Files
sub2api-add/docs/BUSINESS_PLUGIN_BOUNDARIES.md
T
Qiufeng 5feae3ad41
Business Plugins CI / check (plugin-admin) (push) Successful in 3m13s
Business Plugins CI / check (subscription-admin) (push) Successful in 1m41s
chore: initialize standalone business plugin repository
2026-08-27 23:36:08 +08:00

39 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Business Plugin V1 边界
## Core 负责
- 用户身份、密码、2FA、TokenVersion、会话撤销和管理员角色;
- 余额、余额流水、套餐、订阅、订单、用量、配额、计费和退款;
- 网关鉴权、请求路由、原子预留/结算、幂等和核心审计;
- Core 数据库 schema、迁移和事务;
- 现有 `.s2plugin` transport ABI 及 OpenAI OAuth 生命周期;
- `custom_menu_items` 的最终校验和页面可见性。
## 控制面负责
- 业务插件清单、签名、公钥、包哈希和 Core 兼容性;
- 插件安装目录、revision、active 指针和旧版本保留;
- 独立服务进程的启停、drain、健康、升级和回滚;
- 插件配置加密、会话、CSRF、权限和控制面审计;
- 由插件声明的管理员菜单 preview/apply;
- 只允许服务端调用的 Core API Adapter。
## 业务插件负责
- 自己的业务 UI、HTTP API、BFF 和领域逻辑;
- 自己声明的 Core API allowlist、字段映射、分页和错误展示;
- 可删除、可重建的只读 projection;
- 自己的健康端点、版本报告和配置校验;
- 不影响 Core 的独立发布和回滚。
## 明确禁止
- 插件前端持有 Core JWT、refresh token、Admin Key 或服务 secret;
- 插件直连 Core PostgreSQL、Redis、宿主文件目录或内部 Go 包;
- 插件自行判断余额、权限、配额、计费或网关放行;
- 用多个 Admin API 拼接一个本应由 Core 原子事务完成的购买/扣款/续费;
- 把业务插件声明成 `openai.oauth.outbound_transport.v1`;
- 通过 iframe URL、LocalStorage、查询参数或日志传递认证凭据;
- 由插件卸载流程删除 Core 账本、订阅或审计数据;
- 在 V1 承诺无感 SSO、远程任意下载、OS 沙箱或跨插件 RPC。