fix(arch): externes Audit — 13 Backend-Fixes (Workspace-Modules, Tenant-Manifeste, Lifecycle, Contracts, Permissions)
Check Cross-Plugin Imports / check (push) Has been cancelled

Verifikation: Alle 17 Audit-Findings gegen den Code geprueft — alle bestaetigt.
Backend-Lifecycle-Fixes umgesetzt; 4 Frontend-Plugin-Architektur-Punkte
als Phase Q in die Roadmap eingeplant.

- P1 list_workspaces: Module + User-Counts gebuendelt laden (Editor-Overwrite-Bug)
- P1 active-manifests: Tenant-Deaktivierung (tenant_plugin_activation) filtern
- P1 uninstall: volle Service-Deactivation VOR registry.uninstall()
- P1 ContractRegistry: DB-Aktivstatus-Guard (Restart-Edge-Case) + Re-Activate
- P1/P2 Field-Definitions: voller Lifecycle (register/unregister) im Service
- P1/P2 Contact-Felddefinitionen (39) ins ContactsPlugin-Manifest verschoben
- P1 12 fehlende Permission-Keys registriert (AST-Scan: 0 fehlend)
- P2 contact_folder -> ContactsPlugin; ENTITY_PLUGIN_OWNERS wird befuellt
- P2 Entity-Permission-Fallback fail-closed statt contacts:read
- P2 forgejo_error_reporter is_core=False; DMS is_core=True (ADR-020)
- P2 Worker: Contacts-Trash-Cleanup ins Plugin (get_job_modules-Discovery)
- P1/P2 DSGVO-Export delegiert an DSAR-Collector (kein Core->Contacts)
- P2 False-green Tests korrigiert (or True, veraltete Route-Count-Assertion)

Verifikation: tests/test_audit_architecture_fixes.py 17/17; Regressionen
gruen (contacts_lifecycle, entity_registry, workspace_scopes, rbac,
lifecycle_service); Combo-Order-Test 35/35; Cross-Plugin-Checker 497/0;
compileall sauber; ruff auf 7-Error-Baseline.

Doku: PROGRESS.md Audit-Section, PLATFORM_ROADMAP.md Phase Q (Q1-Q4),
plugin-development-guide.md Lifecycle, permissions.md Katalog.
This commit is contained in:
Agent Zero
2026-09-13 02:25:01 +02:00
parent 86cea5d6c4
commit 4a25ac1379
25 changed files with 1020 additions and 141 deletions
+36 -8
View File
@@ -52,16 +52,44 @@ async def list_workspaces(
result = await db.execute(q)
workspaces = result.scalars().all()
items = []
for ws in workspaces:
# Count users
count_q = select(func.count()).select_from(WorkspaceUser).where(
WorkspaceUser.workspace_id == ws.id,
if not workspaces:
return {"items": [], "total": 0}
# Audit P1 (Workspace-Editor): load modules for ALL workspaces in one
# query. Previously list_workspaces() returned modules: [] for every
# workspace, so the WorkspaceManager module editor showed all modules
# as hidden (is_visible=false) and saving OVERWROTE the existing config.
ws_ids = [ws.id for ws in workspaces]
mod_result = await db.execute(
select(WorkspaceModule).where(
WorkspaceModule.workspace_id.in_(ws_ids),
WorkspaceModule.tenant_id == tenant_id,
).order_by(WorkspaceModule.menu_order)
)
modules_by_ws: dict[uuid.UUID, list[WorkspaceModule]] = {}
for mod in mod_result.scalars().all():
modules_by_ws.setdefault(mod.workspace_id, []).append(mod)
# User counts for all workspaces in one query (avoids N+1)
count_result = await db.execute(
select(WorkspaceUser.workspace_id, func.count())
.where(
WorkspaceUser.workspace_id.in_(ws_ids),
WorkspaceUser.tenant_id == tenant_id,
)
count_result = await db.execute(count_q)
user_count = count_result.scalar() or 0
items.append(_workspace_to_dict(ws, user_count=user_count))
.group_by(WorkspaceUser.workspace_id)
)
counts_by_ws: dict[uuid.UUID, int] = dict(count_result.all())
items = []
for ws in workspaces:
items.append(
_workspace_to_dict(
ws,
modules=modules_by_ws.get(ws.id, []),
user_count=counts_by_ws.get(ws.id, 0),
)
)
return {"items": items, "total": len(items)}