Compare commits

..

3 Commits

25 changed files with 738 additions and 155 deletions

View File

@@ -284,6 +284,7 @@ async def login(
"last_name": user.last_name, "last_name": user.last_name,
"role": user.role, "role": user.role,
"tenant_id": str(user.tenant_id), "tenant_id": str(user.tenant_id),
"tenant_slug": tenant.slug if tenant else str(user.tenant_id),
"is_active": user.is_active, "is_active": user.is_active,
"is_two_factor_enabled": user.totp_enabled or False, "is_two_factor_enabled": user.totp_enabled or False,
"created_at": user.created_at.isoformat() if user.created_at else None "created_at": user.created_at.isoformat() if user.created_at else None

View File

@@ -148,10 +148,13 @@ async def read_user(
✅ Implementa multi-tenancy: solo permite acceso a usuarios del propio tenant. ✅ Implementa multi-tenancy: solo permite acceso a usuarios del propio tenant.
""" """
query = select(User).where( if current_user.role.value == 'ADMIN':
User.id == user_id, query = select(User).where(User.id == user_id)
User.tenant_id == current_user.tenant_id # ✅ Seguridad multi-tenant else:
) query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query) result = await db.execute(query)
user = result.scalar_one_or_none() user = result.scalar_one_or_none()
@@ -187,11 +190,14 @@ async def update_user(
detail="You don't have permission to update users" detail="You don't have permission to update users"
) )
# Buscar usuario # Buscar usuario - ADMIN global puede editar cualquier tenant
query = select(User).where( if current_user.role.value == "ADMIN":
User.id == user_id, query = select(User).where(User.id == user_id)
User.tenant_id == current_user.tenant_id else:
) query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query) result = await db.execute(query)
db_user = result.scalar_one_or_none() db_user = result.scalar_one_or_none()
@@ -294,11 +300,14 @@ async def delete_user(
detail="You cannot delete yourself" detail="You cannot delete yourself"
) )
# Buscar usuario # Buscar usuario - ADMIN global puede editar cualquier tenant
query = select(User).where( if current_user.role.value == "ADMIN":
User.id == user_id, query = select(User).where(User.id == user_id)
User.tenant_id == current_user.tenant_id else:
) query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query) result = await db.execute(query)
db_user = result.scalar_one_or_none() db_user = result.scalar_one_or_none()
@@ -371,11 +380,14 @@ async def activate_user(
detail="You don't have permission to activate users" detail="You don't have permission to activate users"
) )
# Buscar usuario # Buscar usuario - ADMIN global puede editar cualquier tenant
query = select(User).where( if current_user.role.value == "ADMIN":
User.id == user_id, query = select(User).where(User.id == user_id)
User.tenant_id == current_user.tenant_id else:
) query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query) result = await db.execute(query)
db_user = result.scalar_one_or_none() db_user = result.scalar_one_or_none()

104
backend/auth_backup.ts Normal file
View File

@@ -0,0 +1,104 @@
import type { Writable } from 'svelte/store';
import { writable } from 'svelte/store';
export interface User {
id: string;
email: string;
first_name: string;
last_name: string;
tenant_id: string;
role: 'CLIENT_ADMIN' | 'CLIENT_USER';
is_active: boolean;
is_two_factor_enabled: boolean;
created_at: string;
}
export interface AuthState {
user: User | null;
token: string | null;
isAuthenticated: boolean;
isLoading: boolean;
}
export interface LoginRequest {
email: string;
password: string;
tenant_slug: string;
totp_code?: string;
}
export interface LoginResponse {
access_token: string;
token_type: string;
expires_in: number;
user: User;
}
const initialState: AuthState = {
user: null,
token: null,
isAuthenticated: false,
isLoading: false
};
function createAuthStore() {
const { subscribe, set, update }: Writable<AuthState> = writable(initialState);
let _state = initialState;
subscribe(s => { _state = s; });
return {
subscribe,
init: async () => {
if (typeof window !== 'undefined') {
try {
const response = await fetch('/api/v1/auth/me', {
credentials: 'include',
headers: { 'X-App': 'client', 'X-Tenant-Slug': 'aduanasoft' }
});
if (response.ok) {
const user = await response.json();
set({ user, token: null, isAuthenticated: true, isLoading: false });
}
} catch (error) {}
}
},
login: async (credentials: LoginRequest): Promise<void> => {
update(state => ({ ...state, isLoading: true }));
try {
const response = await fetch('/api/v1/auth/login', {
method: 'POST',
credentials: 'include',
headers: {
'Content-Type': 'application/json',
'X-Tenant-Slug': credentials.tenant_slug,
},
body: JSON.stringify(credentials)
});
if (!response.ok) {
const error = await response.json();
throw new Error(error.detail || 'Login failed');
}
const data: LoginResponse = await response.json();
set({ user: data.user, token: data.access_token, isAuthenticated: true, isLoading: false });
} catch (error) {
update(state => ({ ...state, isLoading: false }));
throw error;
}
},
logout: async () => {
try {
const token = _state.token;
await fetch('/api/v1/auth/logout', {
method: 'POST',
credentials: 'include',
headers: {
'X-App': 'client',
'X-Tenant-Slug': 'aduanasoft',
...(token ? { 'Authorization': `Bearer ${token}` } : {})
}
});
} catch {}
set(initialState);
if (typeof window !== 'undefined') {
window.location.href = '/login';
}
},
updateUser: (user: User) => { update(state => ({ ...state, user })); },
setUser: (user: User) => { set({ user, token: null, isAuthenticated: true, isLoading: false }); },
setLoading: (isLoading: boolean) => { update(state => ({ ...state, isLoading })); }
};
}
export const auth = createAuthStore();

