◆ RBAC 审计 · 2026-04-26 19:05

接口权限审计清单

本页从当前 API 路由生成,展示每个接口的公开/受保护口径、所需权限和风险等级。用于客户验收安全边界,也用于后续继续收紧生产权限。

107接口总数
98已守卫
7公开 GET
2公开 POST
44高风险已守卫
1高风险开放
1中风险开放
0待评估写入口

一、审计规则

二、接口清单

方法公网路径所需权限暴露口径风险
GET/xia-api/health公开/只读测试入口
GET/xia-api/system/modules公开/只读测试入口
GET/xia-api/system/dashboard公开/只读测试入口
GET/xia-api/auth公开/只读测试入口
POST/xia-api/auth/login公开登录入口
GET/xia-api/auth/me公开/只读测试入口
GET/xia-api/auth/audit-logsrbac:view受 RBAC 守卫保护
GET/xia-api/auth/permission-matrix公开/只读测试入口
GET/xia-api/auth/access-check/financefinance:manage受 RBAC 守卫保护
GET/xia-api/auth/access-check/productionproduction:readiness受 RBAC 守卫保护
GET/xia-api/production-readinessproduction:readiness受 RBAC 守卫保护
POST/xia-api/production-readiness/:itemKey/statusproduction:readiness受 RBAC 守卫保护
GET/xia-api/feedbackfeedback:manage受 RBAC 守卫保护
POST/xia-api/feedback客户公开提交入口
GET/xia-api/feedback/:feedbackNo公开/只读测试入口
POST/xia-api/feedback/:feedbackNo/statusfeedback:manage受 RBAC 守卫保护
GET/xia-api/storesstores:manage受 RBAC 守卫保护
GET/xia-api/stores/:storeIdstores:manage受 RBAC 守卫保护
POST/xia-api/stores/:storeId/auditstores:manage受 RBAC 守卫保护
GET/xia-api/supplierssuppliers:manage受 RBAC 守卫保护
GET/xia-api/suppliers/:supplierIdsuppliers:manage受 RBAC 守卫保护
POST/xia-api/suppliers/:supplierId/approvesuppliers:manage受 RBAC 守卫保护
GET/xia-api/fulfillment-ordersfulfillment:manage受 RBAC 守卫保护
GET/xia-api/fulfillment-orders/:fulfillmentNofulfillment:manage受 RBAC 守卫保护
POST/xia-api/fulfillment-orders/:fulfillmentNo/acceptfulfillment:manage受 RBAC 守卫保护
POST/xia-api/fulfillment-orders/:fulfillmentNo/exception-reportfulfillment:manage受 RBAC 守卫保护
GET/xia-api/productsproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/toggle-statusproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/repricing-previewproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/repricing-versionproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/repricing-publishproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-trackingproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-approveproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-reviseproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-approval-flowproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-blockersproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-resolve-blockersproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-sync-jobproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-sync-resultproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-sync-exceptionproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-sync-retryproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/release-sync-failure-summaryproducts:release受 RBAC 守卫保护
POST/xia-api/products/:productId/withdraw-releaseproducts:release受 RBAC 守卫保护
GET/xia-api/products/:productIdproducts:release受 RBAC 守卫保护
GET/xia-api/pricingpricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/rules/:ruleIdpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/preview-impactpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/update-configpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/validate-configpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/publish-versionpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/preview-linked-impactpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/batch-publishpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/compare-linkedpricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/batches/:batchNo/auditpricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/batches/:batchNo/checklistpricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/batches/:batchNo/approval-flowpricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/batches/:batchNo/blockerspricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/batches/:batchNo/approvalpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/batches/:batchNo/retry-releasepricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/batches/:batchNo/withdraw-releasepricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/rollback-versionpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/rules/:ruleId/toggle-statuspricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/lobster-effective-pricepricing:manage受 RBAC 守卫保护
GET/xia-api/pricing/freight-rules/currentpricing:manage受 RBAC 守卫保护
POST/xia-api/pricing/order-previeworders:manage受 RBAC 守卫保护
GET/xia-api/ordersorders:manage受 RBAC 守卫保护
GET/xia-api/orders/listorders:manage受 RBAC 守卫保护
GET/xia-api/orders/:orderNoorders:manage受 RBAC 守卫保护
POST/xia-api/orders/:orderNo/split-previeworders:manage受 RBAC 守卫保护
POST/xia-api/orders/:orderNo/fulfillment-planorders:manage受 RBAC 守卫保护
POST/xia-api/orders/:orderNo/exception-summaryorders:manage受 RBAC 守卫保护
POST/xia-api/orders/previeworders:manage受 RBAC 守卫保护
POST/xia-api/ordersorders:manage受 RBAC 守卫保护
GET/xia-api/deliverydelivery:manage受 RBAC 守卫保护
GET/xia-api/delivery/ordersdelivery:manage受 RBAC 守卫保护
GET/xia-api/delivery/orders/:deliveryNodelivery:manage受 RBAC 守卫保护
POST/xia-api/delivery/orders/:deliveryNo/handoverdelivery:manage受 RBAC 守卫保护
POST/xia-api/delivery/orders/:deliveryNo/exception-reportdelivery:manage受 RBAC 守卫保护
POST/xia-api/delivery/orders/:deliveryNo/sign-summarydelivery:manage受 RBAC 守卫保护
POST/xia-api/delivery/orders/:deliveryNo/route-plandelivery:manage受 RBAC 守卫保护
POST/xia-api/delivery/ordersdelivery:manage受 RBAC 守卫保护
GET/xia-api/signingsigning:submit受 RBAC 守卫保护
GET/xia-api/signing/pendingsigning:submit受 RBAC 守卫保护
GET/xia-api/signing/:signNosigning:submit受 RBAC 守卫保护
POST/xia-api/signingsigning:submit受 RBAC 守卫保护
GET/xia-api/financefinance:manage受 RBAC 守卫保护
GET/xia-api/finance/store-walletfinance:manage受 RBAC 守卫保护
GET/xia-api/finance/store-billsfinance:manage受 RBAC 守卫保护
GET/xia-api/finance/store-bills/:billNofinance:manage受 RBAC 守卫保护
POST/xia-api/finance/store-bills/:billNo/remindfinance:manage受 RBAC 守卫保护
POST/xia-api/finance/store-bills/:billNo/collection-summaryfinance:manage受 RBAC 守卫保护
GET/xia-api/finance/supplier-settlementsfinance:manage受 RBAC 守卫保护
GET/xia-api/finance/supplier-settlements/:settlementNofinance:manage受 RBAC 守卫保护
POST/xia-api/finance/supplier-settlements/:settlementNo/confirmfinance:manage受 RBAC 守卫保护
POST/xia-api/finance/supplier-settlements/:settlementNo/checkfinance:manage受 RBAC 守卫保护
POST/xia-api/finance/supplier-settlements/:settlementNo/mark-paidfinance:manage受 RBAC 守卫保护
POST/xia-api/finance/supplier-settlements/:settlementNo/payout-summaryfinance:manage受 RBAC 守卫保护
GET/xia-api/commissionsfinance:manage受 RBAC 守卫保护
GET/xia-api/commissions/rules/activecommission:config受 RBAC 守卫保护
POST/xia-api/commissions/rules/active/updatecommission:config受 RBAC 守卫保护
GET/xia-api/commissions/bindingscommission:config受 RBAC 守卫保护
POST/xia-api/commissions/bindingscommission:config受 RBAC 守卫保护
POST/xia-api/commissions/bindings/:bindingNo/updatecommission:config受 RBAC 守卫保护
POST/xia-api/commissions/bindings/:bindingNo/deletecommission:config受 RBAC 守卫保护
GET/xia-api/commissions/statementsfinance:manage受 RBAC 守卫保护
POST/xia-api/commissions/:commissionNo/reviewfinance:manage受 RBAC 守卫保护
POST/xia-api/commissions/:commissionNo/payoutfinance:manage受 RBAC 守卫保护