HTTP Endpoints with RBAC: - ingest_handler: project-level write access check - learn_handler: project-level write access check - projects_handler: filter returned projects by user access - query_handler: filter search results by resource access - context_handler: project-level read access check Example Role Configurations (config/roles/): - admin.yaml: full access to all resources - portfolio-agent.yaml: public visitor access - authenticated-user.yaml: logged-in user access - homelab-team.yaml: team-scoped project access All 660+ tests passing.
19 lines
560 B
YAML
19 lines
560 B
YAML
# Portfolio Agent role: public visitor access via portfolio site
|
|
name: portfolio-agent
|
|
description: Public visitor access - read public docs, manage own conversations
|
|
|
|
rules:
|
|
# Can read/query public wiki and embeddings from allowed projects
|
|
- resources: [wiki, embedding]
|
|
verbs: [read, query]
|
|
scope:
|
|
projects: [homelab, rbc, aws, portfolio]
|
|
visibility: public
|
|
|
|
# Can read/write own conversations in portfolio project only
|
|
- resources: [conversation]
|
|
verbs: [read, write]
|
|
scope:
|
|
projects: [portfolio]
|
|
owner: self
|