Files
OpenFlare/plugins/domain/risk_control/plugin.go
T
ryan 530a9dd3ee refactor(migration): delete pkg/migrator, move SQL to per-plugin embed
BREAKING: pkg/migrator/ deleted entirely. Migration SQL files are now
owned by each plugin in its own migrations/ directory.

Architecture:
- Delete pkg/migrator/ (26 global SQL files + ClickHouse migration)
- Move global SQL to per-plugin migrations/ with go:embed + Register()
- Rewrite cmd/app.go gooseEngine: uses Inject[DBService] for DB, iterates
  all plugin-registered MigrationEntry, runs goose.Up per entry
- core.MigrationEngine.Migrate signature changed: *Context instead of
  context.Context, so engine can resolve services via IoC

Per-plugin migration ownership:
  auth/             → w_access_tokens, w_auth_sources, w_external_accounts
  user/             → w_users (seed system user)
  admin/            → w_system_configs, w_templates (seeds)
  upload/           → w_uploads, w_upload_stats
  message_gateway/  → w_push_*, w_message_*
  risk_control/     → w_user_access_logs (PG + ClickHouse)
  driver_asynq_cron/  → w_schedules
  driver_asynq_worker/ → w_task_executions

Dependencies:
- cmd/banner.go: removed migration report display (migrations are automatic)
- cmd/reset_passwd.go: removed PreRun migrator.Migrate() call
- go.mod: clickhouse-go kept (used by plugins/infra/database/clickhouse.go)
2026-08-28 12:19:25 +08:00

98 lines
2.5 KiB
Go

// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package risk_control provides the access control, IP rate limiting, and telemetry risk analysis domain plugin for Cordis.
package risk_control
import (
"context"
"embed"
"github.com/Rain-kl/Wavelet/core"
"github.com/Rain-kl/Wavelet/core/extpoints"
"github.com/gin-gonic/gin"
)
//go:embed logstore/migrations/*.sql
var riskControlMigrations embed.FS
// Option configures the risk_control plugin.
type Option func(*Plugin)
// WithMiddleware configures a custom risk control middleware.
func WithMiddleware(mw gin.HandlerFunc) Option {
return func(p *Plugin) {
p.middleware = mw
}
}
// Plugin implements core.Plugin to provide risk control and access logging middleware.
type Plugin struct {
middleware gin.HandlerFunc
}
// New creates a new risk_control domain plugin.
func New(opts ...Option) *Plugin {
p := &Plugin{}
for _, opt := range opts {
if opt != nil {
opt(p)
}
}
return p
}
// Name returns the unique identifier for the risk_control domain plugin.
func (p *Plugin) Name() string {
return "risk_control"
}
// Manifest returns the plugin metadata.
func (p *Plugin) Manifest() core.Manifest {
return core.Manifest{
Name: "risk_control",
Version: "1.0.0",
Description: "Access control, IP rate limiting, and access log telemetry domain plugin",
Author: "Wavelet Team",
}
}
// Apply registers risk control middlewares, settings, and cleanup hooks into the Context.
func (p *Plugin) Apply(ctx *core.Context) error {
// 0. Register user access log table migrations
ctx.Migrations().Register("risk_control/logstore", riskControlMigrations)
// 1. Initialize LogWriter if needed
InitLogWriter(ctx.GoContext())
// 2. Register router middleware
mw := p.middleware
if mw == nil {
mw = RiskControlMiddleware()
}
ctx.Router().Use(mw)
// 3. Register Settings Schemas
ctx.Settings().Register(extpoints.SettingSchema{
Key: "risk_control.ip_rate_limit_per_minute",
Default: 60,
Description: "Maximum requests allowed per IP per minute",
Type: "integer",
Category: "security",
})
ctx.Settings().Register(extpoints.SettingSchema{
Key: "risk_control.enable_access_log",
Default: true,
Description: "Enable structured access log auditing and backpressure queueing",
Type: "boolean",
Category: "security",
})
// 4. Register lifecycle disposal cleanup
ctx.OnDispose(func() error {
return StopLogWriter(context.Background())
})
return nil
}