feat: Implement multi-tenancy support in middleware and security layers
- Enhanced TenantMiddleware to validate tenant information from JWT tokens. - Added LicenseValidationMiddleware to check tenant licenses before processing requests. - Updated security utilities to extract tenant information from tokens and validate company access. - Introduced CompanyStore to manage active company state and handle company switching in the frontend. - Modified API routes to include company_id in requests for better resource management. - Improved logging and error handling throughout the middleware and API layers. - Updated frontend components to reflect changes in company management and selection. - Added new API route for fetching user's companies with proper authentication handling.
This commit is contained in:
@@ -4,12 +4,15 @@ DTOs for Seal.
|
||||
|
||||
from pydantic import BaseModel
|
||||
|
||||
|
||||
class SealBaseDTO(BaseModel):
|
||||
seal: str
|
||||
|
||||
|
||||
class SealCreateDTO(SealBaseDTO):
|
||||
pass
|
||||
|
||||
|
||||
class SealResponseDTO(SealBaseDTO):
|
||||
class Config:
|
||||
from_attributes = True
|
||||
from_attributes = True
|
||||
|
||||
@@ -1,4 +1,11 @@
|
||||
from sqlalchemy import Integer, String, ForeignKey, PrimaryKeyConstraint, ForeignKeyConstraint, UniqueConstraint
|
||||
from sqlalchemy import (
|
||||
Integer,
|
||||
String,
|
||||
ForeignKey,
|
||||
PrimaryKeyConstraint,
|
||||
ForeignKeyConstraint,
|
||||
UniqueConstraint,
|
||||
)
|
||||
from sqlalchemy.orm import Mapped, mapped_column
|
||||
from core.database import Base
|
||||
|
||||
@@ -6,16 +13,17 @@ from core.database import Base
|
||||
class Seal(Base):
|
||||
__tablename__ = "seal"
|
||||
__table_args__ = (
|
||||
PrimaryKeyConstraint('id', name='seal_pkey'),
|
||||
ForeignKeyConstraint(['tenant_id'], ['a76.tenants.id'], name='fk_seal_tenant'),
|
||||
ForeignKeyConstraint(['company_id'], ['a76.company.id'], name='fk_seal_company'),
|
||||
UniqueConstraint('tenant_id', 'company_id', 'seal', name='seal_ukey'),
|
||||
{"schema": "a76"}
|
||||
PrimaryKeyConstraint("id", name="seal_pkey"),
|
||||
ForeignKeyConstraint(["tenant_id"], ["a76.tenants.id"], name="fk_seal_tenant"),
|
||||
ForeignKeyConstraint(
|
||||
["company_id"], ["a76.company.id"], name="fk_seal_company"
|
||||
),
|
||||
UniqueConstraint("tenant_id", "company_id", "seal", name="seal_ukey"),
|
||||
{"schema": "a76"},
|
||||
)
|
||||
|
||||
|
||||
id: Mapped[int] = mapped_column(Integer, primary_key=True)
|
||||
tenant_id: Mapped[int] = mapped_column(Integer, nullable=False, index=True)
|
||||
company_id: Mapped[int] = mapped_column(Integer, nullable=False, index=True)
|
||||
|
||||
|
||||
seal: Mapped[str] = mapped_column(String(15))
|
||||
|
||||
@@ -16,8 +16,7 @@ router = APIRouter(prefix="/seals", tags=["Seal"])
|
||||
|
||||
@router.get("/", response_model=List[SealResponseDTO])
|
||||
async def list_seals(
|
||||
db: Session = Depends(get_core_db),
|
||||
current_user: dict = Depends(get_current_user)
|
||||
db: Session = Depends(get_core_db), current_user: dict = Depends(get_current_user)
|
||||
):
|
||||
"""
|
||||
List all Seal entries.
|
||||
@@ -36,7 +35,7 @@ async def list_seals(
|
||||
async def read_seal(
|
||||
seal: str,
|
||||
db: Session = Depends(get_core_db),
|
||||
current_user: dict = Depends(get_current_user)
|
||||
current_user: dict = Depends(get_current_user),
|
||||
):
|
||||
"""
|
||||
Get a specific Seal by its seal.
|
||||
@@ -58,7 +57,7 @@ async def read_seal(
|
||||
async def create_seal(
|
||||
seal_data: SealCreateDTO,
|
||||
db: Session = Depends(get_core_db),
|
||||
current_user: dict = Depends(get_current_user)
|
||||
current_user: dict = Depends(get_current_user),
|
||||
):
|
||||
"""
|
||||
Create a new Seal entry.
|
||||
@@ -77,7 +76,7 @@ async def create_seal(
|
||||
async def delete_seal(
|
||||
seal: str,
|
||||
db: Session = Depends(get_core_db),
|
||||
current_user: dict = Depends(get_current_user)
|
||||
current_user: dict = Depends(get_current_user),
|
||||
):
|
||||
"""
|
||||
Delete a Seal by its seal.
|
||||
@@ -91,4 +90,4 @@ async def delete_seal(
|
||||
|
||||
seal = SealService.delete_seal(db, seal)
|
||||
if not seal:
|
||||
raise HTTPException(status_code=404, detail="Seal not found")
|
||||
raise HTTPException(status_code=404, detail="Seal not found")
|
||||
|
||||
@@ -5,6 +5,7 @@ from . import models, dto
|
||||
Service layer for Seal.
|
||||
"""
|
||||
|
||||
|
||||
class SealService:
|
||||
@staticmethod
|
||||
def get_seal_by_id(db: Session, seal: str):
|
||||
@@ -24,4 +25,4 @@ class SealService:
|
||||
if seal:
|
||||
db.delete(seal)
|
||||
db.commit()
|
||||
return seal
|
||||
return seal
|
||||
|
||||
Reference in New Issue
Block a user