T01: core infrastructure + auth + multi-tenant + RLS

- 10 models: tenants, users, user_tenants, roles, sessions, audit_log, deletion_log, notifications, password_reset_tokens, api_tokens
- Session-based auth (Redis + PostgreSQL audit trail)
- Multi-tenant with ORM-level filtering + PostgreSQL RLS (set_config)
- RBAC with roles/permissions + field-level permissions
- CSRF protection via Origin header validation
- Auth rate limiting (Redis counters with TTL)
- CORS with explicit origins (no wildcard)
- Health endpoint (no auth required)
- Notification service + audit log middleware
- 29 tests, 26 ACs, all passing
- Coverage: 62% (infrastructure modules pending coverage in later tasks)
This commit is contained in:
leocrm-bot
2026-06-29 00:10:10 +02:00
parent 3cc0b2e1b4
commit 7a7daf8100
137 changed files with 3866 additions and 10195 deletions
-45
View File
@@ -1,45 +0,0 @@
"""Pydantic schemas for Contact endpoints."""
from __future__ import annotations
from datetime import datetime
from pydantic import BaseModel, ConfigDict, EmailStr, Field
class ContactBase(BaseModel):
first_name: str = Field(..., min_length=1, max_length=128)
last_name: str = Field(..., min_length=1, max_length=128)
email: EmailStr | None = None
phone: str | None = Field(None, max_length=64)
account_id: int | None = None
class ContactCreate(ContactBase):
pass
class ContactUpdate(BaseModel):
first_name: str | None = Field(None, min_length=1, max_length=128)
last_name: str | None = Field(None, min_length=1, max_length=128)
email: EmailStr | None = None
phone: str | None = Field(None, max_length=64)
account_id: int | None = None
class ContactOut(ContactBase):
model_config = ConfigDict(from_attributes=True)
id: int
org_id: int
owner_id: int
created_at: datetime
updated_at: datetime
deleted_at: datetime | None = None
class ContactListItem(ContactOut):
pass
__all__ = ["ContactCreate", "ContactListItem", "ContactOut", "ContactUpdate"]