fix: add missing @RequirePermission decorators

Adds @RequirePermission to 19 TS GraphQL resolvers across 5
subgraphs (iam, config-service, core-edu, content, msg) per
audit report §6.1. Maps: iam user/role -> IAM_USER_READ;
config-service 5 queries -> CONFIG_USER; core-edu classInfo ->
CLASS_READ, exam -> EXAM_READ, grade -> GRADE_READ, homework
-> HOMEWORK_READ, datascope visibleGrades/visibleExams ->
GRADE_READ/EXAM_READ; content chapter/knowledgePoint/question/
textbook -> CONTENT_*_READ; msg notifications ->
MSG_NOTIFICATION_READ, template -> MSG_NOTIFICATION_MANAGE.
Federation resolveReference left unguarded. Python subgraphs
(data-ana, ai) deferred to follow-up infrastructure work.
This commit is contained in:
SpecialX
2026-07-17 13:26:58 +08:00
parent 315b954998
commit 1b5781bf42
17 changed files with 117 additions and 30 deletions

View File

@@ -19,6 +19,10 @@ import {
DataLoaderService,
type KnowledgePointEntity,
} from "../dataloader.service.js";
import {
Permissions,
RequirePermission,
} from "../../middleware/permission.guard.js";
/**
* KnowledgePoint ObjectTypeFederation @key
@@ -36,7 +40,7 @@ export class KnowledgePoint {
@Field()
title!: string;
@Field({ nullable: true })
@Field(() => String, { nullable: true })
description: string | null = null;
@Field()
@@ -71,6 +75,7 @@ export class KnowledgePointResolver {
* 通过 Apollo Router 访问,直连被 RouterAuthGuard 拒绝ADR-036
*/
@Query(() => KnowledgePoint, { nullable: true })
@RequirePermission(Permissions.CONTENT_KNOWLEDGE_POINT_READ)
async knowledgePoint(
@Args("id", { type: () => ID }) id: string,
): Promise<KnowledgePointEntity | null> {