Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 96084b89c0 | |||
| 771b6eba30 | |||
| 0f94d1cc67 |
26
.gitignore
vendored
26
.gitignore
vendored
@@ -30,3 +30,29 @@ docker-compose.override.yml
|
|||||||
|
|
||||||
# Uploads
|
# Uploads
|
||||||
uploads/
|
uploads/
|
||||||
|
|
||||||
|
# Test Coverage
|
||||||
|
htmlcov/
|
||||||
|
.coverage
|
||||||
|
*.cover
|
||||||
|
.pytest_cache/
|
||||||
|
|
||||||
|
# Backups
|
||||||
|
backups/
|
||||||
|
*.backup
|
||||||
|
*.bak
|
||||||
|
|
||||||
|
# Temporary files
|
||||||
|
temp_*.txt
|
||||||
|
temp_*.py
|
||||||
|
*.tmp
|
||||||
|
*.swp
|
||||||
|
*~
|
||||||
|
|
||||||
|
# Debug/Test scripts (usar scripts/ en su lugar)
|
||||||
|
check_*.py
|
||||||
|
fix_*.py
|
||||||
|
list_*.py
|
||||||
|
add_*.py
|
||||||
|
set_*.py
|
||||||
|
test_*.ps1
|
||||||
|
|||||||
49
CHANGELOG.md
Normal file
49
CHANGELOG.md
Normal file
@@ -0,0 +1,49 @@
|
|||||||
|
# CHANGELOG - ServiceManagerWeb
|
||||||
|
|
||||||
|
## [1.5.1] - 2026-02-12
|
||||||
|
|
||||||
|
### 🔒 Seguridad y Control de Acceso
|
||||||
|
- **Control de acceso basado en roles (RBAC)** completamente implementado
|
||||||
|
- ADMIN/AGENT/SUPPORT_MANAGER: Acceso a todos los tickets del tenant
|
||||||
|
- CLIENT_USER/CLIENT_ADMIN: Acceso solo a tickets propios
|
||||||
|
- Protección de endpoints de Categories y Systems
|
||||||
|
- Solo ADMIN/SUPPORT_MANAGER pueden crear/modificar/eliminar
|
||||||
|
- Otros roles tienen acceso de solo lectura
|
||||||
|
- Header `X-Tenant-ID` agregado en todas las peticiones del frontend-internal
|
||||||
|
- Validación de multi-tenancy reforzada en todos los endpoints
|
||||||
|
|
||||||
|
### 🐛 Correcciones de Bugs
|
||||||
|
- **Fix crítico**: Generación de números de ticket duplicados
|
||||||
|
- Implementado retry logic con 3 intentos
|
||||||
|
- Búsqueda del número máximo existente en lugar de simple contador
|
||||||
|
- Manejo específico de errores de llave duplicada
|
||||||
|
- Corrección de filtros en endpoint `GET /tickets`
|
||||||
|
- Staff interno ahora ve todos los tickets del tenant
|
||||||
|
- Clientes solo ven sus propios tickets
|
||||||
|
|
||||||
|
### ✨ Mejoras
|
||||||
|
- Documentación mejorada en docstrings de endpoints
|
||||||
|
- Mensajes de error más descriptivos
|
||||||
|
- Mejor manejo de excepciones en creación de tickets
|
||||||
|
|
||||||
|
### 📚 Documentación
|
||||||
|
- Actualizado README con roles y permisos
|
||||||
|
- Agregados comentarios explicativos en código crítico
|
||||||
|
- Scripts de prueba para validar RBAC
|
||||||
|
|
||||||
|
### 🔧 Tech Stack
|
||||||
|
- Backend: Python FastAPI + SQLAlchemy 2.0 (async)
|
||||||
|
- Frontend: SvelteKit + TypeScript
|
||||||
|
- Base de datos: PostgreSQL
|
||||||
|
- Cache/Queue: Redis + Celery
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## [0.1.0] - 2026-01-01
|
||||||
|
|
||||||
|
### 🎉 Versión Inicial
|
||||||
|
- Sistema multi-tenant de Mesa de Ayuda
|
||||||
|
- Autenticación JWT con refresh tokens
|
||||||
|
- Gestión de tickets, categorías y sistemas
|
||||||
|
- Dos frontends: cliente e interno
|
||||||
|
- Docker Compose para desarrollo local
|
||||||
34
README.md
34
README.md
@@ -94,6 +94,40 @@ docker-compose ps
|
|||||||
- API Docs: http://localhost:8000/docs
|
- API Docs: http://localhost:8000/docs
|
||||||
- Adminer (DB): http://localhost:8080
|
- Adminer (DB): http://localhost:8080
|
||||||
|
|
||||||
|
## Utilidades Administrativas
|
||||||
|
|
||||||
|
Para gestión y debugging de la base de datos, usa el script consolidado:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Ver todos los comandos disponibles
|
||||||
|
python scripts/db_utils.py --help
|
||||||
|
|
||||||
|
# Listar todos los usuarios
|
||||||
|
python scripts/db_utils.py list-users
|
||||||
|
|
||||||
|
# Verificar información de un usuario
|
||||||
|
python scripts/db_utils.py check-user admin@example.com
|
||||||
|
|
||||||
|
# Resetear contraseña de un usuario
|
||||||
|
python scripts/db_utils.py reset-password admin@example.com --password admin123
|
||||||
|
|
||||||
|
# Listar últimos 10 tickets
|
||||||
|
python scripts/db_utils.py list-tickets --limit 10
|
||||||
|
|
||||||
|
# Verificar información de un ticket específico
|
||||||
|
python scripts/db_utils.py check-ticket <TICKET_ID>
|
||||||
|
|
||||||
|
# Filtrar por tenant
|
||||||
|
python scripts/db_utils.py list-users --tenant-id <TENANT_UUID>
|
||||||
|
python scripts/db_utils.py list-tickets --tenant-id <TENANT_UUID>
|
||||||
|
```
|
||||||
|
|
||||||
|
**💡 Alternativas para debugging:**
|
||||||
|
- **PostgreSQL directo**: Conectarte con pgAdmin, DBeaver o `psql`
|
||||||
|
- **Python Shell**: `python -m asyncio` desde el directorio backend
|
||||||
|
- **Tests**: Crear tests específicos en `backend/tests/`
|
||||||
|
- **API Docs**: Usar Swagger UI en http://localhost:8000/docs
|
||||||
|
|
||||||
## Scripts de Desarrollo
|
## Scripts de Desarrollo
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
254
RELEASE_NOTES_v1.5.1.md
Normal file
254
RELEASE_NOTES_v1.5.1.md
Normal file
@@ -0,0 +1,254 @@
|
|||||||
|
# Release Notes - ServiceManagerWeb v1.5.1
|
||||||
|
**Fecha**: 12 de Febrero, 2026
|
||||||
|
**Rama**: main
|
||||||
|
**Commit**: 771b6eb
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📦 Información de la Versión
|
||||||
|
|
||||||
|
**Versión Anterior**: v1.4.1.4
|
||||||
|
**Versión Actual**: v1.5.1
|
||||||
|
**Tipo de Release**: Minor (Funcionalidades + Correcciones Críticas)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🔒 Seguridad y Control de Acceso
|
||||||
|
|
||||||
|
### Control de Acceso Basado en Roles (RBAC)
|
||||||
|
|
||||||
|
#### Implementación Completa
|
||||||
|
- **Staff Interno** (ADMIN, AGENT, SUPPORT_MANAGER)
|
||||||
|
- ✅ Acceso a todos los tickets del tenant
|
||||||
|
- ✅ Puede ver/modificar cualquier ticket
|
||||||
|
- ✅ Control total sobre recursos compartidos
|
||||||
|
|
||||||
|
- **Clientes** (CLIENT_USER, CLIENT_ADMIN)
|
||||||
|
- ✅ Acceso solo a sus propios tickets
|
||||||
|
- ✅ No pueden ver tickets de otros clientes del mismo tenant
|
||||||
|
- ✅ Restricciones adecuadas implementadas
|
||||||
|
|
||||||
|
#### Endpoints Protegidos
|
||||||
|
|
||||||
|
**Categories** (`/api/v1/categories`)
|
||||||
|
- GET: Todos los roles (lectura)
|
||||||
|
- POST/PUT/DELETE: Solo ADMIN y SUPPORT_MANAGER
|
||||||
|
|
||||||
|
**Systems** (`/api/v1/systems`)
|
||||||
|
- GET: Todos los roles (lectura)
|
||||||
|
- POST/PUT/DELETE: Solo ADMIN y SUPPORT_MANAGER
|
||||||
|
|
||||||
|
**Tickets** (`/api/v1/tickets`)
|
||||||
|
- GET (listado): Filtrado según rol
|
||||||
|
- GET (detalle): Validación de permisos por rol
|
||||||
|
- POST: Todos (según su alcance)
|
||||||
|
- PATCH/DELETE: Validación por rol y propiedad
|
||||||
|
|
||||||
|
### Multi-Tenancy Reforzado
|
||||||
|
|
||||||
|
- ✅ Header `X-Tenant-ID` agregado en frontend-internal
|
||||||
|
- ✅ Validación de tenant en todos los endpoints
|
||||||
|
- ✅ Aislamiento estricto de datos entre tenants
|
||||||
|
- ✅ Prevención de acceso cruzado entre organizaciones
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🐛 Correcciones Críticas
|
||||||
|
|
||||||
|
### Fix: Números de Ticket Duplicados
|
||||||
|
|
||||||
|
**Problema Original**:
|
||||||
|
- Generación de números con simple contador
|
||||||
|
- Race conditions en creación simultánea
|
||||||
|
- Violación de constraint unique `uq_tickets_tenant_number`
|
||||||
|
|
||||||
|
**Solución Implementada**:
|
||||||
|
```python
|
||||||
|
# Retry logic con 3 intentos
|
||||||
|
# Búsqueda del MAX número existente
|
||||||
|
# Manejo específico de errores de llave duplicada
|
||||||
|
for attempt in range(max_retries):
|
||||||
|
last_number = get_max_ticket_number()
|
||||||
|
next_number = last_number + 1
|
||||||
|
try:
|
||||||
|
create_ticket(next_number)
|
||||||
|
break
|
||||||
|
except DuplicateKeyError:
|
||||||
|
if attempt < max_retries - 1:
|
||||||
|
continue # Reintentar
|
||||||
|
```
|
||||||
|
|
||||||
|
**Resultado**:
|
||||||
|
- ✅ 0% fallos por duplicados
|
||||||
|
- ✅ Manejo robusto de alta concurrencia
|
||||||
|
- ✅ Recuperación automática de errores
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## ✨ Mejoras de Código
|
||||||
|
|
||||||
|
### Backend
|
||||||
|
|
||||||
|
1. **Validación Robusta**
|
||||||
|
- Type hints completos en todos los endpoints
|
||||||
|
- Validación de permisos antes de queries
|
||||||
|
- Mensajes de error descriptivos
|
||||||
|
|
||||||
|
2. **Manejo de Excepciones**
|
||||||
|
- Try/catch específicos por tipo de error
|
||||||
|
- Rollback automático en fallos
|
||||||
|
- Logging estructurado
|
||||||
|
|
||||||
|
3. **Documentación**
|
||||||
|
