sprint2+3: remaining services visibility filter + search provider permission-aware + dashboard route
Check Cross-Plugin Imports / check (push) Has been cancelled

This commit is contained in:
Agent Zero
2026-07-29 02:05:14 +02:00
parent 52a5c347de
commit 517e1b6d8b
9 changed files with 370 additions and 78 deletions
@@ -0,0 +1,172 @@
"""CustomFieldDefinition service — CRUD with tenant isolation and visibility filter."""
from __future__ import annotations
import uuid
from typing import Any
from sqlalchemy import select
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.visibility import apply_visibility_filter, check_single_entity_access
from app.models.custom_field_definition import CustomFieldDefinition
def _definition_to_dict(d: CustomFieldDefinition) -> dict[str, Any]:
"""Serialize a CustomFieldDefinition ORM object to dict."""
return {
"id": str(d.id),
"entity": d.entity,
"name": d.name,
"label": d.label,
"field_type": d.field_type,
"options": d.options,
"default_value": d.default_value,
"required": d.required,
"is_active": d.is_active,
"sort_order": d.sort_order,
"owner_id": str(d.owner_id) if d.owner_id else None,
"created_by": str(d.created_by) if d.created_by else None,
"updated_by": str(d.updated_by) if d.updated_by else None,
}
async def list_custom_field_definitions(
db: AsyncSession,
tenant_id: uuid.UUID,
entity: str | None = None,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> list[dict[str, Any]]:
"""List custom field definitions for a tenant, optionally filtered by entity."""
q = select(CustomFieldDefinition).where(
CustomFieldDefinition.tenant_id == tenant_id,
CustomFieldDefinition.is_active == True, # noqa: E712
)
if entity:
q = q.where(CustomFieldDefinition.entity == entity)
if user_id and not is_system_admin:
q = await apply_visibility_filter(
db, q, "custom_field_definition", CustomFieldDefinition, user_id, tenant_id, is_system_admin
)
q = q.order_by(CustomFieldDefinition.sort_order, CustomFieldDefinition.name)
result = await db.execute(q)
return [_definition_to_dict(d) for d in result.scalars().all()]
async def get_custom_field_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
definition_id: uuid.UUID,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> dict[str, Any] | None:
"""Get a single custom field definition by ID."""
q = select(CustomFieldDefinition).where(
CustomFieldDefinition.id == definition_id,
CustomFieldDefinition.tenant_id == tenant_id,
)
result = await db.execute(q)
definition = result.scalar_one_or_none()
if definition is None:
return None
if user_id and not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "read", is_system_admin
)
if not has_access:
raise PermissionError("No access")
return _definition_to_dict(definition)
async def create_custom_field_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
user_id: uuid.UUID,
data: dict[str, Any],
) -> dict[str, Any]:
"""Create a new custom field definition."""
definition = CustomFieldDefinition(
tenant_id=tenant_id,
entity=data["entity"],
name=data["name"],
label=data["label"],
field_type=data["field_type"],
options=data.get("options"),
default_value=data.get("default_value"),
required=data.get("required", False),
is_active=data.get("is_active", True),
sort_order=data.get("sort_order", 0),
created_by=user_id,
updated_by=user_id,
owner_id=user_id,
)
db.add(definition)
await db.flush()
await db.refresh(definition)
return _definition_to_dict(definition)
async def update_custom_field_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
user_id: uuid.UUID,
definition_id: uuid.UUID,
data: dict[str, Any],
is_system_admin: bool = False,
) -> dict[str, Any] | None:
"""Update an existing custom field definition."""
q = select(CustomFieldDefinition).where(
CustomFieldDefinition.id == definition_id,
CustomFieldDefinition.tenant_id == tenant_id,
)
result = await db.execute(q)
definition = result.scalar_one_or_none()
if definition is None:
return None
if not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "write", is_system_admin
)
if not has_access:
raise PermissionError("No access")
update_fields = ["label", "field_type", "options", "default_value", "required", "is_active", "sort_order"]
for field in update_fields:
if field in data:
setattr(definition, field, data[field])
definition.updated_by = user_id
await db.flush()
await db.refresh(definition)
return _definition_to_dict(definition)
async def delete_custom_field_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
user_id: uuid.UUID,
definition_id: uuid.UUID,
is_system_admin: bool = False,
) -> bool:
"""Delete a custom field definition."""
q = select(CustomFieldDefinition).where(
CustomFieldDefinition.id == definition_id,
CustomFieldDefinition.tenant_id == tenant_id,
)
result = await db.execute(q)
definition = result.scalar_one_or_none()
if definition is None:
return False
if not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "admin", is_system_admin
)
if not has_access:
raise PermissionError("No access")
await db.delete(definition)
await db.flush()
return True
+39 -2
View File
@@ -8,6 +8,7 @@ from typing import Any
from sqlalchemy import select, delete
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.visibility import apply_visibility_filter, check_single_entity_access
from app.models.custom_field_definition import CustomFieldDefinition
@@ -15,6 +16,8 @@ async def list_definitions(
db: AsyncSession,
tenant_id: uuid.UUID,
entity: str | None = None,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> list[CustomFieldDefinition]:
"""List custom field definitions for a tenant, optionally filtered by entity."""
