feat: implement auth, projects, and frontend foundation
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
# Auth OAuth Implementation Plan
|
||||
|
||||
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
|
||||
|
||||
**Goal:** Implement Authentik-backed OIDC login that issues internal JWT access tokens, rotates DB-backed refresh tokens, and supports secure logout.
|
||||
|
||||
**Architecture:** FastAPI route handlers delegate to focused auth services: OIDC provider client, token verifier/minting service, and refresh token store. Session state is carried in httpOnly cookies while refresh-token validity is enforced from PostgreSQL. Token trust boundary is explicit: provider token is JWKS-verified before local token minting.
|
||||
|
||||
**Tech Stack:** FastAPI, SQLAlchemy (async), Alembic, python-jose, httpx, pytest/pytest-asyncio, ruff, mypy
|
||||
|
||||
---
|
||||
|
||||
### Task 1: Config and DB schema
|
||||
|
||||
**Files:**
|
||||
- Modify: `apps/api/src/config.py`
|
||||
- Modify: `apps/api/src/models/user.py`
|
||||
- Create: `apps/api/src/models/refresh_token.py`
|
||||
- Modify: `apps/api/src/models/__init__.py`
|
||||
- Create: `apps/api/alembic/versions/0002_refresh_tokens.py`
|
||||
- Test: `apps/api/tests/test_config.py`
|
||||
- Test: `apps/api/tests/test_models.py`
|
||||
|
||||
- [ ] **Step 1: Write failing tests for OIDC/JWT config and refresh-token metadata**
|
||||
- [ ] **Step 2: Run focused tests to verify red state**
|
||||
- [ ] **Step 3: Implement minimal config and model changes**
|
||||
- [ ] **Step 4: Add migration and migration metadata test updates**
|
||||
- [ ] **Step 5: Re-run focused tests to verify green state**
|
||||
|
||||
### Task 2: Auth services
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/src/auth/__init__.py`
|
||||
- Create: `apps/api/src/auth/cookies.py`
|
||||
- Create: `apps/api/src/auth/oidc.py`
|
||||
- Create: `apps/api/src/auth/jwt_service.py`
|
||||
- Create: `apps/api/src/auth/refresh_store.py`
|
||||
- Test: `apps/api/tests/test_auth_services.py`
|
||||
|
||||
- [ ] **Step 1: Write failing tests for cookie policy, JWT mint/verify, and refresh lifecycle**
|
||||
- [ ] **Step 2: Run targeted tests to verify failures are expected**
|
||||
- [ ] **Step 3: Implement minimal auth service modules to satisfy tests**
|
||||
- [ ] **Step 4: Re-run tests and iterate until green**
|
||||
|
||||
### Task 3: Auth API routes
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/src/main.py`
|
||||
- Create: `apps/api/src/api/__init__.py`
|
||||
- Create: `apps/api/src/api/auth.py`
|
||||
- Test: `apps/api/tests/test_auth_api.py`
|
||||
|
||||
- [ ] **Step 1: Write failing API tests for `/auth/login`, `/auth/callback`, `/auth/refresh`, `/auth/logout`, `/auth/me`**
|
||||
- [ ] **Step 2: Run targeted API tests to confirm red state**
|
||||
- [ ] **Step 3: Implement minimal route handlers and dependency wiring**
|
||||
- [ ] **Step 4: Re-run API tests until green**
|
||||
|
||||
### Task 4: Verification and OpenSpec updates
|
||||
|
||||
**Files:**
|
||||
- Modify: `openspec/changes/auth-oauth/tasks.md`
|
||||
|
||||
- [ ] **Step 1: Run full checks: `pytest`, `ruff check src tests`, `mypy src`**
|
||||
- [ ] **Step 2: Run migration against local Postgres and verify current revision**
|
||||
- [ ] **Step 3: Mark completed checkboxes and capture any blockers in OpenSpec tasks**
|
||||
@@ -0,0 +1,79 @@
|
||||
# Database Models Implementation Plan
|
||||
|
||||
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
|
||||
|
||||
**Goal:** Build the backend database foundation for Headquarter with SQLAlchemy 2.0 async models, Alembic migrations, and development seed data.
