主题
认证接入
服务器需提供:登录校验、会话撤销、(推荐)基于 Cookie 的会话,以及业务级 CSRF 防护。壳不持久化凭据。
tsx
import { defineApp, registerNavigateExtension } from '@vlian/app/runtime';
import {
configureShellAuth,
enableShellAccessGuard,
ensureSessionRestored,
getShellAppStore,
installShellAppStore,
} from '@selrux/shell/config';
import type { ShellSessionContext } from '@selrux/shell/config';
import { login, logout, fetchCurrentUser } from './services/auth';
const store = installShellAppStore();
configureShellAuth({
login,
logout,
async restoreSession({ signal }: ShellSessionContext) {
return fetchCurrentUser(signal);
},
});
enableShellAccessGuard(registerNavigateExtension);
export default defineApp({
async bootstrap() {
await ensureSessionRestored(getShellAppStore() ?? store);
},
});契约要点
| 能力 | 说明 |
|---|---|
login / logout / restoreSession? | 认证适配器 |
installShellAppStore | 布局与导航共用同一 store |
enableShellAccessGuard | 导航前会话就绪 + constant/roles 判定 |
hasButtonAccess / useAuth().hasAuth | 按钮权限(any/all) |
未登录访问非 constant 路由 → 登录页;已登录角色不匹配 → /403。blank 布局默认生成 constant: true。
演示:examples/session(会话最小集)、examples/admin(列表/编辑/权限完整流,见 后台用户管理教程)。均为 sessionStorage,非生产。