04d6562f5b
Problem 1: Remove legacy role bypass - Remove role="admin" string bypass in permissions.py resolve_permissions() - Remove role="admin"/"editor" bypass in auth.py check_permission() - Remove legacy role string fallback in deps.py require_admin/require_write - Add migration 0112: Create Role records for built-in roles and link role_id - KI-Kommentar: Legacy Role Bypass entfernt — alle Admins müssen echte role_id haben Problem 2: Enforce API token scopes - Add _token_scopes check in require_permission() in deps.py - When _token_scopes is set (API token auth), required permission must be in scopes - When _token_scopes not set (session auth), normal permission check applies Problem 3: Migration chain verification - Chain is already linear: 0027→0028_rls_force→0028_user_preferences→0029 - user_preferences table confirmed exists in DB - No duplicate revision IDs found Problem 4: RLS for remaining tenant tables - Add migration 0111: Dynamic RLS activation for any remaining tables with tenant_id - Login tables and global tables explicitly excluded - DB check shows 0 tables currently missing RLS (safety net migration) Problem 5: Permission cache invalidation on tenant switch - Add invalidate_permission_cache() call in switch_tenant() for old tenant - Stale cached permissions from old tenant no longer leak Problem 6+7: Guest system removal - Remove get_current_guest() from deps.py - Remove guest_auth.py router from main.py and routes/__init__.py - Rewrite guests.py to use regular User/UserTenant with role=guest - Remove GuestUser/GuestInvitation from models/__init__.py - Add migration 0113: Migrate guest_users to regular users, drop guest tables - Update frontend GuestLogin/GuestContacts to redirect to normal pages - KI-Kommentar: Guest-System umgebaut — Guests sind jetzt reguläre User mit role=guest
29 lines
830 B
Python
29 lines
830 B
Python
"""Routes package."""
|
|
|
|
from app.routes import (
|
|
addresses, # noqa: F401
|
|
ai_copilot, # noqa: F401
|
|
bank_accounts, # noqa: F401
|
|
audit, # noqa: F401
|
|
auth, # noqa: F401
|
|
contacts, # noqa: F401
|
|
dashboard, # noqa: F401
|
|
entity_history, # noqa: F401
|
|
currencies, # noqa: F401
|
|
taxes, # noqa: F401
|
|
sequences, # noqa: F401
|
|
system_settings, # noqa: F401
|
|
attachments, # noqa: F401
|
|
health, # noqa: F401
|
|
import_export, # noqa: F401
|
|
metrics, # noqa: F401
|
|
notifications, # noqa: F401
|
|
plugins, # noqa: F401
|
|
roles, # noqa: F401
|
|
tenants, # noqa: F401
|
|
users, # noqa: F401
|
|
user_preferences, # noqa: F401
|
|
workflows, # noqa: F401
|
|
guests, # noqa: F401 # ⚠️ Guest-System umgebaut — Guests sind jetzt reguläre User mit role=guest
|
|
)
|