ci(arch): include openflare in cordis architecture checks

This commit is contained in:
ryan
2026-09-03 09:32:43 +08:00
parent b183e80565
commit ed57e44e3c
5 changed files with 25 additions and 23 deletions
+1 -1
View File
@@ -40,7 +40,7 @@ build-embedded:
code-check:
@echo "==> Architecture guards..."
@command -v rg >/dev/null 2>&1 || { echo 'error: rg (ripgrep) is required for architecture guards' >&2; exit 1; }
scripts/check_cordis_architecture.sh
@if rg -n 'db\.DB\(|db\.Redis' backend/openflare/plugins/server/kernel/model --glob '*.go' -g '!*_test.go' ; then \
echo 'error: internal/model must not access db.DB or db.Redis (non-test code)' >&2; \
exit 1; \
@@ -2,16 +2,3 @@
// SPDX-License-Identifier: Apache-2.0
package model
// Domain validation messages used by model.Validate and other no-IO rules.
// Persistence / data-access messages belong in internal/repository (do not import repository).
const (
errTemplateKeyRequired = "模板标识符不能为空"
errTemplateNameRequired = "模板名称不能为空"
errTemplateContentRequired = "模板内容不能为空"
errAuthSourceNameRequired = "认证源名称不能为空"
errAuthSourceNameInvalid = "认证源名称只能包含字母、数字、短横线或下划线,且必须以字母或数字开头"
errAuthSourceTypeUnsupported = "认证源类型仅支持 oidc"
errAuthSourceDiscoveryURLRequired = "OIDC 认证源必须配置 Discovery URL"
errAuthSourceClientCredentialsRequired = "启用认证源前必须配置 Client ID 和 Client Secret" //nolint:gosec // false positive: this is an error message, not hardcoded credentials
)
@@ -22,6 +22,4 @@ const (
errExternalAccountBindingIDRequired = "绑定记录 ID 不能为空"
)
const colName = "name"
const colEnabled = "enabled"
@@ -44,7 +44,7 @@ func Legacy(ctx *core.Context) error {
if ctx != nil && ctx.GoContext() != nil {
goCtx = ctx.GoContext()
}
postgres := gormDB.Dialector != nil && gormDB.Dialector.Name() == "postgres"
postgres := gormDB.Dialector != nil && gormDB.Name() == "postgres"
exists, err := gooseTableExists(goCtx, sqlDB, postgres)
if err != nil {
+23 -6
View File
@@ -65,11 +65,11 @@ else
fi
# 1.2 core/ 禁止导入任何插件
CORE_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/" \
CORE_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/" \
"${BACKEND_DIR}/core/" --glob '*.go' -g '!*_test.go' || true)
if [ -n "${CORE_PLUGIN_IMPORTS}" ]; then
log_fail "backend/core/ 严禁直接依赖具体插件 (plugins/ 或 downstream/):"
log_fail "backend/core/ 严禁直接依赖具体插件 (plugins/, downstream/ 或 openflare/):"
echo "${CORE_PLUGIN_IMPORTS}" >&2
else
log_pass "backend/core/ 零插件反向依赖"
@@ -80,7 +80,7 @@ fi
# ==============================================================================
log_check "2. 检查契约层 (backend/core/contracts/) 抽象纯洁度..."
CONTRACTS_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"github.com/gin-gonic/gin\"|\"github.com/hibiken/asynq\"" \
CONTRACTS_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/|\"github.com/gin-gonic/gin\"|\"github.com/hibiken/asynq\"" \
"${BACKEND_DIR}/core/contracts/" --glob '*.go' || true)
if [ -n "${CONTRACTS_PLUGIN_IMPORTS}" ]; then
@@ -109,12 +109,12 @@ fi
# ==============================================================================
log_check "3. 检查基础库 (backend/pkg/) 纯洁度..."
# 3.1 pkg/ 严禁导入 plugins/
PKG_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/" \
# 3.1 pkg/ 严禁导入 plugins/, downstream/, openflare/
PKG_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/" \
"${BACKEND_DIR}/pkg/" --glob '*.go' -g '!*testhelper*' -g '!*_test.go' || true)
if [ -n "${PKG_PLUGIN_IMPORTS}" ]; then
log_fail "backend/pkg/ 严禁导入任何上层 plugins/:"
log_fail "backend/pkg/ 严禁导入任何上层 plugins/, downstream/ 或 openflare/:"
echo "${PKG_PLUGIN_IMPORTS}" >&2
else
log_pass "backend/pkg/ 零插件依赖"
@@ -182,6 +182,23 @@ if [ -d "${BACKEND_DIR}/downstream/plugins" ]; then
done
fi
# 检查 openflare/plugins/ 下的下游插件间隔离性
if [ -d "${BACKEND_DIR}/openflare/plugins" ]; then
for openflare_dir in "${BACKEND_DIR}"/openflare/plugins/*/; do
[ -d "$openflare_dir" ] || continue
openflare_name=$(basename "$openflare_dir")
openflare_self_prefix="${MODULE}/openflare/plugins/${openflare_name}"
# 检查 openflare 插件之间是否违规跨插件直接 import
openflare_cross=$(rg -n "\"${MODULE}/openflare/plugins/" "${openflare_dir}" \
-g '*.go' -g '!*_test.go' 2>/dev/null | rg -v "\"${openflare_self_prefix}(/|\")" || true)
if [ -n "$openflare_cross" ]; then
CROSS_PLUGIN_IMPORTS="${CROSS_PLUGIN_IMPORTS}\n[openflare/plugins/${openflare_name} 违规引用其他 openflare 插件]:\n${openflare_cross}\n"
fi
done
fi
if [ -n "${CROSS_PLUGIN_IMPORTS}" ]; then
log_fail "发现跨插件直接依赖违规(必须通过 core/contracts 契约接口或 EventBus 解耦,严禁跨插件直接 import 具体包):"
echo -e "${CROSS_PLUGIN_IMPORTS}" >&2