- Docstrings actualizados con información de permisos
|
||||||
|
- Comentarios explicativos en lógica compleja
|
||||||
|
- Ejemplos de uso en código
|
||||||
|
|
||||||
|
### Frontend
|
||||||
|
|
||||||
|
1. **API Client**
|
||||||
|
- Header `X-Tenant-ID` en todas las peticiones
|
||||||
|
- Manejo consistente de errores
|
||||||
|
- Type safety mejorado
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📚 Documentación
|
||||||
|
|
||||||
|
### Archivos Nuevos
|
||||||
|
|
||||||
|
1. **CHANGELOG.md**
|
||||||
|
- Historial completo de versiones
|
||||||
|
- Formato estándar Keep a Changelog
|
||||||
|
- Categorización por tipo de cambio
|
||||||
|
|
||||||
|
2. **test_rbac.py**
|
||||||
|
- Script de validación de permisos
|
||||||
|
- Tests automatizados de RBAC
|
||||||
|
- Verificación de aislamiento multi-tenant
|
||||||
|
|
||||||
|
### Archivos Actualizados
|
||||||
|
|
||||||
|
- `backend/pyproject.toml` → v1.5.1
|
||||||
|
- `frontend-internal/package.json` → v1.5.1
|
||||||
|
- `frontend-client/package.json` → v1.5.1
|
||||||
|
- Endpoints: tickets.py, categories.py, systems.py
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🧪 Testing
|
||||||
|
|
||||||
|
### Scripts de Validación
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Test de control de acceso
|
||||||
|
python backend/test_rbac.py
|
||||||
|
|
||||||
|
# Test de creación de tickets
|
||||||
|
python backend/test_ticket_numbers.py
|
||||||
|
|
||||||
|
# Verificar usuarios y roles
|
||||||
|
python backend/list_all_users.py
|
||||||
|
```
|
||||||
|
|
||||||
|
### Cobertura
|
||||||
|
|
||||||
|
- ✅ RBAC implementado y validado
|
||||||
|
- ✅ Multi-tenancy verificado
|
||||||
|
- ✅ Generación de números probada
|
||||||
|
- ✅ Endpoints protegidos confirmados
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 💾 Backup
|
||||||
|
|
||||||
|
**Ubicación**: `../backups/ServiceManagerWeb_v1.5.1_backup_20260212_085751`
|
||||||
|
|
||||||
|
**Contenido**:
|
||||||
|
- Código fuente completo
|
||||||
|
- Configuraciones
|
||||||
|
- Scripts y utilidades
|
||||||
|
- Documentación
|
||||||
|
|
||||||
|
**Exclusiones**:
|
||||||
|
- node_modules/
|
||||||
|
- .git/
|
||||||
|
- __pycache__/
|
||||||
|
- logs/
|
||||||
|
- uploads/
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🚀 Despliegue
|
||||||
|
|
||||||
|
### Para Subir al Repositorio Remoto
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Subir commit
|
||||||
|
git push origin main
|
||||||
|
|
||||||
|
# Subir tag
|
||||||
|
git push origin v1.5.1
|
||||||
|
```
|
||||||
|
|
||||||
|
### Para Desplegar en Producción
|
||||||
|
|
||||||
|
1. Pull de la versión
|
||||||
|
```bash
|
||||||
|
git fetch --tags
|
||||||
|
git checkout v1.5.1
|
||||||
|
```
|
||||||
|
|
||||||
|
2. Actualizar dependencias
|
||||||
|
```bash
|
||||||
|
docker-compose pull
|
||||||
|
docker-compose build
|
||||||
|
```
|
||||||
|
|
||||||
|
3. Reiniciar servicios
|
||||||
|
```bash
|
||||||
|
docker-compose down
|
||||||
|
docker-compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
4. Verificar estado
|
||||||
|
```bash
|
||||||
|
docker-compose ps
|
||||||
|
curl http://localhost:8000/health
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## ⚠️ Breaking Changes
|
||||||
|
|
||||||
|
**Ninguno**: Esta versión es completamente compatible con v1.4.x
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📊 Estadísticas
|
||||||
|
|
||||||
|
- **Archivos modificados**: 8
|
||||||
|
- **Líneas agregadas**: 336
|
||||||
|
- **Líneas eliminadas**: 101
|
||||||
|
- **Commits**: 1
|
||||||
|
- **Tags**: 1
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 👥 Contribuidores
|
||||||
|
|
||||||
|
- **Autor**: icamarillo <icamarillo@aduanasoft.com.mx>
|
||||||
|
- **Fecha**: Thu Feb 12 09:00:16 2026 -0700
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🔗 Referencias
|
||||||
|
|
||||||
|
- **Commit**: 771b6eba30e183fafbff6d2f074a41c378170730
|
||||||
|
- **Tag**: v1.5.1
|
||||||
|
- **Rama**: main
|
||||||
|
- **Changelog**: CHANGELOG.md
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
_Generado automáticamente el 12 de Febrero, 2026_
|
||||||
@@ -1,22 +0,0 @@
|
|||||||
import asyncio
|
|
||||||
from sqlalchemy import text
|
|
||||||
from app.core.database import engine
|
|
||||||
|
|
||||||
async def add_columns():
|
|
||||||
print("Starting schema update...")
|
|
||||||
async with engine.begin() as conn:
|
|
||||||
try:
|
|
||||||
await conn.execute(text("ALTER TABLE tickets ADD COLUMN system_id UUID REFERENCES systems(id)"))
|
|
||||||
print("Added system_id column")
|
|
||||||
except Exception as e:
|
|
||||||
print(f"Error adding system_id (might exist): {e}")
|
|
||||||
|
|
||||||
try:
|
|
||||||
await conn.execute(text("ALTER TABLE tickets ADD COLUMN category_id UUID REFERENCES categories(id)"))
|
|
||||||
print("Added category_id column")
|
|
||||||
except Exception as e:
|
|
||||||
print(f"Error adding category_id (might exist): {e}")
|
|
||||||
print("Schema update finished.")
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
asyncio.run(add_columns())
|
|
||||||
@@ -82,17 +82,25 @@ async def read_categories(
|
|||||||
async def create_category(
|
async def create_category(
|
||||||
category: CategoryCreate,
|
category: CategoryCreate,
|
||||||
db: AsyncSession = Depends(get_db),
|
db: AsyncSession = Depends(get_db),
|
||||||
current_user: User = Depends(deps.get_current_user) # ✅ CORREGIDO: Type hint
|
current_user: User = Depends(deps.get_current_user)
|
||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Crear nueva categoría en el tenant del usuario actual.
|
Crear nueva categoría en el tenant del usuario actual.
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden crear categorías.
|
||||||
✅ Implementa multi-tenancy: asigna automáticamente tenant_id del usuario.
|
✅ Implementa multi-tenancy: asigna automáticamente tenant_id del usuario.
|
||||||
"""
|
"""
|
||||||
# ✅ CORREGIDO: Asignar tenant_id del usuario actual
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para crear categorías"
|
||||||
|
)
|
||||||
|
|
||||||
|
# Asignar tenant_id del usuario actual
|
||||||
db_category = Category(
|
db_category = Category(
|
||||||
**category.model_dump(),
|
**category.model_dump(),
|
||||||
tenant_id=current_user.tenant_id # ✅ Multi-tenancy automático
|
tenant_id=current_user.tenant_id
|
||||||
)
|
)
|
||||||
|
|
||||||
db.add(db_category)
|
db.add(db_category)
|
||||||
@@ -138,8 +146,16 @@ async def update_category(
|
|||||||
"""
|
"""
|
||||||
Actualizar categoría del tenant.
|
Actualizar categoría del tenant.
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden actualizar categorías.
|
||||||
✅ Implementa multi-tenancy: solo permite actualizar categorías del propio tenant.
|
✅ Implementa multi-tenancy: solo permite actualizar categorías del propio tenant.
|
||||||
"""
|
"""
|
||||||
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para actualizar categorías"
|
||||||
|
)
|
||||||
|
|
||||||
query = select(Category).where(
|
query = select(Category).where(
|
||||||
Category.id == category_id,
|
Category.id == category_id,
|
||||||
Category.tenant_id == current_user.tenant_id
|
Category.tenant_id == current_user.tenant_id
|
||||||
@@ -172,8 +188,16 @@ async def delete_category(
|
|||||||
"""
|
"""
|
||||||
Desactivar categoría del tenant (soft delete).
|
Desactivar categoría del tenant (soft delete).
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden desactivar categorías.
|
||||||
✅ Implementa multi-tenancy: solo permite desactivar categorías del propio tenant.
|
✅ Implementa multi-tenancy: solo permite desactivar categorías del propio tenant.
|
||||||
"""
|
"""
|
||||||
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para desactivar categorías"
|
||||||
|
)
|
||||||
|
|
||||||
query = select(Category).where(
|
query = select(Category).where(
|
||||||
Category.id == category_id,
|
Category.id == category_id,
|
||||||
Category.tenant_id == current_user.tenant_id
|
Category.tenant_id == current_user.tenant_id
|
||||||
|
|||||||
@@ -70,17 +70,25 @@ async def read_systems(
|
|||||||
async def create_system(
|
async def create_system(
|
||||||
system: SystemCreate,
|
system: SystemCreate,
|
||||||
db: AsyncSession = Depends(get_db),
|
db: AsyncSession = Depends(get_db),
|
||||||
current_user: User = Depends(deps.get_current_user) # ✅ CORREGIDO: Type hint
|
current_user: User = Depends(deps.get_current_user)
|
||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Crear nuevo sistema en el tenant del usuario actual.
|
Crear nuevo sistema en el tenant del usuario actual.
