diff --git a/Makefile b/Makefile index 5f35bf6f..e2174dd9 100644 --- a/Makefile +++ b/Makefile @@ -40,7 +40,7 @@ build-embedded: code-check: @echo "==> Architecture guards..." - @command -v rg >/dev/null 2>&1 || { echo 'error: rg (ripgrep) is required for architecture guards' >&2; exit 1; } + scripts/check_cordis_architecture.sh @if rg -n 'db\.DB\(|db\.Redis' backend/openflare/plugins/server/kernel/model --glob '*.go' -g '!*_test.go' ; then \ echo 'error: internal/model must not access db.DB or db.Redis (non-test code)' >&2; \ exit 1; \ diff --git a/backend/openflare/plugins/server/kernel/model/errs.go b/backend/openflare/plugins/server/kernel/model/errs.go index 51da0c48..ed7ac7ab 100644 --- a/backend/openflare/plugins/server/kernel/model/errs.go +++ b/backend/openflare/plugins/server/kernel/model/errs.go @@ -2,16 +2,3 @@ // SPDX-License-Identifier: Apache-2.0 package model - -// Domain validation messages used by model.Validate and other no-IO rules. -// Persistence / data-access messages belong in internal/repository (do not import repository). -const ( - errTemplateKeyRequired = "模板标识符不能为空" - errTemplateNameRequired = "模板名称不能为空" - errTemplateContentRequired = "模板内容不能为空" - errAuthSourceNameRequired = "认证源名称不能为空" - errAuthSourceNameInvalid = "认证源名称只能包含字母、数字、短横线或下划线,且必须以字母或数字开头" - errAuthSourceTypeUnsupported = "认证源类型仅支持 oidc" - errAuthSourceDiscoveryURLRequired = "OIDC 认证源必须配置 Discovery URL" - errAuthSourceClientCredentialsRequired = "启用认证源前必须配置 Client ID 和 Client Secret" //nolint:gosec // false positive: this is an error message, not hardcoded credentials -) diff --git a/backend/openflare/plugins/server/kernel/repository/errs.go b/backend/openflare/plugins/server/kernel/repository/errs.go index 92f5e2b4..b62cc95a 100644 --- a/backend/openflare/plugins/server/kernel/repository/errs.go +++ b/backend/openflare/plugins/server/kernel/repository/errs.go @@ -22,6 +22,4 @@ const ( errExternalAccountBindingIDRequired = "绑定记录 ID 不能为空" ) -const colName = "name" - const colEnabled = "enabled" diff --git a/backend/openflare/plugins/server/migrate/stamp.go b/backend/openflare/plugins/server/migrate/stamp.go index b0875e15..aeb9d036 100644 --- a/backend/openflare/plugins/server/migrate/stamp.go +++ b/backend/openflare/plugins/server/migrate/stamp.go @@ -44,7 +44,7 @@ func Legacy(ctx *core.Context) error { if ctx != nil && ctx.GoContext() != nil { goCtx = ctx.GoContext() } - postgres := gormDB.Dialector != nil && gormDB.Dialector.Name() == "postgres" + postgres := gormDB.Dialector != nil && gormDB.Name() == "postgres" exists, err := gooseTableExists(goCtx, sqlDB, postgres) if err != nil { diff --git a/scripts/check_cordis_architecture.sh b/scripts/check_cordis_architecture.sh index 3259546a..db8ec90b 100755 --- a/scripts/check_cordis_architecture.sh +++ b/scripts/check_cordis_architecture.sh @@ -65,11 +65,11 @@ else fi # 1.2 core/ 禁止导入任何插件 -CORE_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/" \ +CORE_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/" \ "${BACKEND_DIR}/core/" --glob '*.go' -g '!*_test.go' || true) if [ -n "${CORE_PLUGIN_IMPORTS}" ]; then - log_fail "backend/core/ 严禁直接依赖具体插件 (plugins/ 或 downstream/):" + log_fail "backend/core/ 严禁直接依赖具体插件 (plugins/, downstream/ 或 openflare/):" echo "${CORE_PLUGIN_IMPORTS}" >&2 else log_pass "backend/core/ 零插件反向依赖" @@ -80,7 +80,7 @@ fi # ============================================================================== log_check "2. 检查契约层 (backend/core/contracts/) 抽象纯洁度..." -CONTRACTS_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"github.com/gin-gonic/gin\"|\"github.com/hibiken/asynq\"" \ +CONTRACTS_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/|\"github.com/gin-gonic/gin\"|\"github.com/hibiken/asynq\"" \ "${BACKEND_DIR}/core/contracts/" --glob '*.go' || true) if [ -n "${CONTRACTS_PLUGIN_IMPORTS}" ]; then @@ -109,12 +109,12 @@ fi # ============================================================================== log_check "3. 检查基础库 (backend/pkg/) 纯洁度..." -# 3.1 pkg/ 严禁导入 plugins/ -PKG_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/" \ +# 3.1 pkg/ 严禁导入 plugins/, downstream/, openflare/ +PKG_PLUGIN_IMPORTS=$(rg -n "\"${MODULE}/plugins/|\"${MODULE}/downstream/|\"${MODULE}/openflare/" \ "${BACKEND_DIR}/pkg/" --glob '*.go' -g '!*testhelper*' -g '!*_test.go' || true) if [ -n "${PKG_PLUGIN_IMPORTS}" ]; then - log_fail "backend/pkg/ 严禁导入任何上层 plugins/:" + log_fail "backend/pkg/ 严禁导入任何上层 plugins/, downstream/ 或 openflare/:" echo "${PKG_PLUGIN_IMPORTS}" >&2 else log_pass "backend/pkg/ 零插件依赖" @@ -182,6 +182,23 @@ if [ -d "${BACKEND_DIR}/downstream/plugins" ]; then done fi +# 检查 openflare/plugins/ 下的下游插件间隔离性 +if [ -d "${BACKEND_DIR}/openflare/plugins" ]; then + for openflare_dir in "${BACKEND_DIR}"/openflare/plugins/*/; do + [ -d "$openflare_dir" ] || continue + openflare_name=$(basename "$openflare_dir") + openflare_self_prefix="${MODULE}/openflare/plugins/${openflare_name}" + + # 检查 openflare 插件之间是否违规跨插件直接 import + openflare_cross=$(rg -n "\"${MODULE}/openflare/plugins/" "${openflare_dir}" \ + -g '*.go' -g '!*_test.go' 2>/dev/null | rg -v "\"${openflare_self_prefix}(/|\")" || true) + + if [ -n "$openflare_cross" ]; then + CROSS_PLUGIN_IMPORTS="${CROSS_PLUGIN_IMPORTS}\n[openflare/plugins/${openflare_name} 违规引用其他 openflare 插件]:\n${openflare_cross}\n" + fi + done +fi + if [ -n "${CROSS_PLUGIN_IMPORTS}" ]; then log_fail "发现跨插件直接依赖违规(必须通过 core/contracts 契约接口或 EventBus 解耦,严禁跨插件直接 import 具体包):" echo -e "${CROSS_PLUGIN_IMPORTS}" >&2