P0.1 — fail-closed secrets: - config.py: no default SECRET_KEY; refuses to boot when unset, a known placeholder, or <32 chars. Generate with: openssl rand -hex 32. - docker-compose.yml: literal secrets removed; runtime env now comes from a git-ignored .env via env_file. .env.example added as template. - .gitignore already covers .env (verified). P0.2 — locked CORS: - main.py: CORS_ORIGINS must be an explicit comma-separated allow-list. '*' or an empty value refuses to boot (was: silently ['*'] with allow_credentials=True). P0.3 — role-safe registration: - services/auth.py: client-supplied 'role' is IGNORED on POST /api/auth/register; self-registered users always get the least-privilege 'CS Rep' role. Unauthenticated callers can no longer mint Admin/Jerome, Admin/Wahab, or Director accounts. Tests: - conftest.py sets test SECRET_KEY/CORS_ORIGINS before app import. - New tests/test_p0_hardening.py (8 tests): role-escalation blocked for Admin/Jerome and Admin/Wahab, duplicate-email 409, and subprocess boot-validation for placeholder/short/missing secret + wildcard CORS. - Full suite: 44 passed. Redeploy note (per research): seed_units/seed_categories are insert-only, so the Aug-26 redeploy does NOT orphan historical tickets referencing units 103E/103W/105E/105W or the legacy 34-category tree. Pending Wahab: are 103E/103W/105E/105W real apartments dropped from the Excel regeneration? Optional follow-up: floor-number backfill for already- seeded units (mapping corrected floors; existing rows keep old values). Checks per HARDENING.md acceptance: - [x] starting without a real key fails loudly (subprocess-verified) - [x] compose carries no literal secret; secrets come from .env - [x] CORS_ORIGINS explicit allow-list, '*' rejected - [x] unauthenticated register cannot mint Admin/* or Director
113 lines
4.5 KiB
Python
113 lines
4.5 KiB
Python
"""Denya OneCare — FastAPI application entry point."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from contextlib import asynccontextmanager
|
|
from pathlib import Path
|
|
|
|
from fastapi import FastAPI
|
|
from fastapi.middleware.cors import CORSMiddleware
|
|
from fastapi.staticfiles import StaticFiles
|
|
from sqlalchemy import text
|
|
|
|
from app.core.config import settings
|
|
from app.core.database import Base, async_session_factory, engine
|
|
from app.routers import auth, health, pages, tickets, whatsapp
|
|
from app.services.seed import seed_categories, seed_units, seed_users
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
async def ensure_legacy_schema(conn) -> None:
|
|
"""Add columns/data changes from alembic migrations that legacy create_all databases lack."""
|
|
result = await conn.execute(text("PRAGMA table_info(categories)"))
|
|
columns = {row[1] for row in result}
|
|
if "show_in_form" not in columns:
|
|
await conn.execute(
|
|
text("ALTER TABLE categories ADD COLUMN show_in_form BOOLEAN NOT NULL DEFAULT 1")
|
|
)
|
|
logger.info("Added missing categories.show_in_form column (legacy database)")
|
|
|
|
result = await conn.execute(text("SELECT name FROM sqlite_master WHERE type='table' AND name='tickets'"))
|
|
if result.scalar():
|
|
result = await conn.execute(text("PRAGMA table_info(tickets)"))
|
|
ticket_columns = {row[1] for row in result}
|
|
if "phone" not in ticket_columns:
|
|
await conn.execute(
|
|
text("ALTER TABLE tickets ADD COLUMN phone VARCHAR(50)")
|
|
)
|
|
logger.info("Added missing tickets.phone column (legacy database)")
|
|
if "reported_at" not in ticket_columns:
|
|
await conn.execute(
|
|
text("ALTER TABLE tickets ADD COLUMN reported_at DATETIME")
|
|
)
|
|
await conn.execute(
|
|
text("UPDATE tickets SET reported_at = created_at WHERE reported_at IS NULL")
|
|
)
|
|
logger.info("Added missing tickets.reported_at column (legacy database)")
|
|
result = await conn.execute(
|
|
text(
|
|
"UPDATE categories SET name = 'Missing Item' "
|
|
"WHERE type = 'cs' AND name = 'Lost Property' AND parent_id IS NULL "
|
|
"AND NOT EXISTS (SELECT 1 FROM categories c2 "
|
|
"WHERE c2.type = 'cs' AND c2.name = 'Missing Item' AND c2.parent_id IS NULL)"
|
|
)
|
|
)
|
|
if result.rowcount:
|
|
logger.info("Renamed legacy 'Lost Property' category to 'Missing Item'")
|
|
|
|
|
|
@asynccontextmanager
|
|
async def lifespan(app: FastAPI):
|
|
"""Initialise database and seed data on startup."""
|
|
logger.info("Starting Denya OneCare …")
|
|
async with engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
await ensure_legacy_schema(conn)
|
|
async with async_session_factory() as session:
|
|
await seed_users(session)
|
|
await session.commit()
|
|
await seed_units(session, json_path=str(settings.BASE_DIR / "apartment_mapping.json"))
|
|
await session.commit()
|
|
await seed_categories(session)
|
|
await session.commit()
|
|
yield
|
|
await engine.dispose()
|
|
logger.info("Denya OneCare stopped.")
|
|
|
|
|
|
app = FastAPI(
|
|
title=settings.APP_NAME,
|
|
version="0.1.0",
|
|
lifespan=lifespan,
|
|
)
|
|
|
|
# ── CORS (HARDENING.md P0.2 — explicit origin allow-list, never "*") ──
|
|
_origins = [o.strip() for o in settings.CORS_ORIGINS.split(",") if o.strip()]
|
|
if "*" in _origins or not _origins:
|
|
raise RuntimeError(
|
|
"CORS_ORIGINS must be an explicit comma-separated origin allow-list "
|
|
"(e.g. 'https://denya.sysloggh.net,http://localhost:8000'). "
|
|
"'*' with allow_credentials=True is invalid and unsafe. Refusing to start."
|
|
)
|
|
app.add_middleware(
|
|
CORSMiddleware,
|
|
allow_origins=_origins,
|
|
allow_credentials=True,
|
|
allow_methods=["*"],
|
|
allow_headers=["*"],
|
|
)
|
|
|
|
# ── Static files (uploads) ───────────────────────────────────────────
|
|
uploads_dir = Path(settings.BASE_DIR / "uploads")
|
|
uploads_dir.mkdir(parents=True, exist_ok=True)
|
|
app.mount("/uploads", StaticFiles(directory=str(uploads_dir)), name="uploads")
|
|
|
|
# ── Routers ──────────────────────────────────────────────────────────
|
|
app.include_router(health.router)
|
|
app.include_router(auth.router)
|
|
app.include_router(whatsapp.router)
|
|
app.include_router(tickets.router)
|
|
app.include_router(pages.router)
|