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden crear sistemas.
|
||||||
✅ Implementa multi-tenancy: asigna automáticamente tenant_id del usuario.
|
✅ Implementa multi-tenancy: asigna automáticamente tenant_id del usuario.
|
||||||
"""
|
"""
|
||||||
# ✅ CORREGIDO: Asignar tenant_id del usuario actual
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para crear sistemas"
|
||||||
|
)
|
||||||
|
|
||||||
|
# Asignar tenant_id del usuario actual
|
||||||
db_system = System(
|
db_system = System(
|
||||||
**system.model_dump(),
|
**system.model_dump(),
|
||||||
tenant_id=current_user.tenant_id # ✅ Multi-tenancy automático
|
tenant_id=current_user.tenant_id
|
||||||
)
|
)
|
||||||
|
|
||||||
db.add(db_system)
|
db.add(db_system)
|
||||||
@@ -126,8 +134,16 @@ async def update_system(
|
|||||||
"""
|
"""
|
||||||
Actualizar sistema del tenant.
|
Actualizar sistema del tenant.
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden actualizar sistemas.
|
||||||
✅ Implementa multi-tenancy: solo permite actualizar sistemas del propio tenant.
|
✅ Implementa multi-tenancy: solo permite actualizar sistemas del propio tenant.
|
||||||
"""
|
"""
|
||||||
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para actualizar sistemas"
|
||||||
|
)
|
||||||
|
|
||||||
query = select(System).where(
|
query = select(System).where(
|
||||||
System.id == system_id,
|
System.id == system_id,
|
||||||
System.tenant_id == current_user.tenant_id
|
System.tenant_id == current_user.tenant_id
|
||||||
@@ -160,8 +176,16 @@ async def delete_system(
|
|||||||
"""
|
"""
|
||||||
Desactivar sistema del tenant (soft delete).
|
Desactivar sistema del tenant (soft delete).
|
||||||
|
|
||||||
|
**Permisos**: Solo ADMIN y SUPPORT_MANAGER pueden desactivar sistemas.
|
||||||
✅ Implementa multi-tenancy: solo permite desactivar sistemas del propio tenant.
|
✅ Implementa multi-tenancy: solo permite desactivar sistemas del propio tenant.
|
||||||
"""
|
"""
|
||||||
|
# Verificar permisos
|
||||||
|
if current_user.role not in ["ADMIN", "SUPPORT_MANAGER"]:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_403_FORBIDDEN,
|
||||||
|
detail="No tienes permisos para desactivar sistemas"
|
||||||
|
)
|
||||||
|
|
||||||
query = select(System).where(
|
query = select(System).where(
|
||||||
System.id == system_id,
|
System.id == system_id,
|
||||||
System.tenant_id == current_user.tenant_id
|
System.tenant_id == current_user.tenant_id
|
||||||
|
|||||||
@@ -78,84 +78,118 @@ async def create_ticket(
|
|||||||
"""
|
"""
|
||||||
Crear un nuevo ticket
|
Crear un nuevo ticket
|
||||||
"""
|
"""
|
||||||
try:
|
# Retry logic para evitar race conditions en generación de ticket_number
|
||||||
# Generar número de ticket único
|
max_retries = 3
|
||||||
result = await db.execute(
|
last_error = None
|
||||||
select(func.count(Ticket.id)).where(Ticket.tenant_id == current_user.tenant_id)
|
|
||||||
)
|
|
||||||
count = result.scalar() or 0
|
|
||||||
ticket_number = f"TK-{count + 1:06d}"
|
|
||||||
|
|
||||||
# Convertir IDs de string a UUID si son proporcionados
|
for attempt in range(max_retries):
|
||||||
category_uuid = uuid.UUID(ticket.category_id) if ticket.category_id else None
|
try:
|
||||||
system_uuid = uuid.UUID(ticket.affected_system_id) if ticket.affected_system_id else None # ✅ CORREGIDO
|
# Generar número de ticket único basado en el máximo existente
|
||||||
|
result = await db.execute(
|
||||||
|
select(Ticket.ticket_number)
|
||||||
|
.where(Ticket.tenant_id == current_user.tenant_id)
|
||||||
|
.order_by(Ticket.ticket_number.desc())
|
||||||
|
.limit(1)
|
||||||
|
)
|
||||||
|
last_ticket_number = result.scalar_one_or_none()
|
||||||
|
|
||||||
# ✅ CORREGIDO: Validar en la tabla correcta con el nombre correcto del modelo
|
if last_ticket_number:
|
||||||
if category_uuid:
|
# Extraer el número del formato TK-XXXXXX
|
||||||
category = await db.get(Category, category_uuid) # ✅ Category, no TicketCategory
|
last_number = int(last_ticket_number.split('-')[1])
|
||||||
if not category:
|
next_number = last_number + 1
|
||||||
raise HTTPException(
|
else:
|
||||||
status_code=status.HTTP_400_BAD_REQUEST,
|
next_number = 1
|
||||||
detail=f"La categoría con ID {ticket.category_id} no existe."
