mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Working on https://github.com/agent-substrate/substrate/issues/1563 ## Summary Initializes an embedded OpenFGA server within `ateapi` backed by PostgreSQL and updates the top-level authorization scope. ## Key Changes - **Rename scope to `global`**: Renamed `type cluster` and `parent_cluster` to `type global` and `parent_global`, adding `can_set_policy` and `can_get_policy` to `global`. - **Embedded OpenFGA server (`internal/authz/server.go`)**: - Compiles `model.fga` into OpenFGA's protobuf representation. - Runs OpenFGA PostgreSQL schema migrations (`goose_db_version`). - Serializes startup via `pg_advisory_lock` to avoid multi-replica races. - Connects OpenFGA's PostgreSQL adapter with a new dedicated `*pgxpool.Pool`. - Idempotently creates or reuses the `"substrate"` store and authorization model. - **Service wiring (`cmd/ateapi`)**: Exposes `Pool()` on `*atepg.Persistence` and initializes `authz.NewServer` on bootstrap. ## Verification - `openfga model test`: 103/103 checks passing (`model_test.fga.yaml`). - `go test -mod=mod ./internal/authz/...`: Passes against PostgreSQL (migrations, tuple writes, permission checks, and restart idempotency).
25 lines
756 B
AMPL
25 lines
756 B
AMPL
module github.com/agent-substrate/substrate/tools/apitool
|
|
|
|
go 1.27.0
|
|
|
|
replace github.com/agent-substrate/substrate => ../..
|
|
|
|
require (
|
|
github.com/agent-substrate/substrate v0.0.0-00010101000000-000000000000
|
|
github.com/bufbuild/protocompile v0.14.1
|
|
github.com/google/go-cmp v0.7.0
|
|
github.com/spf13/cobra v1.10.2
|
|
google.golang.org/protobuf v1.36.12
|
|
)
|
|
|
|
require (
|
|
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
|
github.com/spf13/pflag v1.0.10 // indirect
|
|
golang.org/x/net v0.58.0 // indirect
|
|
golang.org/x/sync v0.22.0 // indirect
|
|
golang.org/x/sys v0.47.0 // indirect
|
|
golang.org/x/text v0.41.0 // indirect
|
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d // indirect
|
|
google.golang.org/grpc v1.83.2 // indirect
|
|
)
|