6
backend/check_lines.py Normal file
View File

@@ -0,0 +1,6 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
for i, line in enumerate(lines):
if "tenant_id == current_user.tenant_id" in line:
print(f"Linea {i+1}: {line.rstrip()}")

14
backend/check_user.py Normal file
View File

@@ -0,0 +1,14 @@
import asyncio
from app.core.database import AsyncSessionLocal
from app.models.user import User
from sqlalchemy import select
import uuid
async def check():
async with AsyncSessionLocal() as db:
result = await db.execute(select(User))
users = result.scalars().all()
for u in users:
print(f"ID: {u.id} | Email: {u.email} | Tenant: {u.tenant_id} | Rol: {u.role}")
asyncio.run(check())

16
backend/fix_response.py Normal file
View File

@@ -0,0 +1,16 @@
with open("/app/app/api/v1/endpoints/auth.py", "r") as f:
lines = f.readlines()
# Linea 286 (0-indexed 285): "tenant_id": str(user.tenant_id),
# Agregar tenant_slug despues de tenant_id
for i, line in enumerate(lines):
if '"tenant_id": str(user.tenant_id),' in line:
indent = " "
new_line = indent + '"tenant_slug": tenant.slug if tenant else str(user.tenant_id),\n'
lines.insert(i + 1, new_line)
print(f"OK: tenant_slug agregado en linea {i+2}")
break
with open("/app/app/api/v1/endpoints/auth.py", "w") as f:
f.writelines(lines)
print("Listo")

18
backend/fix_syntax.py Normal file
View File

@@ -0,0 +1,18 @@
with open("/app/app/api/v1/endpoints/users.py") as f:
lines = f.readlines()
new_block = [
" if current_user.role.value == 'ADMIN':\n",
" query = select(User).where(User.id == user_id)\n",
" else:\n",
" query = select(User).where(\n",
" User.id == user_id,\n",
" User.tenant_id == current_user.tenant_id\n",
" )\n",
]
lines[150:161] = new_block
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.writelines(lines)
print("Listo")

28
backend/fix_users.py Normal file
View File

@@ -0,0 +1,28 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
old1 = " User.tenant_id == current_user.tenant_id # " + "\u2705" + " Seguridad multi-tenant"
new1 = """ from app.models.user import UserRole as _UserRole
if current_user.role == _UserRole.ADMIN:
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)"""
if old1 in content:
content = content.replace(old1, new1)
print("OK bloque 1")
else:
print("SKIP bloque 1 - buscando alternativa")
old1b = " User.tenant_id == current_user.tenant_id\n )\n result = await db.execute(query)\n if not user:"
new1b = " User.tenant_id == current_user.tenant_id\n )\n result = await db.execute(query)\n if not user:"
print("Lineas con tenant_id encontradas:")
for i, line in enumerate(content.split("\n")):
if "tenant_id == current_user.tenant_id" in line:
print(f" Linea {i}: {line}")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print("Listo")

