3.0 KiB
3.0 KiB
RBAC Build Progress — LeoCRM
Letztes Update: 2026-07-29 01:28 CEST
Sprint 1 — Fundament (14h)
Erledigt ✅
-
EntityPermission Model erstellt (
app/models/entity_permission.py)- Generische Tabelle für alle Entities
- principal_type: user | group | role | guest
- permission_level: none | read | write | admin | delete
- expires_at für zeitlich begrenzte Freigaben
- created_by für Audit-Trail
- Indexes auf entity, principal, tenant, expires_at
-
OwnedMixin erstellt (
app/models/owned_mixin.py)- owner_id Feld (nullable, FK → users.id, ON DELETE SET NULL)
- Index auf owner_id
- Kann auf jedes Model angewendet werden
-
Migration 0049: entity_permissions Tabelle — ✅ Ausgeführt in Produktion
-
Migration 0050: owner_id auf 15 Tabellen — ✅ Ausgeführt in Produktion
-
OwnedMixin auf alle 13 Models angewendet:
- Contact, Address, Attachment, BankAccount, Workflow, Sequence
- SavedFilter, SavedView, Webhook, Notification, CustomFieldDefinition
- EntityHistory, AIConversation
-
Universeller Permission Service (
app/services/entity_permission_service.py, 648 Zeilen)- list_permissions, create_permission, update_permission, delete_permission
- get_effective_access (Owner → User → Group → Role → None)
- get_visible_ids (alle sichtbaren Datensätze für User)
- batch_get_effective_access (Batch-Resolution für Listen)
- get_cached_visible_ids (Redis Cache, 5 Min TTL)
- check_entity_access (einfacher Check)
- cleanup_expired_permissions (Background Worker)
-
Universelle Permission API (
app/routes/entity_permissions.py, 151 Zeilen)- GET /api/v1/permissions/{entity_type}/{entity_id}
- POST /api/v1/permissions/{entity_type}/{entity_id}
- PUT /api/v1/permissions/{entity_type}/{entity_id}/{permission_id}
- DELETE /api/v1/permissions/{entity_type}/{entity_id}/{permission_id}
- GET /api/v1/permissions/{entity_type}/{entity_id}/access
- GET /api/v1/permissions/registry
-
Schema erstellt (
app/schemas/entity_permission.py) -
Route in main.py registriert
-
Alle Imports getestet — OK
-
Container neu gestartet
-
Git committed und gepusht (
5afa1fa)
In Bearbeitung 🔄
- PostgreSQL RLS Policies + set_user_context()
- Rate Limiting auf Permission-Änderungen
- Folder ACLs migrieren (Migration 0051)
Noch offen ⬜
- Sprint 2-23 (siehe ENTERPRISE_RBAC_PLAN.md)
Migrationen
| # | Beschreibung | Status |
|---|---|---|
| 0048 | contact_folder_permissions Tabelle | ✅ Ausgeführt |
| 0049 | entity_permissions Tabelle | ✅ Ausgeführt |
| 0050 | owner_id auf 15 Tabellen | ✅ Ausgeführt |
| 0051 | Folder ACLs → entity_permissions | ⬜ Geplant |
Git Commits
| Hash | Beschreibung |
|---|---|
cc021cd |
feat: folder permissions (ACLs) - share folders with users/groups |
5afa1fa |
sprint1: entity_permissions table + owned_mixin + universal permission service + API + migrations 0049+0050 |