diff --git a/README.md b/README.md index 8aabeec..5e1c172 100644 --- a/README.md +++ b/README.md @@ -27,7 +27,8 @@ pnpm --filter web dev # :5175 См. [`docs/integrate-cfdm.md`](docs/integrate-cfdm.md) — то же для Cloudflare Domain Manager (`cfdm:*`, порт Vite `5174`). -См. [`docs/integrate-evobgp.md`](docs/integrate-evobgp.md) — EvoBGP (`bgp:*`), dual auth JWT + API keys, ownership modules/peers/firewall. +См. [`docs/integrate-evobgp.md`](docs/integrate-evobgp.md) — EvoBGP (`bgp:*`). +См. [`docs/integrate-evofirewall.md`](docs/integrate-evofirewall.md) — EvoFirewall (`fw:*`). Корень: diff --git a/docs/integrate-evobgp.md b/docs/integrate-evobgp.md index f5eae47..d2c332f 100644 --- a/docs/integrate-evobgp.md +++ b/docs/integrate-evobgp.md @@ -1,6 +1,6 @@ # Интеграция auth-portal ↔ EvoBGP -Единый вход: пользователь логинится на auth-portal, получает JWT, переходит в EvoBGP с токеном в URL fragment. EvoBGP API проверяет JWT и права `bgp:*`. API-ключи EvoBGP (viewer/editor/operator/node/firewall) остаются для автоматизации и нод. +Единый вход: пользователь логинится на auth-portal, получает JWT, переходит в EvoBGP с токеном в URL fragment. EvoBGP API проверяет JWT и права `bgp:*`. API-ключи EvoBGP (viewer/editor/operator/node) остаются для автоматизации и нод. Firewall-клиенты перенесены в **EvoFirewall** (`fw:*`). ## Архитектура @@ -27,7 +27,6 @@ App id в портале: **`bgp`**. | `bgp:network:read` / `write` | `/network` (пиры и спикеры) | | `bgp:directories:read` / `write` | `/directories` | | `bgp:operations:read` / `write` / `admin` | `/operations` (admin = apply/rollback) | -| `bgp:firewall:read` / `write` | `/firewall` | | `bgp:schedule:read` / `write` | `/schedule` | | `bgp:monitoring:read` | `/monitoring` | | `bgp:access:admin` | `/access` (API-ключи) | @@ -40,7 +39,7 @@ App id в портале: **`bgp`**. ### Ownership -Ресурсы modules / peers / firewall (clients, rules), созданные через JWT, имеют `created_by_user_id`. Видят и редактируют: создатель и portal `is_admin` (или API key `operator`). API keys без user id — tenant-wide scope. +Ресурсы modules / peers, созданные через JWT, имеют `created_by_user_id`. Видят и редактируют: создатель и portal `is_admin` (или API key `operator`). API keys без user id — tenant-wide scope. Firewall — см. EvoFirewall / `docs/integrate-evofirewall.md`. ## Локальный запуск diff --git a/docs/integrate-evofirewall.md b/docs/integrate-evofirewall.md new file mode 100644 index 0000000..2f30a3d --- /dev/null +++ b/docs/integrate-evofirewall.md @@ -0,0 +1,26 @@ +# Интеграция auth-portal ↔ EvoFirewall + +App id: **`fw`**. + +Единый вход: JWT HS256 (общий `JWT_SECRET`), handoff через `#access_token=…`. + +## Permissions + +| Permission | UI | +|------------|-----| +| `fw:dashboard:read` | Dashboard | +| `fw:agents:read` / `write` | Agents | +| `fw:lists:read` / `write` | IP lists | +| `fw:policies:read` / `write` | Rules / overrides | +| `fw:stats:read` | Stats | +| `fw:settings:admin` | Settings | + +## Portal checklist + +1. `APP_IDS` включает `fw` (сделано) +2. Admin → Apps: URL EvoFirewall + выдача прав +3. `RETURN_TO_ALLOWLIST` — origin FW + +## App env + +См. EvoFirewall `docs/integrate-auth-portal.md`. diff --git a/packages/shared/src/contracts/app-switcher.ts b/packages/shared/src/contracts/app-switcher.ts index 2bfcb8d..4520755 100644 --- a/packages/shared/src/contracts/app-switcher.ts +++ b/packages/shared/src/contracts/app-switcher.ts @@ -35,6 +35,7 @@ const DEFAULT_ICONS: Record = { cfdm: 'cloud', vps: 'server', bgp: 'globe', + fw: 'server', } /** Seed / fallback when DB is empty. */ diff --git a/packages/shared/src/contracts/auth.ts b/packages/shared/src/contracts/auth.ts index 1a3d0a1..2fec5f7 100644 --- a/packages/shared/src/contracts/auth.ts +++ b/packages/shared/src/contracts/auth.ts @@ -1,6 +1,6 @@ import { z } from 'zod' -export const APP_IDS = ['cfdm', 'vps', 'bgp'] as const +export const APP_IDS = ['cfdm', 'vps', 'bgp', 'fw'] as const export type AppId = (typeof APP_IDS)[number] export const appIdSchema = z.enum(APP_IDS) @@ -34,6 +34,12 @@ export const APPS: AppMeta[] = [ description: 'Модули, сеть, операции и мониторинг BGP', url: 'https://bgp.shnt.top', }, + { + id: 'fw', + title: 'EvoFirewall', + description: 'Централизованный firewall: агенты, списки, политики', + url: 'https://fw.shnt.top', + }, ] export type CatalogSection = { @@ -100,7 +106,6 @@ export const PERMISSION_CATALOG: AppPermissionCatalog[] = [ 'write', 'admin', ]), - section('firewall', 'Файрвол', 'Клиенты и правила'), section('schedule', 'Задачи', 'Расписание refresh'), section('monitoring', 'Мониторинг', 'Health и BIRD', ['read']), section('access', 'Доступ', 'API-ключи', ['admin']), @@ -110,6 +115,18 @@ export const PERMISSION_CATALOG: AppPermissionCatalog[] = [ section('settings', 'Настройки UI', 'Токен и подключение', ['read']), ], }, + { + appId: 'fw', + title: 'EvoFirewall', + sections: [ + section('dashboard', 'Дашборд', 'KPI и обзор', ['read']), + section('agents', 'Агенты', 'Linux / MikroTik клиенты'), + section('lists', 'Списки IP', 'static / JSON / domains / EvoBGP'), + section('policies', 'Правила', 'Allow/deny политики и overrides'), + section('stats', 'Статистика', 'Пакеты и история', ['read']), + section('settings', 'Настройки', 'Enroll seed и интеграции', ['admin']), + ], + }, ] export function permissionKey(