feat(portal-shell): implement portal-shell with apollo-router integration
M8: portal-shell unified frontend shell (Modular Monolith + micro-kernel). - Apollo Client -> apollo-router (port 4010, RSC prefetch) - 5 layouts: classic/focus/split/triple/canvas - Registry + PluginLoader (dynamic import ssr:false) - 3-layer props merge, Zustand PluginStore - 4 widgets: grades/notification-bell/user-menu/class-selector - config-service: new pluginConfig GraphQL resolver - apollo-router: CORS + header propagation for portal-shell - docker-compose.yml: portal-shell service block
This commit is contained in:
@@ -27,10 +27,12 @@ cors:
|
||||
- "http://localhost:4001"
|
||||
- "http://localhost:4002"
|
||||
- "http://localhost:4003"
|
||||
- "http://localhost:4010"
|
||||
- "http://teacher-portal:4000"
|
||||
- "http://student-portal:4001"
|
||||
- "http://parent-portal:4002"
|
||||
- "http://admin-portal:4003"
|
||||
- "http://portal-shell:4010"
|
||||
methods:
|
||||
- GET
|
||||
- POST
|
||||
@@ -45,12 +47,22 @@ cors:
|
||||
|
||||
# 向所有子图注入 Router-Authorization Header(ADR-036)
|
||||
# 子图的 RouterAuthGuard 校验此 Header,拒绝非 Router 的直接 GraphQL 请求
|
||||
# 同时透传用户身份头(x-user-id / x-user-role)与 Authorization 到子图,
|
||||
# 供 iam/core-edu/msg 等子图做用户级鉴权(M8:portal-shell 查询走 Router)
|
||||
headers:
|
||||
all:
|
||||
request:
|
||||
- add:
|
||||
name: "router-authorization"
|
||||
value: "${env.ROUTER_AUTH_SECRET}"
|
||||
- propagate:
|
||||
named: "Authorization"
|
||||
- propagate:
|
||||
named: "x-user-id"
|
||||
- propagate:
|
||||
named: "x-user-role"
|
||||
- propagate:
|
||||
named: "X-Request-Id"
|
||||
|
||||
# 流量控制
|
||||
traffic_shaping:
|
||||
|
||||
Reference in New Issue
Block a user