Files
OpenViking/sdk
Qin Haojie e2011f2948 feat(acl): 默认继承全员管理权限并支持创建时授权 (#5266)
* feat(acl): default shared resources to inherited manager access

Use immutable user:* manage at the shared root and inherit permissions without
extra creator grants. Tolerate temporarily different ACL index snapshots.

* feat(acl): unify permissions under attrs and support creation attributes

* refactor(acl): accept top-level ACL on resource creation

* fix(acl): bind import permissions to authorized targets

Reject internal ingestion options from public resource arguments and defer
ACL authorization until the final import target has been resolved.

* refactor(acl): isolate import permissions from parser arguments

Build ingestion options from explicit public inputs and keep parser arguments out
of post-processing so they cannot supply internal ACL updates. Remove redundant
mkdir ACL handling and make permission snapshot selection easier to follow.

* fix(acl): release import locks after permission failures

Release locally acquired leases when source commit fails or is cancelled,
and ensure artifact cleanup cannot skip post-processing lock release.

* fix(docs): use CLI labels in ACL API references

* refactor(acl): restore dedicated permission interfaces

Restore standalone ACL HTTP, CLI and SDK operations while keeping attrs
focused on its existing attributes. Retain creation-time ACL support and
align the documentation with the final permission model and interfaces.

* fix(acl): authorize connector imports before creating watches

Reject ACL changes before reserving a Watch so denied requests cannot leave it stuck executing. Cover denial and submission cancellation in the existing Watch cleanup test.

* fix(web-studio): align ACL guidance and restriction status

Describe inherited permissions without creator privileges in both locales. Show access restriction only for restricted mode and verify the existing toggle flow against inherited management grants.
2026-09-23 20:52:49 +08:00
..