Phase 1: Fix all critical release blockers (B1-B10)
B1: Remove duplicate get_redis() — singleton no longer overwritten B2: Plugin routes now enforce activation status via require_active_plugin() B3: Fix UploadFile ForwardRef error — remove functools.wraps from wrap_plugin_route B4: DMS upload uses true streaming via save_stream() instead of RAM accumulation B5: Worker on_startup registers plugin event handlers + webhook dispatcher B6: Implement send_password_reset_email job, remove raw token logging B7: Webhook SSRF protection (IP validation, no redirects), secret removed from response B8: RLS repair migration 0044 + separate crm_runtime DB user (NOSUPERUSER, NOBYPASSRLS) B9: Fix .env.docker.example AUTH_SECRET → SECRET_KEY B10: Remove Redis default password, remove exposed DB/Redis ports Also: add frontend_url to config, add SMTP settings to .env.docker.example, update prestart.sh to use MIGRATION_DATABASE_URL for alembic.
This commit is contained in:
@@ -80,3 +80,72 @@ async def get_job_status(job_id: str) -> dict[str, Any] | None:
|
||||
"start_time": job_info.start_time.isoformat() if job_info.start_time else None,
|
||||
"finish_time": job_info.finish_time.isoformat() if job_info.finish_time else None,
|
||||
}
|
||||
|
||||
|
||||
# ── Password Reset Email Job ─────────────────────────────────────────────────
|
||||
|
||||
async def send_password_reset_email(
|
||||
ctx: dict[str, Any],
|
||||
*,
|
||||
user_id: str,
|
||||
email: str,
|
||||
raw_token: str,
|
||||
expires_at: str,
|
||||
) -> None:
|
||||
"""Send a password reset email via SMTP.
|
||||
|
||||
This is an ARQ worker function. It is registered with the job registry
|
||||
so the worker can execute it when the auth service enqueues it.
|
||||
"""
|
||||
import aiosmtplib
|
||||
from email.mime.text import MIMEText
|
||||
from email.mime.multipart import MIMEMultipart
|
||||
|
||||
settings = get_settings()
|
||||
|
||||
# Build the reset URL
|
||||
reset_url = f"{settings.frontend_url.rstrip('/')}/reset-password?token={raw_token}"
|
||||
|
||||
# Build the email
|
||||
msg = MIMEMultipart("alternative")
|
||||
msg["From"] = settings.smtp_from_email
|
||||
msg["To"] = email
|
||||
msg["Subject"] = "LeoCRM — Passwort zurücksetzen"
|
||||
|
||||
text_body = (
|
||||
f"Sie haben angefordert, Ihr Passwort zurückzusetzen.\n\n"
|
||||
f"Klicken Sie auf den folgenden Link, um ein neues Passwort zu setzen:\n"
|
||||
f"{reset_url}\n\n"
|
||||
f"Dieser Link ist gültig bis {expires_at}.\n\n"
|
||||
f"Falls Sie diese Anfrage nicht gestellt haben, können Sie diese\n"
|
||||
f"E-Mail ignorieren. Ihr Passwort bleibt unverändert.\n"
|
||||
)
|
||||
html_body = (
|
||||
f"<html><body>"
|
||||
f"<h2>Passwort zurücksetzen</h2>"
|
||||
f"<p>Sie haben angefordert, Ihr Passwort zurückzusetzen.</p>"
|
||||
f"<p><a href=\"{reset_url}\">Passwort jetzt zurücksetzen</a></p>"
|
||||
f"<p>Dieser Link ist gültig bis {expires_at}.</p>"
|
||||
f"<p>Falls Sie diese Anfrage nicht gestellt haben, können Sie diese "
|
||||
f"E-Mail ignorieren. Ihr Passwort bleibt unverändert.</p>"
|
||||
f"</body></html>"
|
||||
)
|
||||
msg.attach(MIMEText(text_body, "plain", "utf-8"))
|
||||
msg.attach(MIMEText(html_body, "html", "utf-8"))
|
||||
|
||||
# Send via SMTP
|
||||
await aiosmtplib.send(
|
||||
msg,
|
||||
hostname=settings.smtp_host,
|
||||
port=settings.smtp_port,
|
||||
username=settings.smtp_username,
|
||||
password=settings.smtp_password,
|
||||
start_tls=settings.smtp_use_tls,
|
||||
)
|
||||
logger.info("Password reset email sent to %s for user %s", email, user_id)
|
||||
|
||||
|
||||
# Register the job so the worker can find it
|
||||
from app.core.job_registry import register_job # noqa: E402
|
||||
|
||||
register_job("send_password_reset_email", send_password_reset_email)
|
||||
|
||||
Reference in New Issue
Block a user