Skip to content

feat: accounts, sessions and persons - #13

Merged
jalmena merged 5 commits into
developfrom
feature/accounts
Sep 23, 2026
Merged

jalmena merged 5 commits into
developfrom
feature/accounts

Conversation

@jalmena

@jalmena jalmena commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Second Phase 1 slice: the account model and API.

  • Data: users, auth sessions, persons, person access (owner/manager/viewer), audit log and settings; UUIDv7 identifiers; UTC datetimes portable across SQLite and PostgreSQL; first migration; migrations applied at start-up.
  • Auth: argon2id passwords, hashed cookie sessions (idle 14 d, absolute 90 d), sudo mode (5 min) for destructive actions, login rate limiting, CSRF via fetch metadata / origin, audit log with identifiers only, environment bootstrap of the first administrator.
  • API: /api/auth (instance status, claim, login, logout, session, sudo, own preferences, password change), /api/users (admin: list, create, disable, enable, reset password), /api/persons (CRUD scoped by access, sharing, soft delete under sudo).
  • Tests: 24, run on both engines in CI; verified locally on SQLite and on PostgreSQL 16, alembic check clean on both.

…ings tables

UUIDv7 identifiers, a UTC datetime type that behaves the same on SQLite and PostgreSQL, the first migration, programmatic migrations at start-up and request-scoped sessions.

Signed-off-by: Jose David <josedalmena@gmail.com>
… rate limiting and CSRF protection

Passwords hashed with argon2id; sessions stored as hashes with idle and absolute lifetimes; a five-minute sudo mode for destructive actions; an in-memory login limiter; cross-site request forgery refused through fetch metadata or origin checks; an audit log with identifiers only.

Signed-off-by: Jose David <josedalmena@gmail.com>
…th owner, manager and viewer access

The first person claims the instance and becomes administrator; administrators create, disable and reset accounts; each user keeps language, theme and uncertainty preferences; persons are scoped to the users that may see them, shared by their owner, and soft-deleted under sudo mode.

Signed-off-by: Jose David <josedalmena@gmail.com>
…nd person access

Twenty-four tests exercised on SQLite and PostgreSQL through the API; the development guide documents the claim flow and the bootstrap variables.

Signed-off-by: Jose David <josedalmena@gmail.com>
SQLite gets a fresh file per test; a shared PostgreSQL kept state between tests, so the claim of the first test made later claims fail.

Signed-off-by: Jose David <josedalmena@gmail.com>
@jalmena
jalmena merged commit 17aba25 into develop Sep 23, 2026
5 checks passed
@jalmena
jalmena deleted the feature/accounts branch September 23, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant