Skip to content

认证接入 ​

服务器需提供:登录校验、会话撤销、(推荐)基于 Cookie 的会话,以及业务级 CSRF 防护。壳不持久化凭据。

tsx
import { defineApp, registerNavigateExtension } from '@vlian/app/runtime';
import {
  configureShellAuth,
  enableShellAccessGuard,
  ensureSessionRestored,
  getShellAppStore,
  installShellAppStore,
} from '@selrux/shell/config';
import type { ShellSessionContext } from '@selrux/shell/config';
import { login, logout, fetchCurrentUser } from './services/auth';

const store = installShellAppStore();
configureShellAuth({
  login,
  logout,
  async restoreSession({ signal }: ShellSessionContext) {
    return fetchCurrentUser(signal);
  },
});
enableShellAccessGuard(registerNavigateExtension);

export default defineApp({
  async bootstrap() {
    await ensureSessionRestored(getShellAppStore() ?? store);
  },
});

契约要点 ​

能力说明
login / logout / restoreSession?认证适配器
installShellAppStore布局与导航共用同一 store
enableShellAccessGuard导航前会话就绪 + constant/roles 判定
hasButtonAccess / useAuth().hasAuth按钮权限(any/all)

未登录访问非 constant 路由 → 登录页;已登录角色不匹配 → /403。blank 布局默认生成 constant: true。
演示:examples/session(会话最小集)、examples/admin(列表/编辑/权限完整流,见 后台用户管理教程)。均为 sessionStorage,非生产。

精简版默认可用;完整壳需显式启用并配置私服。