[{"data":1,"prerenderedAt":711},["ShallowReactive",2],{"navigation":3,"doc-/modules/auth":217,"docs-all-paths":656},[4,19,39,63,87,111,127,195,211],{"title":5,"path":6,"stem":7,"children":8},"Welcome","/welcome","01.welcome",[9,11,15],{"title":5,"path":6,"stem":10},"01.welcome/index",{"title":12,"path":13,"stem":14},"Astar とは（5分）","/welcome/product-in-5-min","01.welcome/01.product-in-5-min",{"title":16,"path":17,"stem":18},"事業文脈","/welcome/business-context","01.welcome/02.business-context",{"title":20,"path":21,"stem":22,"children":23},"Getting Started","/getting-started","02.getting-started",[24,27,31,35],{"title":25,"path":21,"stem":26},"はじめかた","02.getting-started/index",{"title":28,"path":29,"stem":30},"リポジトリ取得と環境構築","/getting-started/repo-setup","02.getting-started/01.repo-setup",{"title":32,"path":33,"stem":34},"日々の開発ループ","/getting-started/dev-loop","02.getting-started/02.dev-loop",{"title":36,"path":37,"stem":38},"検証の 4 層","/getting-started/verification-tiers","02.getting-started/03.verification-tiers",{"title":40,"path":41,"stem":42,"children":43},"Architecture","/architecture","03.architecture",[44,47,51,55,59],{"title":45,"path":41,"stem":46},"アーキテクチャ","03.architecture/index",{"title":48,"path":49,"stem":50},"マルチテナンシーと RLS","/architecture/multi-tenancy-rls","03.architecture/01.multi-tenancy-rls",{"title":52,"path":53,"stem":54},"認可モデル","/architecture/authorization","03.architecture/02.authorization",{"title":56,"path":57,"stem":58},"AI サブシステム","/architecture/ai-subsystem","03.architecture/03.ai-subsystem",{"title":60,"path":61,"stem":62},"データモデル","/architecture/data-model","03.architecture/04.data-model",{"title":64,"path":65,"stem":66,"children":67},"Backend","/backend","04.backend",[68,71,75,79,83],{"title":69,"path":65,"stem":70},"バックエンド","04.backend/index",{"title":72,"path":73,"stem":74},"層構造","/backend/layering","04.backend/01.layering",{"title":76,"path":77,"stem":78},"規約","/backend/conventions","04.backend/02.conventions",{"title":80,"path":81,"stem":82},"テスト","/backend/testing","04.backend/03.testing",{"title":84,"path":85,"stem":86},"マイグレーション","/backend/migrations","04.backend/04.migrations",{"title":88,"path":89,"stem":90,"children":91},"Frontend","/frontend","05.frontend",[92,95,99,103,107],{"title":93,"path":89,"stem":94},"フロントエンド","05.frontend/index",{"title":96,"path":97,"stem":98},"モジュール内部構造","/frontend/module-anatomy","05.frontend/01.module-anatomy",{"title":100,"path":101,"stem":102},"API アクセスの一本道","/frontend/api-access-chain","05.frontend/02.api-access-chain",{"title":104,"path":105,"stem":106},"i18n","/frontend/i18n","05.frontend/03.i18n",{"title":108,"path":109,"stem":110},"デザインシステム","/frontend/design-system","05.frontend/04.design-system",{"title":112,"path":113,"stem":114,"children":115},"Go Agent And Cli","/go-agent-and-cli","06.go-agent-and-cli",[116,119,123],{"title":117,"path":113,"stem":118},"Go agent と CLI","06.go-agent-and-cli/index",{"title":120,"path":121,"stem":122},"Go