feat(portal-shell): implement portal-shell with apollo-router integration

M8: portal-shell unified frontend shell (Modular Monolith + micro-kernel).

- Apollo Client -> apollo-router (port 4010, RSC prefetch)

- 5 layouts: classic/focus/split/triple/canvas

- Registry + PluginLoader (dynamic import ssr:false)

- 3-layer props merge, Zustand PluginStore

- 4 widgets: grades/notification-bell/user-menu/class-selector

- config-service: new pluginConfig GraphQL resolver

- apollo-router: CORS + header propagation for portal-shell

- docker-compose.yml: portal-shell service block
This commit is contained in:
SpecialX
2026-07-15 08:06:09 +08:00
parent 47e950c664
commit 514e26ebb4
49 changed files with 2802 additions and 6 deletions

View File

@@ -27,10 +27,12 @@ cors:
- "http://localhost:4001"
- "http://localhost:4002"
- "http://localhost:4003"
- "http://localhost:4010"
- "http://teacher-portal:4000"
- "http://student-portal:4001"
- "http://parent-portal:4002"
- "http://admin-portal:4003"
- "http://portal-shell:4010"
methods:
- GET
- POST
@@ -45,12 +47,22 @@ cors:
# 向所有子图注入 Router-Authorization HeaderADR-036
# 子图的 RouterAuthGuard 校验此 Header拒绝非 Router 的直接 GraphQL 请求
# 同时透传用户身份头x-user-id / x-user-role与 Authorization 到子图,
# 供 iam/core-edu/msg 等子图做用户级鉴权M8portal-shell 查询走 Router
headers:
all:
request:
- add:
name: "router-authorization"
value: "${env.ROUTER_AUTH_SECRET}"
- propagate:
named: "Authorization"
- propagate:
named: "x-user-id"
- propagate:
named: "x-user-role"
- propagate:
named: "X-Request-Id"
# 流量控制
traffic_shaping: