refactor(protocol): centralize tenants.* RPC method names as constants (#1371)

The tenants.* methods were the only RPC group without MethodXxx
constants in pkg/protocol/methods.go. Their wire names were hardcoded
as raw string literals across three call sites — router registration,
and the read/admin allowlists in the permission policy — which is
inconsistent with the other 147 methods and risks silent drift: a
typo in any allowlist string is not caught by the compiler and would
fail-closed (deny) at runtime, which is hard to diagnose.

Add MethodTenants{List,Get,Create,Update,UsersList,UsersAdd,
UsersRemove,Mine} and replace the method-identifier literals in
internal/permissions/policy.go and internal/gateway/methods/tenants.go
with the constants.

No behavior change — string values are identical. Human-facing error
labels and log prefixes in internal/http/tenants.go are intentionally
left as free-form text, matching the sibling HTTP handler convention.
This commit is contained in:
fastopencn authored and GitHub committed 2026-07-07 12:54:08 +07:00
1 parent b5895c0a05
commit 93eef5feac
3 files changed
+28 -16

No files matched your search

+8 -8
View File
@@ -34,14 +34,14 @@ func NewTenantsMethods(tenantStore store.TenantStore, msgBus *bus.MessageBus, wo
// Register registers tenant management RPC methods.
func (m *TenantsMethods) Register(router *gateway.MethodRouter) {
router.Register("tenants.list", m.handleList)
router.Register("tenants.get", m.handleGet)
router.Register("tenants.create", m.handleCreate)
router.Register("tenants.update", m.handleUpdate)
router.Register("tenants.users.list", m.handleUsersList)
router.Register("tenants.users.add", m.handleUsersAdd)
router.Register("tenants.users.remove", m.handleUsersRemove)
router.Register("tenants.mine", m.handleMine)
router.Register(protocol.MethodTenantsList, m.handleList)
router.Register(protocol.MethodTenantsGet, m.handleGet)
router.Register(protocol.MethodTenantsCreate, m.handleCreate)
router.Register(protocol.MethodTenantsUpdate, m.handleUpdate)
router.Register(protocol.MethodTenantsUsersList, m.handleUsersList)
router.Register(protocol.MethodTenantsUsersAdd, m.handleUsersAdd)
router.Register(protocol.MethodTenantsUsersRemove, m.handleUsersRemove)
router.Register(protocol.MethodTenantsMine, m.handleMine)
}
func (m *TenantsMethods) handleList(ctx context.Context, client *gateway.Client, req *protocol.RequestFrame) {
+8 -8
View File
@@ -279,10 +279,10 @@ func isAdminMethod(method string) bool {
protocol.MethodTeamsTaskDeleteBulk,
// Tenants — write paths.
"tenants.create",
"tenants.update",
"tenants.users.add",
"tenants.users.remove",
protocol.MethodTenantsCreate,
protocol.MethodTenantsUpdate,
protocol.MethodTenantsUsersAdd,
protocol.MethodTenantsUsersRemove,
// API keys expose secret material — gate list + mutations as admin.
protocol.MethodAPIKeysList,
@@ -434,10 +434,10 @@ func isReadMethod(method string) bool {
protocol.MethodVoicesList,
// Tenants read
"tenants.list",
"tenants.get",
"tenants.users.list",
"tenants.mine",
protocol.MethodTenantsList,
protocol.MethodTenantsGet,
protocol.MethodTenantsUsersList,
protocol.MethodTenantsMine,
// Teams read
protocol.MethodTeamsList,
+12
View File
@@ -165,6 +165,18 @@ const (
MethodTeamsEventsList = "teams.events.list"
)
// Tenants (multi-tenant management)
const (
MethodTenantsList = "tenants.list"
MethodTenantsGet = "tenants.get"
MethodTenantsCreate = "tenants.create"
MethodTenantsUpdate = "tenants.update"
MethodTenantsUsersList = "tenants.users.list"
MethodTenantsUsersAdd = "tenants.users.add"
MethodTenantsUsersRemove = "tenants.users.remove"
MethodTenantsMine = "tenants.mine"
)
// API key management
const (
MethodAPIKeysList = "api_keys.list"