60
backend/fix_users2.py Normal file
View File

@@ -0,0 +1,60 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
from app.models.user import UserRole as _UserRole
# Reemplazar el patron comun de query con filtro de tenant
# por una version que permite a ADMIN ver todos los tenants
old_get_user = """ query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
user = result.scalar_one_or_none()
if not user:"""
new_get_user = """ if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
user = result.scalar_one_or_none()
if not user:"""
old_update_user = """ query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
new_update_user = """ if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
count = 0
for old, new in [(old_get_user, new_get_user), (old_update_user, new_update_user)]:
occurrences = content.count(old)
if occurrences > 0:
content = content.replace(old, new)
count += occurrences
print(f"OK: {occurrences} ocurrencia(s) reemplazada(s)")
else:
print(f"SKIP: bloque no encontrado")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print(f"Total: {count} reemplazos aplicados")

36
backend/fix_users3.py Normal file
View File

@@ -0,0 +1,36 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
old1 = """ # Buscar usuario
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
new1 = """ # Buscar usuario - ADMIN global puede editar cualquier tenant
if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
count = content.count(old1)
if count > 0:
content = content.replace(old1, new1)
print(f"OK: {count} bloques reemplazados")
else:
print("ERROR: bloque no encontrado")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print("Listo")

38
backend/fix_users4.py Normal file
View File

@@ -0,0 +1,38 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
admin_check = [
" # Buscar usuario - ADMIN global puede editar cualquier tenant\n",
" if current_user.role.value == \"ADMIN\":\n",
" query = select(User).where(User.id == user_id)\n",
" else:\n",
" query = select(User).where(\n",
" User.id == user_id,\n",
" User.tenant_id == current_user.tenant_id\n",
" )\n",
]
# Reemplazar bloques en lineas 198, 305, 382 (0-indexed: 197, 304, 381)
replaced = 0
new_lines = lines[:]
i = 0
while i < len(new_lines):
if (new_lines[i].strip() == "# Buscar usuario" and
i+1 < len(new_lines) and "select(User).where(" in new_lines[i+1] and
i+2 < len(new_lines) and "User.id == user_id," in new_lines[i+2] and
i+3 < len(new_lines) and "User.tenant_id == current_user.tenant_id" in new_lines[i+3]):
indent = " "
new_block = admin_check[:]
# Remove old 4 lines of query block (comment + query 4 lines)
new_lines[i:i+5] = new_block
replaced += 1
i += len(new_block)
else:
i += 1
print(f"Reemplazos realizados: {replaced}")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.writelines(new_lines)
print("Listo")

11
backend/show_context.py Normal file
View File

@@ -0,0 +1,11 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
# Mostrar contexto alrededor de lineas con tenant_id
targets = [51, 92, 159, 200, 307, 384]
for t in targets:
print(f"\n=== Linea {t} ===")
start = max(0, t-5)
end = min(len(lines), t+5)
for i in range(start, end):
print(f"{i+1}: {lines[i].rstrip()}")

6
check_lines.py Normal file
View File

@@ -0,0 +1,6 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
for i, line in enumerate(lines):
if "tenant_id == current_user.tenant_id" in line:
print(f"Linea {i+1}: {line.rstrip()}")

14
check_user.py Normal file
View File

@@ -0,0 +1,14 @@
import asyncio
from app.core.database import AsyncSessionLocal
from app.models.user import User
from sqlalchemy import select
import uuid
async def check():
async with AsyncSessionLocal() as db:
result = await db.execute(select(User))
users = result.scalars().all()
for u in users:
print(f"ID: {u.id} | Email: {u.email} | Tenant: {u.tenant_id} | Rol: {u.role}")
asyncio.run(check())

16
fix_response.py Normal file
View File

@@ -0,0 +1,16 @@
with open("/app/app/api/v1/endpoints/auth.py", "r") as f:
lines = f.readlines()
# Linea 286 (0-indexed 285): "tenant_id": str(user.tenant_id),
# Agregar tenant_slug despues de tenant_id
for i, line in enumerate(lines):
if '"tenant_id": str(user.tenant_id),' in line:
indent = " "
new_line = indent + '"tenant_slug": tenant.slug if tenant else str(user.tenant_id),\n'
lines.insert(i + 1, new_line)
print(f"OK: tenant_slug agregado en linea {i+2}")
break
with open("/app/app/api/v1/endpoints/auth.py", "w") as f:
f.writelines(lines)
print("Listo")

18
fix_syntax.py Normal file
View File

@@ -0,0 +1,18 @@
with open("/app/app/api/v1/endpoints/users.py") as f:
lines = f.readlines()
new_block = [
" if current_user.role.value == 'ADMIN':\n",
" query = select(User).where(User.id == user_id)\n",
" else:\n",
" query = select(User).where(\n",
" User.id == user_id,\n",
" User.tenant_id == current_user.tenant_id\n",
" )\n",
]
lines[150:161] = new_block
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.writelines(lines)
print("Listo")