|
||||
|
||||
**Architecture:** Add a minimal FastAPI backend package under `apps/api/src` with one shared declarative base, one async database/session module, and focused model modules for each core entity. Drive the work from tests that assert schema metadata and relationship wiring first, then add Alembic and seeding on top.
|
||||
|
||||
**Tech Stack:** Python 3.11, SQLAlchemy 2.x, asyncpg, Alembic, pytest, pytest-asyncio, Pydantic Settings, PostgreSQL JSONB/UUID types
|
||||
|
||||
---
|
||||
|
||||
### Task 1: Backend package skeleton and settings
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/src/__init__.py`
|
||||
- Create: `apps/api/src/config.py`
|
||||
- Create: `apps/api/src/database.py`
|
||||
- Test: `apps/api/tests/test_config.py`
|
||||
|
||||
- [ ] Step 1: Write a failing test for configuration defaults and async engine URL expectations.
|
||||
- [ ] Step 2: Run the focused config test and confirm it fails because the module does not exist.
|
||||
- [ ] Step 3: Add minimal settings and async session factory implementation.
|
||||
- [ ] Step 4: Run the focused config test and confirm it passes.
|
||||
|
||||
### Task 2: Declarative base and shared timestamp/UUID columns
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/src/models/__init__.py`
|
||||
- Create: `apps/api/src/models/base.py`
|
||||
- Test: `apps/api/tests/test_models.py`
|
||||
|
||||
- [ ] Step 1: Write a failing metadata test that imports the base and asserts mapped tables can inherit UUID/timestamp columns.
|
||||
- [ ] Step 2: Run the focused model test and confirm it fails.
|
||||
- [ ] Step 3: Implement the declarative base plus reusable UUID/timestamp mixins.
|
||||
- [ ] Step 4: Re-run the focused model test and confirm it passes.
|
||||
|
||||
### Task 3: Core entity models and relationships
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/src/models/user.py`
|
||||
- Create: `apps/api/src/models/project.py`
|
||||
- Create: `apps/api/src/models/git_repository.py`
|
||||
- Create: `apps/api/src/models/ssh_key.py`
|
||||
- Create: `apps/api/src/models/user_config.py`
|
||||
- Modify: `apps/api/src/models/__init__.py`
|
||||
- Test: `apps/api/tests/test_models.py`
|
||||
|
||||
- [ ] Step 1: Write failing tests that assert the five tables exist, required columns are present, and the expected relationships are wired.
|
||||
- [ ] Step 2: Run the focused model tests and confirm they fail because the models are missing.
|
||||
- [ ] Step 3: Implement the minimal models to satisfy the spec, including PostgreSQL UUID/JSONB fields and foreign keys.
|
||||
- [ ] Step 4: Re-run the focused model tests and confirm they pass.
|
||||
|
||||
### Task 4: Alembic integration and initial migration
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/alembic.ini`
|
||||
- Create: `apps/api/alembic/env.py`
|
||||
- Create: `apps/api/alembic/script.py.mako`
|
||||
- Create: `apps/api/alembic/versions/0001_initial_schema.py`
|
||||
- Test: `apps/api/tests/test_migration_metadata.py`
|
||||
|
||||
- [ ] Step 1: Write a failing test that imports model metadata and asserts the initial migration covers all expected tables.
|
||||
- [ ] Step 2: Run the focused migration test and confirm it fails.
|
||||
- [ ] Step 3: Add minimal Alembic configuration plus an initial migration that creates all core tables.
|
||||
- [ ] Step 4: Re-run the focused migration test and confirm it passes.
|
||||
|
||||
### Task 5: Seed data and verification
|
||||
|
||||
**Files:**
|
||||
- Create: `apps/api/scripts/seed.py`
|
||||
- Modify: `openspec/changes/database-models/tasks.md`
|
||||
- Test: `apps/api/tests/test_seed.py`
|
||||
|
||||
- [ ] Step 1: Write a failing test that verifies the seed module builds a deterministic development user payload.
|
||||
- [ ] Step 2: Run the focused seed test and confirm it fails.
|
||||
- [ ] Step 3: Implement the minimal seed helpers and script entrypoint.
|
||||
- [ ] Step 4: Re-run the focused seed test and confirm it passes.
|
||||
- [ ] Step 5: Mark completed OpenSpec checklist items and run the targeted verification commands.
|
||||
Reference in New Issue
Block a user