agent","/go-agent-and-cli/go-agent","06.go-agent-and-cli/01.go-agent",{"title":124,"path":125,"stem":126},"CLI","/go-agent-and-cli/cli","06.go-agent-and-cli/02.cli",{"title":128,"path":129,"stem":130,"children":131},"Modules","/modules","07.modules",[132,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191],{"title":133,"path":129,"stem":134},"モジュール","07.modules/index",{"title":136,"path":137,"stem":138},"テーブル","/modules/table","07.modules/01.table",{"title":140,"path":141,"stem":142},"ドキュメントツリー","/modules/document","07.modules/02.document",{"title":144,"path":145,"stem":146},"AIチャット","/modules/ai","07.modules/03.ai",{"title":148,"path":149,"stem":150},"認証・権限","/modules/auth","07.modules/04.auth",{"title":152,"path":153,"stem":154},"AI取込","/modules/organize","07.modules/05.organize",{"title":156,"path":157,"stem":158},"ストレージ","/modules/storage","07.modules/06.storage",{"title":160,"path":161,"stem":162},"NAS同期","/modules/sync","07.modules/07.sync",{"title":164,"path":165,"stem":166},"ワークスペース","/modules/workspace","07.modules/08.workspace",{"title":168,"path":169,"stem":170},"テナントとメンバーシップ","/modules/tenant-membership","07.modules/09.tenant-membership",{"title":172,"path":173,"stem":174},"検索","/modules/search","07.modules/10.search",{"title":176,"path":177,"stem":178},"表示ビュー","/modules/display","07.modules/11.display",{"title":180,"path":181,"stem":182},"テンプレート","/modules/template","07.modules/12.template",{"title":184,"path":185,"stem":186},"メール","/modules/mail","07.modules/13.mail",{"title":188,"path":189,"stem":190},"電話","/modules/phone","07.modules/14.phone",{"title":192,"path":193,"stem":194},"リアルタイム","/modules/realtime","07.modules/15.realtime",{"title":196,"path":197,"stem":198,"children":199},"Infra And Deploy","/infra-and-deploy","08.infra-and-deploy",[200,203,207],{"title":201,"path":197,"stem":202},"インフラとデプロイ","08.infra-and-deploy/index",{"title":204,"path":205,"stem":206},"環境の種類","/infra-and-deploy/environments","08.infra-and-deploy/01.environments",{"title":208,"path":209,"stem":210},"セルフホスト構成","/infra-and-deploy/self-host","08.infra-and-deploy/02.self-host",{"title":212,"path":213,"stem":214,"children":215},"docs-map","/docs-map","09.docs-map/index",[216],{"title":212,"path":213,"stem":214},{"id":218,"title":148,"body":219,"description":650,"extension":651,"meta":652,"navigation":653,"path":149,"seo":654,"stem":150,"__hash__":655},"docs/07.modules/04.auth.md",{"type":220,"value":221,"toc":641},"minimark",[222,226,230,250,253,346,350,367,481,485,498,541,544,611],[223,224,148],"h1",{"id":225},"認証権限",[227,228,229],"h2",{"id":229},"一言でいうと",[231,232,233,234,238,239,238,242,245,246,249],"p",{},"「誰が」「何を」「どこまで」できるかを決めるモジュール。認証は JWT ベース、権限モデルは Discord のロール方式（1ユーザーに複数ロールを割り当て、ロールごとに権限を付与）を採用している。認可判定そのもののアルゴリズムと primitives（",[235,236,237],"code",{},"ResourceType"," × ",[235,240,241],{},"Action",[235,243,244],{},"Scope","）の詳細は ",[247,248,52],"a",{"href":53}," にまとめてあるので、このページはモジュールの構造に絞る。",[227,251,252],{"id":252},"主要ドメイン概念",[254,255,256,269],"table",{},[257,258,259],"thead",{},[260,261,262,266],"tr",{},[263,264,265],"th",{},"概念",[263,267,268],{},"役割",[270,271,272,287,297,319,332],"tbody",{},[260,273,274,280],{},[275,276,277],"td",{},[235,278,279],{},"DynamicRole",[275,281,282,283,286],{},"テナントごとに定義できるロール。",[235,284,285],{},"position","（階層順位）を持つ",[260,288,289,294],{},[275,290,291],{},[235,292,293],{},"UserRole",[275,295,296],{},"ユーザー ↔ ロールの多対多割り当て（Discord 方式：1人が複数ロールを持てる）",[260,298,299,304],{},[275,300,301],{},[235,302,303],{},"PermissionRule",[275,305,306,307,309,310,309,312,314,315,318],{},"権限の最小単位。",[235,308,237],{}," + ",[235,311,241],{},[235,313,244],{}," の3値からなる sealed class（",[235,316,317],{},"GeneralRule"," 等）",[260,320,321,326],{},[275,322,323],{},[235,324,325],{},"RolePermission",[275,327,328,329,331],{},"ロール ↔ ",[235,330,303],{}," の割り当て",[260,333,334,343],{},[275,335,336,339,340],{},[235,337,338],{},"AuthContext"," / ",[235,341,342],{},"AuthenticatedUserContext",[275,344,345],{},"リクエストごとの認証済みユーザー・テナント文脈",[227,347,349],{"id":348},"backend-構造","Backend 構造",[231,351,352,355,356,359,360,363,364,366],{},[235,353,354],{},"core/auth/"," は ",[235,357,358],{},"role"," の概念も内包している（",[235,361,362],{},"domain/model/DynamicRole.kt"," 等はここにあり、別モジュールに ",[235,365,358],{}," は存在しない）。",[368,369,370,415,429,438,451,463,469],"ul",{},[371,372,373,376,377,380,381,339,384,387,388,339,391,339,394,397,398,401,402,405,406,401,409,401,412],"li",{},[235,374,375],{},"api/controller/",": ",[235,378,379],{},"AuthController","（ログイン/ログアウト）、",[235,382,383],{},"AuthSetupController",[235,385,386],{},"BuiltInAuthController","（初期セットアップ・組み込み認証）、",[235,389,390],{},"RoleController",[235,392,393],{},"RolePermissionController",[235,395,396],{},"UserRoleController","（ロール・権限・割り当て CRUD）、",[235,399,400],{},"PermissionController","、",[235,403,404],{},"PlatformAdminController","（運営者向け横断操作）、",[235,407,408],{},"MyTenantsController",[235,410,411],{},"ResourceResolverController",[235,413,414],{},"DemoAuthController",[371,416,417,420,421,424,425,428],{},[235,418,419],{},"domain/service/AuthorizationService",": 権限・ロール管理の中心サービス（\"Centralized authorization service\"）。",[235,422,423],{},"AuthorizationCache"," でキャッシュし、",[235,426,427],{},"CacheEvictionService"," が変更時に無効化する",[371,430,431,434,435,437],{},[235,432,433],{},"domain/service/RoleHierarchyService",": ロールの階層順位（",[235,436,285],{},"）を扱う。「自分より上位のロールは操作できない」といったガードの土台",[371,439,440,443,444,339,447,450],{},[235,441,442],{},"domain/service/UserRoleService",": ユーザーへのロール割り当て・同期（\"following Discord's model where users can have multiple roles\"、",[235,445,446],{},"syncRolesForUser",[235,448,449],{},"syncMembersForRole"," は差分計算してから適用する Discord 方式の同期）",[371,452,453,376,456,401,459,462],{},[235,454,455],{},"infrastructure/jwt/",[235,457,458],{},"JwtClaimsExtractor",[235,460,461],{},"TenantAwareJwtAuthenticationConverter","（JWT からテナント文脈付きの認証情報へ変換）",[371,464,465,468],{},[235,466,467],{},"infrastructure/security/",": Spring Security 設定",[371,470,471,376,474,309,476,309,478,480],{},[235,472,473],{},"domain/model/PermissionRule.kt",[235,475,237],{},[235,477,241],{},[235,479,244],{}," の3値からなる sealed class。「文字列処理は一切ビジネスロジックで行わない」とコメントされており、DB 文字列表現への変換は Mapper 層に閉じている",[227,482,484],{"id":483},"frontend-構造","Frontend 構造",[231,486,487,488,491,492,494,495,497],{},"backend の ",[235,489,490],{},"auth","（role を含む）は frontend では ",[235,493,490],{}," と ",[235,496,358],{}," の2モジュールに分かれている。",[368,499,500,522],{},[371,501,502,376,505,508,509,401,512,401,515,518,519],{},[235,503,504],{},"app/modules/auth/",[235,506,507],{},"composables/useDesktopAuth.ts","（Tauri デスクトップの認証）、",[235,510,511],{},"useDesktopSessionGuard.ts",[235,513,514],{},"usePlatformAdmin.ts",[235,516,517],{},"useSetup.ts","（初期セットアップ）、",[235,520,521],{},"repositories/AuthSetupRepository.ts",[371,523,524,376,527,530,531,530,534,530,537,540],{},[235,525,526],{},"app/modules/role/",[235,528,529],{},"composables/useRoles.ts","・",[235,532,533],{},"useRoleForm.ts",[235,535,536],{},"useRoleHierarchy.ts",[235,538,539],{},"useRolePermissions.ts","（ロール CRUD・階層・権限編集の UI ロジック）",[227,542,543],{"id":543},"他モジュールとの辺",[368,545,546,559,571,598],{},[371,547,548,549,309,552,555,556,558],{},"全モジュール: ",[235,550,551],{},"@PreAuthorize",[235,553,554],{},"AuthorizationService"," によるチェックはほぼ全 Controller が通る（",[247,557,52],{"href":53}," 参照）",[371,560,561,339,564,567,568,570],{},[235,562,563],{},"membership",[235,565,566],{},"tenant","（frontend ",[235,569,566],{},"）: テナントメンバーシップ・招待は別モジュール。ロール割り当ての対象になるユーザーはここから来る",[371,572,573,576,577,580,581,583,584,587,588,530,591,530,594,597],{},[235,574,575],{},"office","（WOPI）: ",[235,578,579],{},"WopiAccessTokenAuthentication"," のようにモジュール固有の認証方式が ",[235,582,490],{}," の ",[235,585,586],{},"Authentication"," 実装として追加されることがある（",[235,589,590],{},"SandboxRenderAuthentication",[235,592,593],{},"ServiceAccountAuthentication",[235,595,596],{},"MediaAccessAuthentication"," など多数）",[371,599,600,603,604,607,608,610],{},[235,601,602],{},"rolesync",": 外部システムとのロール同期（",[235,605,606],{},"RoleSyncResult"," モデルはこの ",[235,609,490],{}," 内にある）",[612,613,615],"callout",{"type":614},"warning",[231,616,617,618,621,622,625,626,629,630,633,634,494,637,640],{},"テナント・主キーの指定はエンドポイントの種類ごとに規約が固定されている（ルート ",[235,619,620],{},"CLAUDE.md"," 参照）：in-tenant エンドポイントは ",[235,623,624],{},"X-Tenant-Id"," ヘッダー（",[235,627,628],{},"TenantContextFilter"," が RLS context を設定）、platform-admin の横断エンドポイントは ",[235,631,632],{},"/tenants/{tenantId}/"," パス変数。query param でテナントを渡すのはどちらの規約にも当てはまらない逸脱として禁止されている。新しい認可判定を書く前に、同種 Controller が ",[235,635,636],{},"@PathVariable",[235,638,639],{},"@RequestHeader"," のどちらでテナントを取っているかを確認してから合わせること。",{"title":642,"searchDepth":643,"depth":643,"links":644},"",2,[645,646,647,648,649],{"id":229,"depth":643,"text":229},{"id":252,"depth":643,"text":252},{"id":348,"depth":643,"text":349},{"id":483,"depth":643,"text":484},{"id":543,"depth":643,"text":543},"JWT認証、Discord方式の権限モデル、primitives-only認可。backend core/auth (roleを含む) ⇄ frontend app/modules/auth + app/modules/role の深掘り。","md",{},true,{"title":148,"description":650},"x_pCsyxrqRqrXRBwl1cEWvubxmipAA5htHePDKUbnmU",[657,659,660,662,663,664,665,666,667,668,669,670,672,673,674,675,676,678,679,680,681,682,684,686,688,689,690,691,692,693,694,695,696,697,698,699,700,701,702,703,704,706,707,708,709],{"path":13,"title":658},"Astar とは何か（5分で）",{"path":17,"title":16},{"path":6,"title":661},"ようこそ",{"path":29,"title":28},{"path":33,"title":32},{"path":37,"title":36},{"path":21,"title":25},{"path":49,"title":48},{"path":53,"title":52},{"path":57,"title":56},{"path":61,"title":60},{"path":41,"title":671},"システムアーキテクチャ",{"path":73,"title":72},{"path":77,"title":76},{"path":81,"title":80},{"path":85,"title":84},{"path":65,"title":677},"バックエンドガイド",{"path":97,"title":96},{"path":101,"title":100},{"path":105,"title":104},{"path":109,"title":108},{"path":89,"title":683},"フロントエンドガイド",{"path":121,"title":685},"Go agent — NAS 同期エージェント",{"path":125,"title":687},"astar CLI",{"path":113,"title":117},{"path":137,"title":136},{"path":141,"title":140},{"path":145,"title":144},{"path":149,"title":148},{"path":153,"title":152},{"path":157,"title":156},{"path":161,"title":160},{"path":165,"title":164},{"path":169,"title":168},{"path":173,"title":172},{"path":177,"title":176},{"path":181,"title":180},{"path":185,"title":184},{"path":189,"title":188},{"path":193,"title":192},{"path":129,"title":705},"モジュール索引",{"path":205,"title":204},{"path":209,"title":208},{"path":197,"title":201},{"path":213,"title":710},"docs/ 地図",1785452455333]