28
fix_users.py Normal file
View File

@@ -0,0 +1,28 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
old1 = " User.tenant_id == current_user.tenant_id # " + "\u2705" + " Seguridad multi-tenant"
new1 = """ from app.models.user import UserRole as _UserRole
if current_user.role == _UserRole.ADMIN:
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)"""
if old1 in content:
content = content.replace(old1, new1)
print("OK bloque 1")
else:
print("SKIP bloque 1 - buscando alternativa")
old1b = " User.tenant_id == current_user.tenant_id\n )\n result = await db.execute(query)\n if not user:"
new1b = " User.tenant_id == current_user.tenant_id\n )\n result = await db.execute(query)\n if not user:"
print("Lineas con tenant_id encontradas:")
for i, line in enumerate(content.split("\n")):
if "tenant_id == current_user.tenant_id" in line:
print(f" Linea {i}: {line}")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print("Listo")

60
fix_users2.py Normal file
View File

@@ -0,0 +1,60 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
from app.models.user import UserRole as _UserRole
# Reemplazar el patron comun de query con filtro de tenant
# por una version que permite a ADMIN ver todos los tenants
old_get_user = """ query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
user = result.scalar_one_or_none()
if not user:"""
new_get_user = """ if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
user = result.scalar_one_or_none()
if not user:"""
old_update_user = """ query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
new_update_user = """ if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
count = 0
for old, new in [(old_get_user, new_get_user), (old_update_user, new_update_user)]:
occurrences = content.count(old)
if occurrences > 0:
content = content.replace(old, new)
count += occurrences
print(f"OK: {occurrences} ocurrencia(s) reemplazada(s)")
else:
print(f"SKIP: bloque no encontrado")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print(f"Total: {count} reemplazos aplicados")

36
fix_users3.py Normal file
View File

@@ -0,0 +1,36 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
content = f.read()
old1 = """ # Buscar usuario
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
new1 = """ # Buscar usuario - ADMIN global puede editar cualquier tenant
if current_user.role.value == "ADMIN":
query = select(User).where(User.id == user_id)
else:
query = select(User).where(
User.id == user_id,
User.tenant_id == current_user.tenant_id
)
result = await db.execute(query)
db_user = result.scalar_one_or_none()
if not db_user:"""
count = content.count(old1)
if count > 0:
content = content.replace(old1, new1)
print(f"OK: {count} bloques reemplazados")
else:
print("ERROR: bloque no encontrado")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.write(content)
print("Listo")

38
fix_users4.py Normal file
View File

@@ -0,0 +1,38 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
admin_check = [
" # Buscar usuario - ADMIN global puede editar cualquier tenant\n",
" if current_user.role.value == \"ADMIN\":\n",
" query = select(User).where(User.id == user_id)\n",
" else:\n",
" query = select(User).where(\n",
" User.id == user_id,\n",
" User.tenant_id == current_user.tenant_id\n",
" )\n",
]
# Reemplazar bloques en lineas 198, 305, 382 (0-indexed: 197, 304, 381)
replaced = 0
new_lines = lines[:]
i = 0
while i < len(new_lines):
if (new_lines[i].strip() == "# Buscar usuario" and
i+1 < len(new_lines) and "select(User).where(" in new_lines[i+1] and
i+2 < len(new_lines) and "User.id == user_id," in new_lines[i+2] and
i+3 < len(new_lines) and "User.tenant_id == current_user.tenant_id" in new_lines[i+3]):
indent = " "
new_block = admin_check[:]
# Remove old 4 lines of query block (comment + query 4 lines)
new_lines[i:i+5] = new_block
replaced += 1
i += len(new_block)
else:
i += 1
print(f"Reemplazos realizados: {replaced}")
with open("/app/app/api/v1/endpoints/users.py", "w") as f:
f.writelines(new_lines)
print("Listo")