stmt = select(CustomFieldDefinition).where(
@@ -23,6 +26,10 @@ async def list_definitions(
)
if entity:
stmt = stmt.where(CustomFieldDefinition.entity == entity)
if user_id and not is_system_admin:
stmt = await apply_visibility_filter(
db, stmt, "custom_field_definition", CustomFieldDefinition, user_id, tenant_id, is_system_admin
)
stmt = stmt.order_by(CustomFieldDefinition.sort_order, CustomFieldDefinition.name)
result = await db.execute(stmt)
return list(result.scalars().all())
@@ -32,6 +39,8 @@ async def get_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
definition_id: uuid.UUID,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> CustomFieldDefinition | None:
"""Get a single custom field definition by ID."""
stmt = select(CustomFieldDefinition).where(
@@ -39,7 +48,16 @@ async def get_definition(
CustomFieldDefinition.tenant_id == tenant_id,
)
result = await db.execute(stmt)
return result.scalar_one_or_none()
definition = result.scalar_one_or_none()
if definition is None:
return None
if user_id and not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "read", is_system_admin
)
if not has_access:
raise PermissionError("No access")
return definition
async def create_definition(
@@ -62,6 +80,7 @@ async def create_definition(
sort_order=data.get("sort_order", 0),
created_by=user_id,
updated_by=user_id,
owner_id=user_id,
)
db.add(definition)
await db.flush()
@@ -75,12 +94,20 @@ async def update_definition(
definition_id: uuid.UUID,
data: dict[str, Any],
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> CustomFieldDefinition | None:
"""Update an existing custom field definition."""
definition = await get_definition(db, tenant_id, definition_id)
definition = await get_definition(db, tenant_id, definition_id, user_id, is_system_admin)
if definition is None:
return None
if not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "write", is_system_admin
)
if not has_access:
raise PermissionError("No access")
update_fields = ["label", "field_type", "options", "default_value", "required", "is_active", "sort_order"]
for field in update_fields:
if field in data:
@@ -98,6 +125,8 @@ async def delete_definition(
db: AsyncSession,
tenant_id: uuid.UUID,
definition_id: uuid.UUID,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> bool:
"""Delete a custom field definition."""
stmt = select(CustomFieldDefinition).where(
@@ -108,6 +137,14 @@ async def delete_definition(
definition = result.scalar_one_or_none()
if definition is None:
return False
if not is_system_admin:
has_access = await check_single_entity_access(
db, "custom_field_definition", definition.id, user_id, tenant_id, "admin", is_system_admin
)
if not has_access:
raise PermissionError("No access")
await db.delete(definition)
await db.flush()
return True
+28 -3
View File
@@ -9,6 +9,7 @@ from typing import Any
from sqlalchemy import select
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.visibility import apply_visibility_filter, check_single_entity_access
from app.models.entity_history import EntityHistory
@@ -33,6 +34,7 @@ async def record_history(
snapshot_before=snapshot_before,
snapshot_after=snapshot_after,
changes=changes,
owner_id=user_id,
)
db.add(entry)
await db.flush()
@@ -45,6 +47,8 @@ async def get_entity_history(
entity_type: str,
entity_id: uuid.UUID,
limit: int = 50,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> list[EntityHistory]:
"""Get all history entries for an entity, newest first."""
q = (
@@ -57,6 +61,10 @@ async def get_entity_history(
.order_by(EntityHistory.created_at.desc())
.limit(limit)
)
if user_id and not is_system_admin:
q = await apply_visibility_filter(
db, q, "entity_history", EntityHistory, user_id, tenant_id, is_system_admin
)
result = await db.execute(q)
return list(result.scalars().all())
@@ -65,6 +73,8 @@ async def get_history_entry(
db: AsyncSession,
tenant_id: uuid.UUID,
history_id: uuid.UUID,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> EntityHistory | None:
"""Get a specific history entry by ID."""
q = select(EntityHistory).where(
@@ -72,7 +82,16 @@ async def get_history_entry(
EntityHistory.tenant_id == tenant_id,
)
result = await db.execute(q)
return result.scalar_one_or_none()
entry = result.scalar_one_or_none()
if entry is None:
return None
if user_id and not is_system_admin:
has_access = await check_single_entity_access(
db, "entity_history", entry.id, user_id, tenant_id, "read", is_system_admin
)
if not has_access:
raise PermissionError("No access")
return entry
async def restore_from_history(
@@ -80,6 +99,7 @@ async def restore_from_history(
tenant_id: uuid.UUID,
history_id: uuid.UUID,
user_id: uuid.UUID,
is_system_admin: bool = False,
) -> dict[str, Any]:
"""Restore an entity to a previous snapshot state.
@@ -89,7 +109,7 @@ async def restore_from_history(
Returns the restored data dict.
"""
entry = await get_history_entry(db, tenant_id, history_id)
entry = await get_history_entry(db, tenant_id, history_id, user_id, is_system_admin)
if entry is None:
raise ValueError("History entry not found")
@@ -175,6 +195,7 @@ async def undo_last_action(
user_id: uuid.UUID,
entity_type: str,
entity_id: uuid.UUID,
is_system_admin: bool = False,
) -> dict[str, Any]:
"""Undo the most recent action for an entity.
@@ -191,9 +212,13 @@ async def undo_last_action(
.order_by(EntityHistory.created_at.desc())
.limit(1)
)
if not is_system_admin:
q = await apply_visibility_filter(
db, q, "entity_history", EntityHistory, user_id, tenant_id, is_system_admin
)
result = await db.execute(q)
entry = result.scalar_one_or_none()
if entry is None:
raise ValueError("No history found for this entity")
return await restore_from_history(db, tenant_id, entry.id, user_id)
return await restore_from_history(db, tenant_id, entry.id, user_id, is_system_admin)