Files
leocrm/RBAC_PROGRESS.md
T

3.0 KiB

RBAC Build Progress — LeoCRM

Letztes Update: 2026-07-29 01:28 CEST

Sprint 1 — Fundament (14h)

Erledigt

  • EntityPermission Model erstellt (app/models/entity_permission.py)

    • Generische Tabelle für alle Entities
    • principal_type: user | group | role | guest
    • permission_level: none | read | write | admin | delete
    • expires_at für zeitlich begrenzte Freigaben
    • created_by für Audit-Trail
    • Indexes auf entity, principal, tenant, expires_at
  • OwnedMixin erstellt (app/models/owned_mixin.py)

    • owner_id Feld (nullable, FK → users.id, ON DELETE SET NULL)
    • Index auf owner_id
    • Kann auf jedes Model angewendet werden
  • Migration 0049: entity_permissions Tabelle — Ausgeführt in Produktion

  • Migration 0050: owner_id auf 15 Tabellen — Ausgeführt in Produktion

  • OwnedMixin auf alle 13 Models angewendet:

    • Contact, Address, Attachment, BankAccount, Workflow, Sequence
    • SavedFilter, SavedView, Webhook, Notification, CustomFieldDefinition
    • EntityHistory, AIConversation
  • Universeller Permission Service (app/services/entity_permission_service.py, 648 Zeilen)

    • list_permissions, create_permission, update_permission, delete_permission
    • get_effective_access (Owner → User → Group → Role → None)
    • get_visible_ids (alle sichtbaren Datensätze für User)
    • batch_get_effective_access (Batch-Resolution für Listen)
    • get_cached_visible_ids (Redis Cache, 5 Min TTL)
    • check_entity_access (einfacher Check)
    • cleanup_expired_permissions (Background Worker)
  • Universelle Permission API (app/routes/entity_permissions.py, 151 Zeilen)

    • GET /api/v1/permissions/{entity_type}/{entity_id}
    • POST /api/v1/permissions/{entity_type}/{entity_id}
    • PUT /api/v1/permissions/{entity_type}/{entity_id}/{permission_id}
    • DELETE /api/v1/permissions/{entity_type}/{entity_id}/{permission_id}
    • GET /api/v1/permissions/{entity_type}/{entity_id}/access
    • GET /api/v1/permissions/registry
  • Schema erstellt (app/schemas/entity_permission.py)

  • Route in main.py registriert

  • Alle Imports getestet — OK

  • Container neu gestartet

  • Git committed und gepusht (5afa1fa)

In Bearbeitung 🔄

  • PostgreSQL RLS Policies + set_user_context()
  • Rate Limiting auf Permission-Änderungen
  • Folder ACLs migrieren (Migration 0051)

Noch offen

  • Sprint 2-23 (siehe ENTERPRISE_RBAC_PLAN.md)

Migrationen

# Beschreibung Status
0048 contact_folder_permissions Tabelle Ausgeführt
0049 entity_permissions Tabelle Ausgeführt
0050 owner_id auf 15 Tabellen Ausgeführt
0051 Folder ACLs → entity_permissions Geplant

Git Commits

Hash Beschreibung
cc021cd feat: folder permissions (ACLs) - share folders with users/groups
5afa1fa sprint1: entity_permissions table + owned_mixin + universal permission service + API + migrations 0049+0050