627360113f
P8: Invalidate all Redis sessions when is_system_admin changes - Added is_system_admin to UserUpdate schema and UserResponse - Added invalidate_all_user_sessions call in users.py route - Added is_system_admin param to user_service.update_user P9: Remove no-op permission resolution strategies - Only highest_wins supported, others removed as no-ops - Updated tenant.py CheckConstraint to only allow highest_wins - Added KI-Kommentar in permissions.py P10: Remove legacy check_permission from auth.py - Removed duplicate check_permission and filter_fields_by_permission - Fixed ai_copilot_service.py to use permissions.check_permission - Updated ai_copilot route to pass resolved permissions dict P11: Verified — no guest_users remnants found P12: Migrate ContactFolderPermission to EntityPermission - contact_folder_permission_service now delegates to entity_permission_service - contact_folder_service uses EntityPermission queries - Removed ContactFolderPermission from models/__init__.py - Created migration 0114 to migrate data and drop table P13: Added RLS migration history comment in alembic/env.py P14: Verified — services already apply visibility_filter - saved_filters/views filter by user_id (personal data) - workspaces are UI context only - notifications already filter by entity access P15: Split entity_permission_service.py (932 lines) into 4 modules - permission_resolver.py: get_effective_access, get_visible_ids, etc. - permission_cache.py: Redis caching functions - permission_audit.py: Audit logging helpers - entity_permission_service.py: CRUD operations + re-exports P16: Centralize PERM_RANK in permissions.py - Single source: app.core.permissions.PERM_RANK - Updated all services to import from permissions.py P17: Fix MIGRATION_DATABASE_URL to use crm_migration - docker-compose.yaml defaults changed from crm_user to crm_migration - .env.docker.example updated - prestart.sh comment updated
111 lines
4.2 KiB
Bash
111 lines
4.2 KiB
Bash
#!/bin/sh
|
|
# =============================================================================
|
|
# prestart.sh — Container entrypoint for CRM API container
|
|
#
|
|
# Responsibilities:
|
|
# 1. Run Alembic DB migrations (alembic upgrade head) using the owner user.
|
|
# 2. Set the crm_runtime password (for RLS-enforced app access).
|
|
# 3. Start uvicorn as PID 1 (so signals like SIGTERM are forwarded correctly).
|
|
#
|
|
# Notes:
|
|
# - `set -e` ensures the container crashes loudly if migrations fail.
|
|
# - The ARQ worker runs in a separate container (see worker.sh / docker-compose).
|
|
# - Migrations use MIGRATION_DATABASE_URL (crm_migration, NOSUPERUSER, BYPASSRLS).
|
|
# - The app uses DATABASE_URL (crm_runtime, NOSUPERUSER, NOBYPASSRLS).
|
|
# =============================================================================
|
|
|
|
set -e
|
|
|
|
# Use MIGRATION_DATABASE_URL for alembic (falls back to DATABASE_URL for backwards compat)
|
|
export ALEMBIC_DATABASE_URL="${MIGRATION_DATABASE_URL:-$DATABASE_URL}"
|
|
|
|
# Configure alembic to use the migration database URL
|
|
export ALEMBIC_DATABASE_URL
|
|
|
|
echo "[prestart] $(date -u +%Y-%m-%dT%H:%M:%SZ) - Running alembic upgrade head (owner user)..."
|
|
# Temporarily override DATABASE_URL for alembic
|
|
DATABASE_URL="$ALEMBIC_DATABASE_URL" alembic upgrade head
|
|
echo "[prestart] DB migrations completed successfully."
|
|
|
|
# Set passwords for all application DB roles (crm_api, crm_auth, crm_worker, crm_migration)
|
|
# Migration 0070 creates these roles without passwords; we set them here so the
|
|
# API/Worker/Auth connections can authenticate.
|
|
echo "[prestart] Setting DB role passwords..."
|
|
cat > /tmp/set_role_passwords.py << 'PYEOF'
|
|
import asyncio
|
|
import os
|
|
import re
|
|
from sqlalchemy.ext.asyncio import create_async_engine
|
|
from sqlalchemy import text
|
|
|
|
async def set_passwords():
|
|
db_url = os.environ.get('MIGRATION_DATABASE_URL', os.environ.get('DATABASE_URL', ''))
|
|
if not db_url:
|
|
print('[prestart] WARNING: No DB URL for password setup')
|
|
return
|
|
match = re.search(r'://([^:]+):([^@]+)@', db_url)
|
|
if not match:
|
|
print('[prestart] WARNING: Could not extract password from DB URL')
|
|
return
|
|
pwd = match.group(2)
|
|
engine = create_async_engine(db_url)
|
|
roles = ['crm_api', 'crm_auth', 'crm_worker', 'crm_migration']
|
|
try:
|
|
async with engine.begin() as conn:
|
|
for role in roles:
|
|
try:
|
|
await conn.execute(text(f"ALTER ROLE {role} WITH LOGIN PASSWORD '{pwd}'"))
|
|
print(f'[prestart] Password set for {role}')
|
|
except Exception as e:
|
|
print(f'[prestart] WARNING: Could not set password for {role}: {e}')
|
|
print('[prestart] DB role passwords set.')
|
|
except Exception as e:
|
|
print(f'[prestart] WARNING: Could not set DB role passwords: {e}')
|
|
finally:
|
|
await engine.dispose()
|
|
|
|
asyncio.run(set_passwords())
|
|
PYEOF
|
|
python3 /tmp/set_role_passwords.py
|
|
rm -f /tmp/set_role_passwords.py
|
|
|
|
# Set crm_runtime password if RUNTIME_DB_PASSWORD is set (legacy support)
|
|
if [ -n "$RUNTIME_DB_PASSWORD" ]; then
|
|
echo "[prestart] Setting crm_runtime password..."
|
|
python3 -c "
|
|
import asyncio
|
|
import os
|
|
from sqlalchemy.ext.asyncio import create_async_engine
|
|
from sqlalchemy import text
|
|
|
|
async def set_password():
|
|
db_url = os.environ.get('MIGRATION_DATABASE_URL', os.environ.get('DATABASE_URL', ''))
|
|
if not db_url:
|
|
print('[prestart] WARNING: No DB URL for password setup')
|
|
return
|
|
engine = create_async_engine(db_url)
|
|
pwd = os.environ.get('RUNTIME_DB_PASSWORD', '')
|
|
try:
|
|
async with engine.begin() as conn:
|
|
await conn.execute(text(
|
|
"ALTER ROLE crm_runtime WITH LOGIN PASSWORD :pwd NOSUPERUSER NOBYPASSRLS"
|
|
), {"pwd": pwd})
|
|
print('[prestart] crm_runtime password set.')
|
|
except Exception as e:
|
|
print(f'[prestart] WARNING: Could not set crm_runtime password: {e}')
|
|
finally:
|
|
await engine.dispose()
|
|
|
|
asyncio.run(set_password())
|
|
"
|
|
fi
|
|
|
|
echo "[prestart] Seeding admin user if not exists..."
|
|
python3 /app/scripts/seed_admin.py || echo "[prestart] WARNING: Admin seed failed (may already exist)"
|
|
|
|
echo "[prestart] Starting uvicorn on 0.0.0.0:8000 (workers=1)..."
|
|
exec uvicorn app.main:app \
|
|
--host 0.0.0.0 \
|
|
--port 8000 \
|
|
--workers 1
|