Core platform · ws_suns · 07/7/2026

rt-authz — Permission engine (runtime) CORE

Engine phân quyền runtime: rt_role (grants JSONB: module/group/feature/action + field + rule-predicate + deny), resolve thuần có test được, rt_permission_epoch invalidate cache, guard requirePermission + accessor row-filter.

Đánh giá: ✅ Thiết kế tốt · ⚠ chưa nối hết · Chi tiết khuyến nghị ở mục 3 — tham chiếu hệ thống phổ biến.
1

Thành phần chính

Thành phầnVai trò
rt_role · rt_role_assignment · rt_permission_epoch3 bảng — một nguồn sự thật grants; epoch bump khi sửa quyền
resolve.jsMerge grants (inherits ≤2 tầng, deny-wins, OR rule) — hàm thuần, unit-test không cần DB
guard.js · predicate.jsrequirePermission (opt-in) + buildWhere an toàn (parametrized, field allowlist)
authorize.jsHybrid UNION CP-cache + engine — giai đoạn chuyển tiếp RT-14
2

Hiện trạng (đọc từ code)

  • Thiết kế grants ngang tầm Casbin/OPA thu nhỏ: deny-wins, inherits, custom action, field & row-level đã chừa sẵn cấu trúc
  • Predicate → Sequelize where parametrized + allowlist field — chống injection & leak đúng cách
  • ⚠ guard/requirePermission và row-filter chưa gắn vào route nào (opt-in, chờ RT-16 di cư role)
  • ⚠ Data scope: đã có plan 5 phase (~3 MM) — manifest fields/scopeVars + ctxVars + seed role
3

Khuyến nghị — tham chiếu hệ phổ biến

Tham chiếuKhuyến nghị
Casbin/OPA — single authorityChạy plan data-scope P1→P5, pilot module student; sau RT-16 gỡ nhánh CP-cache trong authorize.js — một chỗ duy nhất trả lời 'ai được làm gì thấy gì'
Odoo record rulesGiữ nguyên hướng rule-predicate trong rt_role (đúng mô hình Odoo ir.rule) — chính sách theo trung tâm nằm ở data, không ở manifest
Test bất biếnresolve.js là hàm thuần — bổ sung bộ test property (deny thắng allow mọi thứ tự, union không mất quyền) trước khi di cư role thật
4

Liên kết trong core

  • cp-rbac — sync roles từ CP (origin cp/local)
  • rt-host — seedRoleTemplates + bump epoch lúc install
  • plan data-scope — lộ trình nối
Phân quyền

Ma trận tác nhân × năng lực

Core không phải module nghiệp vụ — thay ma trận vai trò bằng tác nhân × năng lực, kèm cơ chế/quyền gate từng năng lực. R đọc · W thực hiện · A duyệt.

Năng lựcCơ chế / quyền gateSUPEROWNER/QTHTDEVSVCUSER
CRUD rt_role (grants/rule)iam.administration.role-adminW
Gán role (rt_role_assignment)iam.administration.role-adminW
Bump epoch khi đổi quyềntự động trong transactionW
Resolve + enforce mỗi requestmiddleware requirePermission/scopeWhereW
Sync role từ CP (origin=cp)Bearer serviceW

SUPER = super admin CP · OWNER/QTHT = chủ workspace / quản trị WS · DEV = developer/publisher · SVC = service-to-service (runtime/hook) · USER = người dùng cuối. Mục ghi (đích) = theo khuyến nghị P1–P5, chưa có ở hiện trạng.