View File

@@ -0,0 +1,104 @@
import type { Writable } from 'svelte/store';
import { writable } from 'svelte/store';
export interface User {
id: string;
email: string;
first_name: string;
last_name: string;
tenant_id: string;
role: 'CLIENT_ADMIN' | 'CLIENT_USER';
is_active: boolean;
is_two_factor_enabled: boolean;
created_at: string;
}
export interface AuthState {
user: User | null;
token: string | null;
isAuthenticated: boolean;
isLoading: boolean;
}
export interface LoginRequest {
email: string;
password: string;
tenant_slug: string;
totp_code?: string;
}
export interface LoginResponse {
access_token: string;
token_type: string;
expires_in: number;
user: User;
}
const initialState: AuthState = {
user: null,
token: null,
isAuthenticated: false,
isLoading: false
};
function createAuthStore() {
const { subscribe, set, update }: Writable<AuthState> = writable(initialState);
let _state = initialState;
subscribe(s => { _state = s; });
return {
subscribe,
init: async () => {
if (typeof window !== 'undefined') {
try {
const response = await fetch('/api/v1/auth/me', {
credentials: 'include',
headers: { 'X-App': 'client', 'X-Tenant-Slug': 'aduanasoft' }
});
if (response.ok) {
const user = await response.json();
set({ user, token: null, isAuthenticated: true, isLoading: false });
}
} catch (error) {}
}
},
login: async (credentials: LoginRequest): Promise<void> => {
update(state => ({ ...state, isLoading: true }));
try {
const response = await fetch('/api/v1/auth/login', {
method: 'POST',
credentials: 'include',
headers: {
'Content-Type': 'application/json',
'X-Tenant-Slug': credentials.tenant_slug,
},
body: JSON.stringify(credentials)
});
if (!response.ok) {
const error = await response.json();
throw new Error(error.detail || 'Login failed');
}
const data: LoginResponse = await response.json();
set({ user: data.user, token: data.access_token, isAuthenticated: true, isLoading: false });
} catch (error) {
update(state => ({ ...state, isLoading: false }));
throw error;
}
},
logout: async () => {
try {
const token = _state.token;
await fetch('/api/v1/auth/logout', {
method: 'POST',
credentials: 'include',
headers: {
'X-App': 'client',
'X-Tenant-Slug': 'aduanasoft',
...(token ? { 'Authorization': `Bearer ${token}` } : {})
}
});
} catch {}
set(initialState);
if (typeof window !== 'undefined') {
window.location.href = '/login';
}
},
updateUser: (user: User) => { update(state => ({ ...state, user })); },
setUser: (user: User) => { set({ user, token: null, isAuthenticated: true, isLoading: false }); },
setLoading: (isLoading: boolean) => { update(state => ({ ...state, isLoading })); }
};
}
export const auth = createAuthStore();

View File

@@ -2,8 +2,6 @@ import { auth } from '$lib/stores/auth';
import { get } from 'svelte/store'; import { get } from 'svelte/store';
const API_BASE = '/api/v1'; const API_BASE = '/api/v1';
const TENANT_SLUG = 'aduanasoft';
interface RequestOptions extends RequestInit { interface RequestOptions extends RequestInit {
params?: Record<string, string>; params?: Record<string, string>;
} }
@@ -34,7 +32,8 @@ async function request<T>(endpoint: string, options: RequestOptions = {}): Promi
headers.set('Content-Type', 'application/json'); headers.set('Content-Type', 'application/json');
} }
headers.set('X-App', 'client'); headers.set('X-App', 'client');
headers.set('X-Tenant-Slug', TENANT_SLUG); const slug = get(authStore)?.user?.tenant_slug || get(authStore)?.user?.tenant_id || '';
headers.set('X-Tenant-Slug', slug);
const response = await fetch(url, { const response = await fetch(url, {
...init, ...init,
@@ -72,7 +71,8 @@ async function downloadFile(endpoint: string, filename: string): Promise<void> {
headers.set('X-Tenant-ID', authState.user.tenant_id); headers.set('X-Tenant-ID', authState.user.tenant_id);
} }
headers.set('X-App', 'client'); headers.set('X-App', 'client');
headers.set('X-Tenant-Slug', TENANT_SLUG); const slug = get(authStore)?.user?.tenant_slug || get(authStore)?.user?.tenant_id || '';
headers.set('X-Tenant-Slug', slug);
const response = await fetch(`${API_BASE}${endpoint}`, { const response = await fetch(`${API_BASE}${endpoint}`, {
method: 'GET', method: 'GET',

