feat: accounts, sessions and persons - #13
Merged
Merged
Conversation
…ings tables UUIDv7 identifiers, a UTC datetime type that behaves the same on SQLite and PostgreSQL, the first migration, programmatic migrations at start-up and request-scoped sessions. Signed-off-by: Jose David <josedalmena@gmail.com>
… rate limiting and CSRF protection Passwords hashed with argon2id; sessions stored as hashes with idle and absolute lifetimes; a five-minute sudo mode for destructive actions; an in-memory login limiter; cross-site request forgery refused through fetch metadata or origin checks; an audit log with identifiers only. Signed-off-by: Jose David <josedalmena@gmail.com>
…th owner, manager and viewer access The first person claims the instance and becomes administrator; administrators create, disable and reset accounts; each user keeps language, theme and uncertainty preferences; persons are scoped to the users that may see them, shared by their owner, and soft-deleted under sudo mode. Signed-off-by: Jose David <josedalmena@gmail.com>
…nd person access Twenty-four tests exercised on SQLite and PostgreSQL through the API; the development guide documents the claim flow and the bootstrap variables. Signed-off-by: Jose David <josedalmena@gmail.com>
SQLite gets a fresh file per test; a shared PostgreSQL kept state between tests, so the claim of the first test made later claims fail. Signed-off-by: Jose David <josedalmena@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Second Phase 1 slice: the account model and API.
/api/auth(instance status, claim, login, logout, session, sudo, own preferences, password change),/api/users(admin: list, create, disable, enable, reset password),/api/persons(CRUD scoped by access, sharing, soft delete under sudo).alembic checkclean on both.