CMDCRAGArcana.Plugin.AccessControl (cmdc_rag_arcana v0.5.0)

Copy Markdown View Source

RAG collection ACL Plugin。

:before_tool 阶段拦截 rag_search / rag_answer,按 tenant / user / role / department 校验 collection 权限。该插件默认 fail closed:

  • 未指定 collections: block
  • 未配置 allowlist/policy 且 default_allow? 为 false: block
  • 任一 collection 越权: block