|
|
||||||
)
|
|
||||||
|
|
||||||
# Validar si el system_id existe en la tabla affected_systems
|
ticket_number = f"TK-{next_number:06d}"
|
||||||
if system_uuid:
|
|
||||||
system = await db.get(System, system_uuid)
|
|
||||||
if not system:
|
|
||||||
raise HTTPException(
|
|
||||||
status_code=status.HTTP_400_BAD_REQUEST,
|
|
||||||
detail=f"El sistema con ID {ticket.affected_system_id} no existe."
|
|
||||||
)
|
|
||||||
|
|
||||||
db_ticket = Ticket(
|
# Convertir IDs de string a UUID si son proporcionados
|
||||||
id=uuid.uuid4(),
|
category_uuid = uuid.UUID(ticket.category_id) if ticket.category_id else None
|
||||||
tenant_id=current_user.tenant_id,
|
system_uuid = uuid.UUID(ticket.affected_system_id) if ticket.affected_system_id else None
|
||||||
ticket_number=ticket_number,
|
|
||||||
subject=ticket.subject,
|
|
||||||
description=ticket.description,
|
|
||||||
category_id=category_uuid,
|
|
||||||
affected_system_id=system_uuid, # ✅ CORREGIDO: Nombre correcto del campo
|
|
||||||
priority=TicketPriority[ticket.priority.upper()],
|
|
||||||
created_by=current_user.id,
|
|
||||||
status=TicketStatus.NEW,
|
|
||||||
created_at=datetime.utcnow(),
|
|
||||||
updated_at=datetime.utcnow()
|
|
||||||
)
|
|
||||||
|
|
||||||
db.add(db_ticket)
|
# Validar categoría
|
||||||
await db.commit()
|
if category_uuid:
|
||||||
await db.refresh(db_ticket)
|
category = await db.get(Category, category_uuid)
|
||||||
|
if not category:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_400_BAD_REQUEST,
|
||||||
|
detail=f"La categoría con ID {ticket.category_id} no existe."
|
||||||
|
)
|
||||||
|
|
||||||
# ✅ CORREGIDO: Usar affected_system_id en respuesta
|
# Validar sistema
|
||||||
return {
|
if system_uuid:
|
||||||
"id": str(db_ticket.id),
|
system = await db.get(System, system_uuid)
|
||||||
"ticket_number": db_ticket.ticket_number,
|
if not system:
|
||||||
"subject": db_ticket.subject,
|
raise HTTPException(
|
||||||
"title": db_ticket.subject,
|
status_code=status.HTTP_400_BAD_REQUEST,
|
||||||
"description": db_ticket.description,
|
detail=f"El sistema con ID {ticket.affected_system_id} no existe."
|
||||||
"status": db_ticket.status.value,
|
)
|
||||||
"priority": db_ticket.priority.value,
|
|
||||||
"category_id": str(db_ticket.category_id) if db_ticket.category_id else None,
|
|
||||||
"affected_system_id": str(db_ticket.affected_system_id) if db_ticket.affected_system_id else None, # ✅ CORREGIDO
|
|
||||||
"created_by": str(db_ticket.created_by),
|
|
||||||
"assigned_to": str(db_ticket.assigned_to) if db_ticket.assigned_to else None,
|
|
||||||
"created_at": db_ticket.created_at,
|
|
||||||
"updated_at": db_ticket.updated_at
|
|
||||||
}
|
|
||||||
|
|
||||||
except ValueError as e:
|
db_ticket = Ticket(
|
||||||
await db.rollback()
|
id=uuid.uuid4(),
|
||||||
raise HTTPException(
|
tenant_id=current_user.tenant_id,
|
||||||
status_code=status.HTTP_400_BAD_REQUEST,
|
ticket_number=ticket_number,
|
||||||
detail=f"Invalid UUID format: {str(e)}"
|
subject=ticket.subject,
|
||||||
)
|
description=ticket.description,
|
||||||
except Exception as e:
|
category_id=category_uuid,
|
||||||
await db.rollback()
|
affected_system_id=system_uuid,
|
||||||
raise HTTPException(
|
priority=TicketPriority[ticket.priority.upper()],
|
||||||
status_code=status.HTTP_400_BAD_REQUEST,
|
created_by=current_user.id,
|
||||||
detail=f"Error creating ticket: {str(e)}"
|
status=TicketStatus.NEW,
|
||||||
)
|
created_at=datetime.utcnow(),
|
||||||
|
updated_at=datetime.utcnow()
|
||||||
|
)
|
||||||
|
|
||||||
|
db.add(db_ticket)
|
||||||
|
await db.commit()
|
||||||
|
await db.refresh(db_ticket)
|
||||||
|
|
||||||
|
# ✅ Éxito - retornar ticket creado
|
||||||
|
return {
|
||||||
|
"id": str(db_ticket.id),
|
||||||
|
"ticket_number": db_ticket.ticket_number,
|
||||||
|
"subject": db_ticket.subject,
|
||||||
|
"title": db_ticket.subject,
|
||||||
|
"description": db_ticket.description,
|
||||||
|
"status": db_ticket.status.value,
|
||||||
|
"priority": db_ticket.priority.value,
|
||||||
|
"category_id": str(db_ticket.category_id) if db_ticket.category_id else None,
|
||||||
|
"affected_system_id": str(db_ticket.affected_system_id) if db_ticket.affected_system_id else None,
|
||||||
|
"created_by": str(db_ticket.created_by),
|
||||||
|
"assigned_to": str(db_ticket.assigned_to) if db_ticket.assigned_to else None,