View File

@@ -7,7 +7,7 @@
let email = ''; let email = '';
let password = ''; let password = '';
let tenantSlug = 'aduanasoft-demo'; let tenantSlug = 'ventas';
let totpCode = ''; let totpCode = '';
let isLoading = false; let isLoading = false;
let showTwoFactor = false; let showTwoFactor = false;
@@ -34,11 +34,11 @@
await auth.login({ await auth.login({
email, email,
password, password,
tenant_slug: tenantSlug.trim() || 'aduanasoft-demo', tenant_slug: tenantSlug.trim() || 'ventas',
totp_code: totpCode || undefined totp_code: totpCode || undefined
}); });
toast.success('¡Bienvenido! Has iniciado sesión correctamente'); toast.success('¡Bienvenido! Has iniciado sesión correctamente');
goto('/'); goto('/');
} catch (error: any) { } catch (error: any) {
console.error('Login error:', error); console.error('Login error:', error);
@@ -46,9 +46,9 @@
// Check if 2FA is required // Check if 2FA is required
if (error.message.includes('two-factor') || error.message.includes('2FA')) { if (error.message.includes('two-factor') || error.message.includes('2FA')) {
showTwoFactor = true; showTwoFactor = true;
errorMessage = 'Introduce el código de tu aplicación de autenticación'; errorMessage = 'Introduce el código de tu aplicación de autenticación';
} else { } else {
errorMessage = error.message || 'Error al iniciar sesión'; errorMessage = error.message || 'Error al iniciar sesión';
toast.error(errorMessage); toast.error(errorMessage);
} }
} finally { } finally {
@@ -96,8 +96,8 @@
de Servicios de TI de Servicios de TI
</h2> </h2>
<p class="text-lg text-blue-100/90 font-light max-w-lg leading-relaxed drop-shadow-md"> <p class="text-lg text-blue-100/90 font-light max-w-lg leading-relaxed drop-shadow-md">
Portal de atención a clientes. Genere tickets de soporte técnico para nuestros sistemas y Portal de atención a clientes. Genere tickets de soporte técnico para nuestros sistemas y
reciba asistencia especializada para garantizar la continuidad de su operación. reciba asistencia especializada para garantizar la continuidad de su operación.
</p> </p>
</div> </div>
@@ -135,7 +135,7 @@
<!-- Email Input --> <!-- Email Input -->
<div class="space-y-1.5"> <div class="space-y-1.5">
<label for="email" class="block text-sm font-semibold text-gray-700" <label for="email" class="block text-sm font-semibold text-gray-700"
>Correo Electrónico</label >Correo Electrónico</label
> >
<div class="relative group"> <div class="relative group">
<div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none"> <div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none">
@@ -160,7 +160,7 @@
<!-- Password Input --> <!-- Password Input -->
<div class="space-y-1.5"> <div class="space-y-1.5">
<label for="password" class="block text-sm font-semibold text-gray-700" <label for="password" class="block text-sm font-semibold text-gray-700"
>Contraseña</label >Contraseña</label
> >
<div class="relative group"> <div class="relative group">
<div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none"> <div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none">
@@ -176,7 +176,7 @@
bind:value={password} bind:value={password}
on:keydown={handleKeyDown} on:keydown={handleKeyDown}
class="block w-full pl-10 pr-10 py-3 bg-[#fff9c4]/0 hover:bg-gray-50 focus:bg-white border text-gray-900 border-gray-300 rounded-lg focus:ring-2 focus:ring-blue-600 focus:border-transparent transition-all duration-200 sm:text-sm" class="block w-full pl-10 pr-10 py-3 bg-[#fff9c4]/0 hover:bg-gray-50 focus:bg-white border text-gray-900 border-gray-300 rounded-lg focus:ring-2 focus:ring-blue-600 focus:border-transparent transition-all duration-200 sm:text-sm"
placeholder="••••••••" placeholder="••••••••"
required required
disabled={isLoading} disabled={isLoading}
/> />
@@ -187,7 +187,7 @@
bind:value={password} bind:value={password}
on:keydown={handleKeyDown} on:keydown={handleKeyDown}
class="block w-full pl-10 pr-10 py-3 bg-[#fff9c4]/0 hover:bg-gray-50 focus:bg-white border text-gray-900 border-gray-300 rounded-lg focus:ring-2 focus:ring-blue-600 focus:border-transparent transition-all duration-200 sm:text-sm" class="block w-full pl-10 pr-10 py-3 bg-[#fff9c4]/0 hover:bg-gray-50 focus:bg-white border text-gray-900 border-gray-300 rounded-lg focus:ring-2 focus:ring-blue-600 focus:border-transparent transition-all duration-200 sm:text-sm"
placeholder="••••••••" placeholder="••••••••"
required required
disabled={isLoading} disabled={isLoading}
/> />
@@ -221,7 +221,7 @@
class="text-sm font-medium text-blue-600 hover:text-blue-500 bg-transparent border-none p-0 cursor-pointer" class="text-sm font-medium text-blue-600 hover:text-blue-500 bg-transparent border-none p-0 cursor-pointer"
on:click={() => goto('/forgot-password')} on:click={() => goto('/forgot-password')}
> >
Olvidé mi clave Olvidé mi clave
</button> </button>
</div> </div>
</div> </div>
@@ -229,9 +229,9 @@
<!-- 2FA Input --> <!-- 2FA Input -->
<div class="space-y-4 animate-slide-up"> <div class="space-y-4 animate-slide-up">
<label for="code" class="block text-sm font-medium text-gray-700 text-center" <label for="code" class="block text-sm font-medium text-gray-700 text-center"
>Código de Verificación (2FA)</label >Código de Verificación (2FA)</label
> >
<p class="text-xs text-center text-gray-500 mb-4">Ingrese el código de 6 dígitos</p> <p class="text-xs text-center text-gray-500 mb-4">Ingrese el código de 6 dígitos</p>
<div class="relative"> <div class="relative">
<div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none"> <div class="absolute inset-y-0 left-0 pl-3 flex items-center pointer-events-none">
@@ -268,7 +268,7 @@
</div> </div>
<div class="mt-8 text-center text-xs text-gray-400"> <div class="mt-8 text-center text-xs text-gray-400">
© 2026 Aduanasoft. Acceso exclusivo autorizado. © 2026 Aduanasoft. Acceso exclusivo autorizado.
</div> </div>
</form> </form>
</div> </div>

