chore: initialize standalone business plugin repository
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
# Business Plugin V1 架构与流程图
|
||||
|
||||
## 拓扑
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
B[管理员浏览器] --> C[Core custom_menu_items]
|
||||
C --> I[Core /custom/:id sandbox iframe]
|
||||
I --> P[反向代理 /extensions/:plugin-id/]
|
||||
P --> M[Plugin Control Plane]
|
||||
M --> S[独立业务插件服务]
|
||||
S --> A[Typed Core API Adapter]
|
||||
A --> K[Core Auth/Admin API]
|
||||
K --> D[Core 权威账本与审计]
|
||||
M --> R[Plugin Registry / Revisions / Audit]
|
||||
M --> H[Supervisor + healthz/readyz]
|
||||
```
|
||||
|
||||
## 登录时序
|
||||
|
||||
```mermaid
|
||||
sequenceDiagram
|
||||
participant B as Browser
|
||||
participant P as Plugin BFF
|
||||
participant C as Core
|
||||
B->>P: POST /login
|
||||
P->>C: POST /api/v1/auth/login
|
||||
C-->>P: access/refresh 或 2FA challenge
|
||||
P->>C: POST /api/v1/auth/login/2fa (按需)
|
||||
P->>C: GET /api/v1/auth/me
|
||||
C-->>P: role=admin
|
||||
P-->>B: HttpOnly plugin session + CSRF token
|
||||
B->>P: GET /api/plugins
|
||||
P->>C: Bearer Core JWT + X-Request-ID
|
||||
P-->>B: 脱敏业务数据
|
||||
```
|
||||
|
||||
## 生命周期
|
||||
|
||||
```mermaid
|
||||
stateDiagram-v2
|
||||
[*] --> discovered
|
||||
discovered --> verified: manifest/signature/hash pass
|
||||
verified --> installed: atomic staging
|
||||
installed --> disabled
|
||||
disabled --> starting: enable
|
||||
starting --> healthy: health + contract pass
|
||||
starting --> error: timeout/failure
|
||||
healthy --> draining: disable/upgrade
|
||||
draining --> disabled
|
||||
healthy --> upgrading: new revision
|
||||
upgrading --> healthy: new revision pass
|
||||
upgrading --> rollback_pending: new revision fail
|
||||
rollback_pending --> healthy: old revision restored
|
||||
verified --> incompatible: version/capability mismatch
|
||||
```
|
||||
|
||||
## 数据边界
|
||||
|
||||
```text
|
||||
Core authoritative data
|
||||
user / admin role / balance / plan / subscription / order / usage / billing / audit
|
||||
▲
|
||||
│ typed HTTPS API, server-side token only
|
||||
▼
|
||||
Plugin projection and UI
|
||||
cache / filters / display index / plugin audit reference
|
||||
▲
|
||||
│ controlled by
|
||||
▼
|
||||
Plugin control plane
|
||||
manifest / signature / revision / health / config / menu ownership / session
|
||||
```
|
||||
Reference in New Issue
Block a user