refactor: update resource permission constants for improved clarity

This commit is contained in:
wxg0103 2025-07-28 10:29:29 +08:00
parent ca070d7466
commit 60c7f78a90

View File

@ -90,11 +90,11 @@ class SystemGroup(Enum):
USER_MANAGEMENT = "USER_MANAGEMENT" USER_MANAGEMENT = "USER_MANAGEMENT"
ROLE = "ROLE" ROLE = "ROLE"
WORKSPACE = "WORKSPACE" WORKSPACE = "WORKSPACE"
RESOURCE = "RESOURCE" #RESOURCE = "RESOURCE"
# RESOURCE_APPLICATION = "RESOURCE_APPLICATION" RESOURCE_APPLICATION = "RESOURCE_APPLICATION"
# RESOURCE_KNOWLEDGE = "RESOURCE_KNOWLEDGE" RESOURCE_KNOWLEDGE = "RESOURCE_KNOWLEDGE"
# RESOURCE_TOOL = "RESOURCE_TOOL" RESOURCE_TOOL = "RESOURCE_TOOL"
# RESOURCE_MODEL = "RESOURCE_MODEL" RESOURCE_MODEL = "RESOURCE_MODEL"
RESOURCE_PERMISSION = "RESOURCE_PERMISSION" RESOURCE_PERMISSION = "RESOURCE_PERMISSION"
SHARED_KNOWLEDGE = "SHARED_KNOWLEDGE" SHARED_KNOWLEDGE = "SHARED_KNOWLEDGE"
SHARED_MODEL = "SHARED_MODEL" SHARED_MODEL = "SHARED_MODEL"
@ -280,10 +280,10 @@ Permission_Label = {
SystemGroup.USER_MANAGEMENT.value: _("User Management"), SystemGroup.USER_MANAGEMENT.value: _("User Management"),
SystemGroup.ROLE.value: _("Role"), SystemGroup.ROLE.value: _("Role"),
SystemGroup.WORKSPACE.value: _("Workspace"), SystemGroup.WORKSPACE.value: _("Workspace"),
# SystemGroup.RESOURCE_APPLICATION.value: _("Resource Application"), SystemGroup.RESOURCE_APPLICATION.value: _("Resource Application"),
# SystemGroup.RESOURCE_KNOWLEDGE.value: _("Resource Knowledge"), SystemGroup.RESOURCE_KNOWLEDGE.value: _("Resource Knowledge"),
# SystemGroup.RESOURCE_TOOL.value: _("Resource Tool"), SystemGroup.RESOURCE_TOOL.value: _("Resource Tool"),
# SystemGroup.RESOURCE_MODEL.value: _("Resource Model"), SystemGroup.RESOURCE_MODEL.value: _("Resource Model"),
SystemGroup.RESOURCE_PERMISSION.value: _("Resource Permission"), SystemGroup.RESOURCE_PERMISSION.value: _("Resource Permission"),
SystemGroup.SHARED_KNOWLEDGE.value: _("Shared Knowledge"), SystemGroup.SHARED_KNOWLEDGE.value: _("Shared Knowledge"),
SystemGroup.SHARED_MODEL.value: _("Shared Model"), SystemGroup.SHARED_MODEL.value: _("Shared Model"),
@ -364,7 +364,7 @@ Permission_Label = {
Group.MODEL_WORKSPACE_USER_RESOURCE_PERMISSION.value: _("Model"), Group.MODEL_WORKSPACE_USER_RESOURCE_PERMISSION.value: _("Model"),
Group.TOOL_WORKSPACE_USER_RESOURCE_PERMISSION.value: _("Tool"), Group.TOOL_WORKSPACE_USER_RESOURCE_PERMISSION.value: _("Tool"),
Group.SYSTEM_RES_APPLICATION.value: _("Application"), Group.SYSTEM_RES_APPLICATION.value: _("Application"),
SystemGroup.RESOURCE.value: _("Resource"), #SystemGroup.RESOURCE.value: _("Resource"),
} }
@ -374,7 +374,7 @@ class Permission:
""" """
def __init__(self, group: Group, operate: Operate, resource_path=None, role_list=None, def __init__(self, group: Group, operate: Operate, resource_path=None, role_list=None,
resource_permission_group_list=None, parent_group=None, label=None, is_ee=True, is_show=True): resource_permission_group_list=None, parent_group=None, label=None, is_ee=True):
if role_list is None: if role_list is None:
role_list = [] role_list = []
if resource_permission_group_list is None: if resource_permission_group_list is None:
@ -389,7 +389,6 @@ class Permission:
self.parent_group = parent_group # 新增字段:父级组 self.parent_group = parent_group # 新增字段:父级组
self.label = label self.label = label
self.is_ee = is_ee # 是否是企业版权限 self.is_ee = is_ee # 是否是企业版权限
self.is_show = is_show # 是否在前端展示
@staticmethod @staticmethod
def new_instance(permission_str: str): def new_instance(permission_str: str):
@ -1195,128 +1194,128 @@ class PermissionConstants(Enum):
) )
RESOURCE_APPLICATION_READ = Permission( RESOURCE_APPLICATION_READ = Permission(
group=Group.SYSTEM_RES_APPLICATION, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_APPLICATION, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE] parent_group=[SystemGroup.RESOURCE_APPLICATION]
) )
RESOURCE_KNOWLEDGE_READ = Permission( RESOURCE_KNOWLEDGE_READ = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE] parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_CREATE = Permission( RESOURCE_KNOWLEDGE_CREATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_EDIT = Permission( RESOURCE_KNOWLEDGE_EDIT = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_SYNC = Permission( RESOURCE_KNOWLEDGE_SYNC = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.SYNC, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.SYNC, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_VECTOR = Permission( RESOURCE_KNOWLEDGE_VECTOR = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.VECTOR, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.VECTOR, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_EXPORT = Permission( RESOURCE_KNOWLEDGE_EXPORT = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_GENERATE = Permission( RESOURCE_KNOWLEDGE_GENERATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.GENERATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.GENERATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DELETE = Permission( RESOURCE_KNOWLEDGE_DELETE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_READ = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_READ = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_CREATE = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_CREATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_EDIT = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_EDIT = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_DELETE = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_DELETE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_SYNC = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_SYNC = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.SYNC, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.SYNC, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_EXPORT = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_EXPORT = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_DOWNLOAD_SOURCE_FILE = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_DOWNLOAD_SOURCE_FILE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.DOWNLOAD, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.DOWNLOAD, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_VECTOR = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_VECTOR = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.VECTOR, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.VECTOR, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_GENERATE = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_GENERATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.GENERATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.GENERATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_DOCUMENT_MIGRATE = Permission( RESOURCE_KNOWLEDGE_DOCUMENT_MIGRATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.MIGRATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_DOCUMENT, operate=Operate.MIGRATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_PROBLEM_READ = Permission( RESOURCE_KNOWLEDGE_PROBLEM_READ = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_PROBLEM_CREATE = Permission( RESOURCE_KNOWLEDGE_PROBLEM_CREATE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_PROBLEM_EDIT = Permission( RESOURCE_KNOWLEDGE_PROBLEM_EDIT = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_KNOWLEDGE_PROBLEM_DELETE = Permission( RESOURCE_KNOWLEDGE_PROBLEM_DELETE = Permission(
group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_KNOWLEDGE_PROBLEM, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_KNOWLEDGE]
) )
RESOURCE_TOOL_READ = Permission( RESOURCE_TOOL_READ = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE] parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_CREATE = Permission( RESOURCE_TOOL_CREATE = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.CREATE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_EDIT = Permission( RESOURCE_TOOL_EDIT = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.EDIT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_DELETE = Permission( RESOURCE_TOOL_DELETE = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.DELETE, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_IMPORT = Permission( RESOURCE_TOOL_IMPORT = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.IMPORT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.IMPORT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_EXPORT = Permission( RESOURCE_TOOL_EXPORT = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.EXPORT, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_TOOL_DEBUG = Permission( RESOURCE_TOOL_DEBUG = Permission(
group=Group.SYSTEM_RES_TOOL, operate=Operate.DEBUG, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_TOOL, operate=Operate.DEBUG, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE], is_show=False parent_group=[SystemGroup.RESOURCE_TOOL]
) )
RESOURCE_MODEL_READ = Permission( RESOURCE_MODEL_READ = Permission(
group=Group.SYSTEM_RES_MODEL, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.SYSTEM_RES_MODEL, operate=Operate.READ, role_list=[RoleConstants.ADMIN],
parent_group=[SystemGroup.RESOURCE] parent_group=[SystemGroup.RESOURCE_MODEL]
) )
OPERATION_LOG_READ = Permission( OPERATION_LOG_READ = Permission(
group=Group.OPERATION_LOG, operate=Operate.READ, role_list=[RoleConstants.ADMIN], group=Group.OPERATION_LOG, operate=Operate.READ, role_list=[RoleConstants.ADMIN],