531dc968a8
- Add Logto OIDC integration (app/core/logto.py): CookieStorage adapter, create/decode session token helpers, sync_logto_user upsert - New auth endpoints (/api/v1/auth): sign-in, callback, sign-out, me - AuthRedirectMiddleware: protects HTML pages, redirects to /setup when Logto is unconfigured, to /login otherwise - Update require_admin_auth: accepts dmarq_session cookie JWT first, then API key, then Bearer JWT (fully backward compatible) - Update User model: add logto_id, username, picture, created_at, updated_at; make hashed_password nullable for Logto-only users; is_superuser default=True - New Alembic migration d4e5f6a7b8c9 for the above schema changes - Add LOGTO_ENDPOINT / LOGTO_APP_ID / LOGTO_APP_SECRET / LOGTO_REDIRECT_URI settings with logto_configured property - Create login.html (Sign in with Logto button) and setup.html (step-by-step configuration guide) - Update base.html: user menu with avatar/name and sign-out via Alpine.js fetch to /api/v1/auth/me - Update settings.html: remove localStorage adminApiKey; session cookie is sent automatically by browser; add 401 → /login redirect - Update requirements.txt: replace fastapi-users additions with logto + aiohttp - Add test_auth.py: 18 new tests covering session tokens, CookieStorage, sync_logto_user, /me, /sign-in (503), /sign-out cookie clearing - Fix test_security_extra.py: pass Request mock to require_admin_auth; add new test_valid_session_cookie_returns_auth_context Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/b448f585-7646-40f8-ae2d-9986c361e3fd Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
45 lines
1.7 KiB
Python
45 lines
1.7 KiB
Python
from datetime import datetime
|
||
|
||
from sqlalchemy import Boolean, Column, DateTime, Integer, String
|
||
from sqlalchemy.orm import relationship
|
||
|
||
from app.core.database import Base
|
||
|
||
|
||
class User(Base):
|
||
"""User model – local shadow of the identity managed by Logto."""
|
||
|
||
__tablename__ = "users"
|
||
|
||
id = Column(Integer, primary_key=True, index=True)
|
||
email = Column(String, unique=True, index=True, nullable=False)
|
||
# Logto subject claim (the user's stable ID inside Logto).
|
||
# Null for users that pre-date Logto integration or for
|
||
# programmatic/service accounts created directly in the DB.
|
||
logto_id = Column(String, unique=True, index=True, nullable=True)
|
||
# hashed_password kept for possible future local-auth fallback; nullable
|
||
# because Logto users authenticate externally and have no local password.
|
||
hashed_password = Column(String, nullable=True)
|
||
is_active = Column(Boolean, default=True)
|
||
# For now all users are treated as admin. RBAC tiers are planned.
|
||
is_superuser = Column(Boolean, default=True)
|
||
is_verified = Column(Boolean, default=False)
|
||
|
||
# Profile – synced from Logto claims on every login
|
||
full_name = Column(String, nullable=True)
|
||
username = Column(String, nullable=True)
|
||
organization = Column(String, nullable=True)
|
||
picture = Column(String, nullable=True)
|
||
|
||
# Timestamps
|
||
created_at = Column(DateTime, default=datetime.utcnow, nullable=True)
|
||
updated_at = Column(
|
||
DateTime,
|
||
default=datetime.utcnow,
|
||
onupdate=datetime.utcnow,
|
||
nullable=True,
|
||
)
|
||
|
||
# Relationships
|
||
user_domains = relationship("UserDomain", back_populates="user", cascade="all, delete-orphan")
|