fix(platform): 代码审查整改——反代按域拆分授权、根除探测副作用与死代码清理

- YARP: map-edit/ai-config 全方法、reflection 写方法挂 PlatformScope,
  reflection/selection 单独放行(运营端 3D 高亮),堵住运营账号直达地图编辑/反射调用
- goto-site 探测改用不存在的 car/-1(消除健康检查真实派车风险)并加 60s 缓存
- Config PUT 按 scope 收紧:RCSMonitor 仅可写 ops 节;wizard 写操作与
  simplelite/restart-for-update 限 PlatformScope;/api/health 去除虚假端口表
- 修复 wms 模块菜单裁剪失效(admin-config-location → admin-config-facility)
- vrHost 默认 location.hostname:8223(新增 utils/vrender.ts),远程访问 3D 视口可用
- /status 页改接真实 /api/health* 诊断;uploadAsset 移除矛盾 multipart 头;
  mapsApi.merge 对齐 save 的 409 冲突处理;JWT 验签参数改启动期 DI 一次性配置
- 清理死代码:ProjectionController、DataTablePro、useClipboard、CadToolbarView、
  AppShell 未用导入;lint 脚本替换为 typecheck;日志窗口 List 改 Queue
This commit is contained in:
zhaowei.huang
2026-06-12 23:00:47 +08:00
parent d857cda071
commit 20f98db6da
24 changed files with 266 additions and 320 deletions
+40
View File
@@ -44,8 +44,48 @@
"Dispatch": {
}
},
"_comment_ReverseProxy": "sl-route 兜底 AnyAuthed(投影只读 + SSE)。管理面路径(map-edit / ai-config / reflection 写操作)单独拆路由挂 PlatformScope,防止运营账号经反代直达地图编辑与任意反射调用。",
"ReverseProxy": {
"Routes": {
"sl-mapedit-route": {
"ClusterId": "sl-cluster",
"AuthorizationPolicy": "PlatformScope",
"Order": -2,
"Match": { "Path": "/api/sl/projection/map-edit/{**catch-all}" },
"Transforms": [
{ "PathRemovePrefix": "/api/sl" }
]
},
"sl-aiconfig-route": {
"ClusterId": "sl-cluster",
"AuthorizationPolicy": "PlatformScope",
"Order": -2,
"Match": { "Path": "/api/sl/projection/ai-config/{**catch-all}" },
"Transforms": [
{ "PathRemovePrefix": "/api/sl" }
]
},
"sl-reflection-selection-route": {
"ClusterId": "sl-cluster",
"AuthorizationPolicy": "AnyAuthed",
"Order": -3,
"Match": { "Path": "/api/sl/projection/reflection/selection/{**catch-all}" },
"Transforms": [
{ "PathRemovePrefix": "/api/sl" }
]
},
"sl-reflection-write-route": {
"ClusterId": "sl-cluster",
"AuthorizationPolicy": "PlatformScope",
"Order": -1,
"Match": {
"Path": "/api/sl/projection/reflection/{**catch-all}",
"Methods": [ "POST", "PUT", "PATCH", "DELETE" ]
},
"Transforms": [
{ "PathRemovePrefix": "/api/sl" }
]
},
"sl-route": {
"ClusterId": "sl-cluster",
"AuthorizationPolicy": "AnyAuthed",