fix: 修复集成测试中发现的全部 bug — 15 服务端到端验证通过
修复涵盖 6 大类问题: 1. api-gateway - 路径前缀剥离 /api 而非 /api/v1,保留下游 /v1/ controller 前缀 - JWKS URL 默认值修复 - publicPaths 白名单对齐 /v1/iam/* 2. iam - iam.module.ts exports 补充 PermissionCacheService 和 IamRepository - main.ts resolveProtoPath() 多路径探测 proto 文件 3. core-edu - app.module.ts AuthMiddleware 全局注册 4. BFF 层 GraphQL 端点(teacher-bff / parent-bff / student-bff) - teacher-bff: mock dataScope OWN→SELF 对齐 GraphQL enum;WHATWG Request header .get() 提取 - parent-bff: handleNodeRequestAndResponse 不存在 → 直接 yoga(req,res);WHATWG Request header .get() 提取 - student-bff: auth.resolver 移除 ActionState 信封返回扁平对象;WHATWG Request header .get() 提取 5. ai - Kafka 事务降级 + 10s 超时 - gRPC 拦截器降级 - dev mode 禁用事务模式 6. 前端 + 共享包 - teacher-portal: MF 插件条件实例化 + transpilePackages + extensionAlias - ui-components: error-boundary.tsx 添加 use client - ui-tokens: tailwind-theme.css 移除 @layer base - shared-ts: 导出从源码改为 dist 编译产物;OutboxModule global:true 7. infra - .gitignore 补充 keys/ *.pem *.key secrets/ 排除规则 - infra/init-sql/02-all-services-schema.sql 36 张表 DDL 验证结果: - TS typecheck: 19 个 workspace 项目全部通过 - Go vet + Ruff: 通过 - 15 服务全部启动成功 - 3 个 BFF GraphQL 端点 + 4 个前端页面全部 200 - Gateway → iam → core-edu 端到端链路验证通过 AI identity: trae-main(集成测试修复会话)
This commit is contained in:
@@ -57,7 +57,7 @@ func Load() *Config {
|
||||
}
|
||||
|
||||
// 非 DevMode 下要求 JWKS URL(RS256 验签)
|
||||
jwksURL := getEnv("IAM_JWKS_URL", "http://localhost:3002/.well-known/jwks.json")
|
||||
jwksURL := getEnv("IAM_JWKS_URL", "http://localhost:3002/v1/iam/.well-known/jwks.json")
|
||||
if !devMode && jwksURL == "" {
|
||||
panic("IAM_JWKS_URL must be set in non-dev mode (RS256 JWT verification)")
|
||||
}
|
||||
|
||||
@@ -11,17 +11,19 @@ import (
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// publicPaths 是无需鉴权的公开路径(精确匹配,基于去掉 /api/v1 前缀后的路径)
|
||||
// publicPaths 是无需鉴权的公开路径(精确匹配,基于去掉 /api 前缀后的路径)
|
||||
// 下游 NestJS controller 路径为 /v1/iam/*
|
||||
var publicPaths = map[string]bool{
|
||||
"/iam/register": true,
|
||||
"/iam/login": true,
|
||||
"/iam/refresh": true,
|
||||
"/v1/iam/register": true,
|
||||
"/v1/iam/login": true,
|
||||
"/v1/iam/refresh": true,
|
||||
"/v1/iam/.well-known/jwks.json": true,
|
||||
}
|
||||
|
||||
// isPublicPath 判断请求路径是否属于公开路径(无需鉴权)
|
||||
// 匹配规则:去掉 /api/v1 前缀后,与 publicPaths 精确匹配
|
||||
// 匹配规则:去掉 /api 前缀后,与 publicPaths 精确匹配
|
||||
func isPublicPath(path string) bool {
|
||||
stripped := strings.TrimPrefix(path, "/api/v1")
|
||||
stripped := strings.TrimPrefix(path, "/api")
|
||||
return publicPaths[stripped]
|
||||
}
|
||||
|
||||
|
||||
@@ -19,8 +19,9 @@ func NewProxy(targetURL string) (*httputil.ReverseProxy, error) {
|
||||
originalDirector := proxy.Director
|
||||
proxy.Director = func(req *http.Request) {
|
||||
originalDirector(req)
|
||||
// 去除 /api/v1 前缀(Gateway 不改路径,直接透传给下游服务根路径)
|
||||
req.URL.Path = strings.TrimPrefix(req.URL.Path, "/api/v1")
|
||||
// 去除 /api 前缀,保留 /v1 下游 controller 前缀
|
||||
// 下游 NestJS controller 路径为 /v1/iam/*, /v1/exams/* 等
|
||||
req.URL.Path = strings.TrimPrefix(req.URL.Path, "/api")
|
||||
req.Host = target.Host
|
||||
}
|
||||
return proxy, nil
|
||||
|
||||
Reference in New Issue
Block a user