52e3852129
- Add LocalUser model with bcrypt password hashing, email verification tokens, and password reset tokens - Add ALLOW_LOCAL_SIGNUP config flag (requires SMTP to be configured) - Add Stripe billing config fields (STRIPE_SECRET_KEY, etc.) - Add stripe_customer_id to UserProfile and stripe_price_id_monthly/ stripe_price_id_yearly to SubscriptionPlan - Create migration 018_add_local_users_and_billing - Add app/utils/local_auth.py: hash_password, verify_password, generate_token, is_token_expired, send_verification_email, send_password_reset_email, build_session_user - Add app/api/local_auth.py: signup, email verification, password reset endpoints plus signup/verify-email-sent/reset-password page routes - Add app/api/billing.py: Stripe Checkout, Customer Portal, and webhook endpoints; syncs subscription tier from webhook events - Update auth() to check LocalUser table before admin credentials fallback - Update login() to pass allow_signup context variable to template - Add signup.html, verify_email_sent.html, password_reset_form.html, billing_success.html templates (Alpine.js, Tailwind, WCAG 2.1 AA) - Update login.html to show 'Create account' link when signup enabled - Update pricing.html CTA buttons to use Stripe Checkout for paid tiers - Add docs/BillingSetup.md with setup guide, webhook config, compliance - Add tests/test_local_auth.py (42 tests) and tests/test_billing.py (31 tests); all 106 tests in the modified test suite pass - Add stripe>=7.0.0,<15.0.0 to requirements.txt Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
48 lines
1.8 KiB
Plaintext
48 lines
1.8 KiB
Plaintext
fastapi[all] # Web framework with all extras
|
||
uvicorn # ASGI server
|
||
celery # Task queue
|
||
redis # Message broker for Celery
|
||
sqlalchemy # Database ORM
|
||
pydantic # Data validation
|
||
cryptography>=41.0.0 # Encryption for sensitive settings in database
|
||
openai # GPT integration for metadata extraction
|
||
pypdf>=3.9.0 # PDF processing for text extraction, metadata editing and rotation (upgraded from PyPDF2 to fix CVE-2023-36464)
|
||
requests # HTTP client
|
||
puremagic>=1.25,<2.0 # File type detection (pure Python)
|
||
filetype>=1.2.0,<2.0 # File type detection fallback (pure Python)
|
||
dropbox>=11.36.0 # Dropbox integration
|
||
azure-ai-documentintelligence # Azure OCR service
|
||
authlib>=1.6.5 # Authentication - fixed security vulnerabilities (GHSA-xxx)
|
||
python-dotenv # Environment variables
|
||
starlette>=0.49.1 # ASGI toolkit (used by FastAPI) - fixed DoS vulnerability
|
||
alembic # Database migrations
|
||
slowapi>=0.1.9 # Rate limiting middleware for FastAPI
|
||
|
||
# Google Drive API
|
||
google-api-python-client>=2.79.0
|
||
google-auth>=2.22.0
|
||
google-auth-oauthlib>=1.0.0
|
||
|
||
# OneDrive/Microsoft Graph API
|
||
msgraph-core>=1.0.0
|
||
msal>=1.20.0
|
||
|
||
# AWS S3
|
||
boto3>=1.28.0
|
||
|
||
# SFTP
|
||
paramiko>=3.4.0 # SSH/SFTP implementation for Python (LGPL license)
|
||
|
||
# Notification service
|
||
apprise>=1.4.0
|
||
|
||
# AI provider aggregator - enables Anthropic, Gemini, Ollama, and 100+ LLM providers
|
||
litellm>=1.0.0,<2.0.0
|
||
|
||
# Self-hosted OCR engines (optional – only required when the provider is enabled)
|
||
pytesseract>=0.3.10 # Python wrapper for Tesseract OCR
|
||
pdf2image>=1.17.0 # Convert PDF pages to images (used by Tesseract and EasyOCR providers)
|
||
ocrmypdf>=16.0.0,<18.0.0 # Post-processing: embeds searchable text layers into PDFs via Tesseract
|
||
meilisearch>=0.31.0 # Full-text search engine client
|
||
stripe>=7.0.0,<15.0.0 # Stripe billing SDK (MIT license)
|