||
ssh_username?: string;
|
||||
database_host?: string;
|
||||
database_port?: number;
|
||||
created_by?: string;
|
||||
status: "active" | "revoked";
|
||||
revoked_at?: string | null;
|
||||
created_at?: string;
|
||||
};
|
||||
|
||||
export type InterfaceClient = {
|
||||
id: string;
|
||||
name: string;
|
||||
@@ -477,6 +505,12 @@ export const getInterfaceCenterSummary = () =>
|
||||
api.get<InterfaceSummary>("/interface-center/summary");
|
||||
export const getInterfaceCenterCatalog = () =>
|
||||
api.get<InterfaceCatalogDatabase[]>("/interface-center/catalog");
|
||||
export const listDbeaverAccessGrants = () =>
|
||||
api.get<DbeaverAccessGrant[]>("/interface-center/dbeaver-access");
|
||||
export const issueDbeaverAccess = (data: unknown) =>
|
||||
api.post<DbeaverAccessGrant>("/interface-center/dbeaver-access", data);
|
||||
export const revokeDbeaverAccess = (grantId: string) =>
|
||||
api.post(`/interface-center/dbeaver-access/${encodeURIComponent(grantId)}/revoke`, {});
|
||||
export const listInterfaceClients = () =>
|
||||
api.get<InterfaceClient[]>("/interface-center/clients");
|
||||
export const createInterfaceClient = (data: unknown) =>
|
||||
@@ -541,30 +575,11 @@ export const graphOverview = () => api.get("/graph/overview");
|
||||
export const graphQuery = (cypher: string, limit = 200) =>
|
||||
api.post("/graph/query", { cypher, limit });
|
||||
|
||||
// ── RBAC & Accounts (P1) ──
|
||||
export const listRoles = () => api.get("/roles");
|
||||
export const createRole = (data: unknown) => api.post("/roles", data);
|
||||
export const updateRole = (roleKey: string, data: unknown) =>
|
||||
api.patch(`/roles/${roleKey}`, data);
|
||||
export const deleteRole = (roleKey: string) => api.delete(`/roles/${roleKey}`);
|
||||
|
||||
export const listCapabilities = () => api.get("/capabilities");
|
||||
export const createCapability = (data: unknown) => api.post("/capabilities", data);
|
||||
export const deleteCapability = (capKey: string) =>
|
||||
api.delete(`/capabilities/${capKey}`);
|
||||
|
||||
export const getPermissionMatrix = () => api.get("/permission-matrix");
|
||||
export const setPermissionCell = (
|
||||
roleKey: string,
|
||||
capKey: string,
|
||||
value: string
|
||||
) => api.put("/permission-matrix", { role_key: roleKey, cap_key: capKey, value });
|
||||
|
||||
// ── User management ──
|
||||
export const listUsers = () => api.get("/users");
|
||||
export const createUser = (data: unknown) => api.post("/users", data);
|
||||
export const updateUser = (id: number, data: unknown) =>
|
||||
api.patch(`/users/${id}`, data);
|
||||
export const deleteUser = (id: number) => api.delete(`/users/${id}`);
|
||||
|
||||
// ── Super Agent (autonomous KG curator) ──
|
||||
export const superAgentRun = () => api.post("/super-agent/run", {});
|
||||
|
||||
Reference in new issue
Block a user