diff --git a/README.md b/README.md index d0ec0e9..5a2fc21 100644 --- a/README.md +++ b/README.md @@ -39,7 +39,7 @@ | `fox novels create --title <書名> [--slug ] [--synopsis <簡介>]` | `POST /novels` | 建立作品(需授權,見下) | | `fox novels update [--title ...] [--slug ...] [--synopsis ...]` | `PATCH /novels/:slug` | 更新作品(需授權,見下) | -> **授權缺口(待後端跟進)**:目前 `novels` 的授權端點只吃瀏覽器 session(Bear SSO cookie),尚未接受 Bearer access token;access token 也暫無 `accountId` 歸屬(見 `backend/src/access-token` 註解)。CLI 第一步先支援公開端點與 `access-tokens` 系列;待後端讓 `AccessTokenGuard` 套用到 `novels`(並為 token 加帳號歸屬)後,再補齊 `novels` 的授權命令。 +> **授權(issue #16 已補齊)**:受保護端點(`novels list/create/update`、`auth me`)的 `AuthGuard` 現在同時接受 `Authorization: Bearer ` 與瀏覽器 session(cookie);Bearer 優先。access token 需綁定帳號(`POST /access-tokens` 帶 `accountId`,或由管理員建立時指定),未綁帳號的系統 token 只能用於 `tokens verify`。CLI 待 M3 補齊 `novels list/create/update` 命令。 ## 四、AI agent 使用指引