View File

@@ -1,23 +1,22 @@
import { writable } from 'svelte/store';
import type { Writable } from 'svelte/store'; import type { Writable } from 'svelte/store';
import { writable } from 'svelte/store';
// Types export interface User {
export interface InternalUser {
id: string; id: string;
email: string; email: string;
first_name: string; first_name: string;
last_name: string; last_name: string;
role: 'ADMIN' | 'SUPPORT_MANAGER' | 'AGENT' | 'AUDITOR'; tenant_id: string;
tenant_slug: string;
role: 'CLIENT_ADMIN' | 'CLIENT_USER';
is_active: boolean; is_active: boolean;
is_two_factor_enabled: boolean; is_two_factor_enabled: boolean;
created_at: string; created_at: string;
tenant_id: string;
} }
export interface AuthState { export interface AuthState {
user: InternalUser | null; user: User | null;
token: string | null; token: string | null;
refreshToken: string | null;
isAuthenticated: boolean; isAuthenticated: boolean;
isLoading: boolean; isLoading: boolean;
} }
@@ -25,181 +24,90 @@ export interface AuthState {
export interface LoginRequest { export interface LoginRequest {
email: string; email: string;
password: string; password: string;
tenant_slug: string; tenant_slug?: string;
totp_code?: string; totp_code?: string;
} }
export interface LoginResponse { export interface LoginResponse {
access_token: string; access_token: string;
refresh_token: string;
token_type: string; token_type: string;
expires_in: number; expires_in: number;
user: InternalUser; user: User;
} }
export interface RefreshTokenRequest {
refresh_token: string;
}
export interface TokenResponse {
access_token: string;
token_type: string;
expires_in: number;
}
// Initial state
const initialState: AuthState = { const initialState: AuthState = {
user: null, user: null,
token: null, token: null,
refreshToken: null,
isAuthenticated: false, isAuthenticated: false,
isLoading: false isLoading: false
}; };
// Create auth store
function createAuthStore() { function createAuthStore() {
const { subscribe, set, update } = writable<AuthState>(initialState); const { subscribe, set, update }: Writable<AuthState> = writable(initialState);
// Track current state for uso interno (evita dependencias circulares)
let _state = initialState; let _state = initialState;
subscribe(s => { _state = s; }); subscribe(s => { _state = s; });
return { return {
subscribe, subscribe,
// Rehidrata sesión desde cookie HttpOnly (no toca localStorage)
init: async () => { init: async () => {
if (typeof window !== 'undefined') { if (typeof window !== 'undefined') {
try { try {
const response = await fetch('/api/v1/auth/me', { const response = await fetch('/api/v1/auth/me', {
credentials: 'include', credentials: 'include',
headers: { 'X-App': 'internal' } headers: { 'X-App': 'client' }
}); });
if (response.ok) { if (response.ok) {
const user = await response.json(); const user = await response.json();
set({ set({ user, token: null, isAuthenticated: true, isLoading: false });
user,
token: null,
refreshToken: null,
isAuthenticated: true,
isLoading: false
});
} }
// 401/400 es esperado cuando no hay sesión activa — no es un error } catch (error) {}
} catch (error) {
// Ignorar errores de red en init
}
} }
}, },
// Login
login: async (credentials: LoginRequest): Promise<void> => { login: async (credentials: LoginRequest): Promise<void> => {
update(state => ({ ...state, isLoading: true })); update(state => ({ ...state, isLoading: true }));
try { try {
const response = await fetch('/api/v1/auth/login', { const response = await fetch('/api/v1/auth/login', {
method: 'POST', method: 'POST',
credentials: 'include', credentials: 'include',
headers: { headers: {
'Content-Type': 'application/json', 'Content-Type': 'application/json',
'X-Tenant-Slug': credentials.tenant_slug, 'X-App': 'client',
}, },
body: JSON.stringify(credentials) body: JSON.stringify(credentials)
}); });
if (!response.ok) { if (!response.ok) {
const error = await response.json(); const error = await response.json();
throw new Error(error.detail || 'Login failed'); throw new Error(error.detail || 'Login failed');
} }
const data: LoginResponse = await response.json(); const data: LoginResponse = await response.json();
set({ user: data.user, token: data.access_token, isAuthenticated: true, isLoading: false });
set({
user: data.user,
token: data.access_token,
refreshToken: data.refresh_token,
isAuthenticated: true,
isLoading: false
});
} catch (error) { } catch (error) {
update(state => ({ ...state, isLoading: false })); update(state => ({ ...state, isLoading: false }));
throw error; throw error;
} }
}, },
// Refresh Session
refreshSession: async (): Promise<void> => {
const currentRefreshToken = _state.refreshToken;
if (!currentRefreshToken) {
throw new Error("No refresh token available");
}
update(state => ({ ...state, isLoading: true }));
try {
const response = await fetch('/api/v1/auth/refresh', {
method: 'POST',
credentials: 'include',
headers: {
'Content-Type': 'application/json',
},
body: JSON.stringify({ refresh_token: currentRefreshToken })
});
if (!response.ok) {
// If refresh fails, logout
if (response.status === 401 || response.status === 403) {
auth.logout();
}
const error = await response.json();
throw new Error(error.detail || 'Refresh failed');
}
const data: TokenResponse = await response.json();
update(state => ({
...state,
token: data.access_token,
isLoading: false
}));
} catch (error) {
update(state => ({ ...state, isLoading: false }));
throw error;
}
},
// Logout
logout: async () => { logout: async () => {
// Llamar al backend para que borre la cookie HttpOnly
try { try {
const token = _state.token;
const slug = _state.user?.tenant_slug || _state.user?.tenant_id || '';
await fetch('/api/v1/auth/logout', { await fetch('/api/v1/auth/logout', {
method: 'POST', method: 'POST',
credentials: 'include', credentials: 'include',
headers: { 'X-App': 'internal' } headers: {
'X-App': 'client',
'X-Tenant-Slug': slug,
...(token ? { 'Authorization': `Bearer ${token}` } : {})
}
}); });
} catch { /* ignorar errores de red */ } } catch {}
set(initialState); set(initialState);
if (typeof window !== 'undefined') { if (typeof window !== 'undefined') {
window.location.href = '/login'; window.location.href = '/login';
} }
}, },
updateUser: (user: User) => { update(state => ({ ...state, user })); },
// Update user data setUser: (user: User) => { set({ user, token: null, isAuthenticated: true, isLoading: false }); },
updateUser: (user: InternalUser) => { setLoading: (isLoading: boolean) => { update(state => ({ ...state, isLoading })); }
update(state => ({ ...state, user }));
},
// Set user from SSR pre-load (no fetch required)
setUser: (user: InternalUser) => {
set({ user, token: null, refreshToken: null, isAuthenticated: true, isLoading: false });
},
// Set loading state
setLoading: (isLoading: boolean) => {
update(state => ({ ...state, isLoading }));
}
}; };
} }

11
show_context.py Normal file
View File

@@ -0,0 +1,11 @@
with open("/app/app/api/v1/endpoints/users.py", "r") as f:
lines = f.readlines()
# Mostrar contexto alrededor de lineas con tenant_id
targets = [51, 92, 159, 200, 307, 384]
for t in targets:
print(f"\n=== Linea {t} ===")
start = max(0, t-5)
end = min(len(lines), t+5)
for i in range(start, end):
print(f"{i+1}: {lines[i].rstrip()}")