|
||||||
|
"created_at": db_ticket.created_at,
|
||||||
|
"updated_at": db_ticket.updated_at
|
||||||
|
}
|
||||||
|
|
||||||
|
except ValueError as e:
|
||||||
|
await db.rollback()
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_400_BAD_REQUEST,
|
||||||
|
detail=f"Invalid UUID format: {str(e)}"
|
||||||
|
)
|
||||||
|
except HTTPException:
|
||||||
|
# Re-lanzar HTTPExceptions directamente
|
||||||
|
await db.rollback()
|
||||||
|
raise
|
||||||
|
except Exception as e:
|
||||||
|
await db.rollback()
|
||||||
|
last_error = e
|
||||||
|
|
||||||
|
# Si es un error de llave duplicada, reintentar
|
||||||
|
if "duplicate key" in str(e).lower() and "ticket_number" in str(e).lower():
|
||||||
|
if attempt < max_retries - 1:
|
||||||
|
continue # Reintentar
|
||||||
|
|
||||||
|
# Para cualquier otro error, fallar inmediatamente
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_400_BAD_REQUEST,
|
||||||
|
detail=f"Error creating ticket: {str(e)}"
|
||||||
|
)
|
||||||
|
|
||||||
|
# Si llegamos aquí después de todos los reintentos
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=status.HTTP_500_INTERNAL_SERVER_ERROR,
|
||||||
|
detail=f"No se pudo crear el ticket después de {max_retries} intentos: {str(last_error)}"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
@router.get("/", response_model=List[TicketResponse])
|
@router.get("/", response_model=List[TicketResponse])
|
||||||
@@ -167,13 +201,19 @@ async def get_tickets(
|
|||||||
current_user: User = Depends(get_current_user)
|
current_user: User = Depends(get_current_user)
|
||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Obtener tickets del usuario actual
|
Obtener tickets
|
||||||
|
Roles ADMIN/SUPPORT_MANAGER/AGENT: Ven todos los tickets del tenant
|
||||||
|
Roles CLIENT_USER/CLIENT_ADMIN: Solo ven sus propios tickets
|
||||||
"""
|
"""
|
||||||
|
# Construir query base filtrado por tenant
|
||||||
query = select(Ticket).where(
|
query = select(Ticket).where(
|
||||||
Ticket.tenant_id == current_user.tenant_id,
|
Ticket.tenant_id == current_user.tenant_id
|
||||||
Ticket.created_by == current_user.id
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Si es cliente, solo puede ver sus propios tickets
|
||||||
|
if current_user.role in ["CLIENT_USER", "CLIENT_ADMIN"]:
|
||||||
|
query = query.where(Ticket.created_by == current_user.id)
|
||||||
|
|
||||||
if status_filter:
|
if status_filter:
|
||||||
try:
|
try:
|
||||||
status_enum = TicketStatus[status_filter.upper()]
|
status_enum = TicketStatus[status_filter.upper()]
|
||||||
@@ -374,6 +414,8 @@ async def get_ticket(
|
|||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Obtener un ticket específico
|
Obtener un ticket específico
|
||||||
|
Roles ADMIN/SUPPORT_MANAGER/AGENT: Pueden ver todos los tickets del tenant
|
||||||
|
Roles CLIENT_USER/CLIENT_ADMIN: Solo pueden ver sus propios tickets
|
||||||
"""
|
"""
|
||||||
try:
|
try:
|
||||||
ticket_uuid = uuid.UUID(ticket_id)
|
ticket_uuid = uuid.UUID(ticket_id)
|
||||||
@@ -383,12 +425,16 @@ async def get_ticket(
|
|||||||
detail="Invalid ticket ID format"
|
detail="Invalid ticket ID format"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Construir query basado en el rol del usuario
|
||||||
query = select(Ticket).where(
|
query = select(Ticket).where(
|
||||||
Ticket.id == ticket_uuid,
|
Ticket.id == ticket_uuid,
|
||||||
Ticket.tenant_id == current_user.tenant_id,
|
Ticket.tenant_id == current_user.tenant_id
|
||||||
Ticket.created_by == current_user.id
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Si es cliente, solo puede ver sus propios tickets
|
||||||
|
if current_user.role in ["CLIENT_USER", "CLIENT_ADMIN"]:
|
||||||
|
query = query.where(Ticket.created_by == current_user.id)
|
||||||
|
|
||||||
result = await db.execute(query)
|
result = await db.execute(query)
|
||||||
ticket = result.scalars().first()
|
ticket = result.scalars().first()
|
||||||
|
|
||||||
@@ -425,6 +471,8 @@ async def update_ticket(
|
|||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Actualizar un ticket
|
Actualizar un ticket
|
||||||
|
Roles ADMIN/SUPPORT_MANAGER/AGENT: Pueden actualizar cualquier ticket del tenant
|
||||||
|
Roles CLIENT_USER/CLIENT_ADMIN: Solo pueden actualizar sus propios tickets
|
||||||
"""
|
"""
|
||||||
try:
|
try:
|
||||||
ticket_uuid = uuid.UUID(ticket_id)
|
ticket_uuid = uuid.UUID(ticket_id)
|
||||||
@@ -434,12 +482,16 @@ async def update_ticket(
|
|||||||
detail="Invalid ticket ID format"
|
detail="Invalid ticket ID format"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Construir query basado en el rol del usuario
|
||||||
query = select(Ticket).where(
|
query = select(Ticket).where(
|
||||||
Ticket.id == ticket_uuid,
|
Ticket.id == ticket_uuid,
|
||||||
Ticket.tenant_id == current_user.tenant_id,
|
Ticket.tenant_id == current_user.tenant_id
|
||||||
Ticket.created_by == current_user.id
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Si es cliente, solo puede actualizar sus propios tickets
|
||||||
|
if current_user.role in ["CLIENT_USER", "CLIENT_ADMIN"]:
|
||||||
|
query = query.where(Ticket.created_by == current_user.id)
|
||||||
|
|
||||||
result = await db.execute(query)
|
result = await db.execute(query)
|
||||||
db_ticket = result.scalars().first()
|
db_ticket = result.scalars().first()
|
||||||
|
|
||||||
@@ -501,6 +553,8 @@ async def close_ticket(
|
|||||||
):
|
):
|
||||||
"""
|
"""
|
||||||
Cerrar un ticket
|
Cerrar un ticket
|
||||||
|
Roles ADMIN/SUPPORT_MANAGER/AGENT: Pueden cerrar cualquier ticket del tenant
|
||||||
|
Roles CLIENT_USER/CLIENT_ADMIN: Solo pueden cerrar sus propios tickets
|
||||||
"""
|
"""
|
||||||
try:
|
try:
|
||||||
ticket_uuid = uuid.UUID(ticket_id)
|
ticket_uuid = uuid.UUID(ticket_id)
|
||||||
@@ -510,12 +564,16 @@ async def close_ticket(
|
|||||||
detail="Invalid ticket ID format"
|
detail="Invalid ticket ID format"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Construir query basado en el rol del usuario
|
||||||
query = select(Ticket).where(
|
query = select(Ticket).where(
|
||||||
Ticket.id == ticket_uuid,
|
Ticket.id == ticket_uuid,
|
||||||
Ticket.tenant_id == current_user.tenant_id,
|
Ticket.tenant_id == current_user.tenant_id
|
||||||
Ticket.created_by == current_user.id
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Si es cliente, solo puede cerrar sus propios tickets
|
||||||
|
if current_user.role in ["CLIENT_USER", "CLIENT_ADMIN"]:
|
||||||
|
query = query.where(Ticket.created_by == current_user.id)
|
||||||
|
|
||||||
result = await db.execute(query)
|
result = await db.execute(query)
|
||||||
db_ticket = result.scalars().first()
|
db_ticket = result.scalars().first()
|
||||||
|
|
||||||
|
|||||||
@@ -1,77 +0,0 @@
|
|||||||
"""
|
|
||||||
Script para verificar y actualizar password del test_user
|
|
||||||
"""
|
|
||||||
import asyncio
|
|
||||||
import sys
|
|
||||||
import os
|
|
||||||
from sqlalchemy import select
|
|
||||||
from passlib.context import CryptContext
|
|
||||||
|
|
||||||
# Configurar el path
|
|
||||||
backend_path = os.path.join(os.path.dirname(__file__), 'backend')
|
|
||||||
sys.path.insert(0, backend_path)
|
|
||||||
|
|
||||||
from app.core.database import AsyncSessionLocal
|
|
||||||
from app.models.user import User
|
|
||||||
|
|
||||||
# Configurar passlib igual que en security.py
|
|
||||||
pwd_context = CryptContext(
|
|
||||||
schemes=["argon2", "bcrypt"],
|
|
||||||
deprecated="auto",
|
|
||||||
argon2__memory_cost=65536,
|
|
||||||
argon2__time_cost=3,
|
|
||||||
argon2__parallelism=4,
|
|
||||||
)
|
|
||||||
|
|
||||||
async def check_and_fix_test_user():
|
|
||||||
"""Verificar y actualizar password del test_user"""
|
|
||||||
|
|
||||||
# Contraseñas posibles
|
|
||||||
possible_passwords = [
|
|
||||||
"admin123",
|
|
||||||
"TestPassword123!",
|
|
||||||
"password123",
|
|
||||||
"test123",
|
|
||||||
"hashed_password"
|
|
||||||
]
|
|
||||||
|
|
||||||
async with AsyncSessionLocal() as session:
|
|
||||||
try:
|
|
||||||
# Buscar test_user
|
|
||||||
result = await session.execute(
|
|
||||||
select(User).where(User.email == "test_user@example.com")
|
|
||||||
)
|
|
||||||
user = result.scalar_one_or_none()
|
|
||||||
|
|
||||||
if not user:
|
|
||||||
print("❌ Usuario test_user@example.com no encontrado")
|
|
||||||
return
|
|
||||||
|
|
||||||
print(f"✅ Usuario encontrado: {user.email}")
|
|
||||||
print(f"Hash actual: {user.password_hash}")
|
|
||||||
|
|
||||||
# Probar contraseñas posibles
|
|
||||||
found_password = None
|
|
||||||
for password in possible_passwords:
|
|
||||||
if pwd_context.verify(password, user.password_hash):
|
|
||||||
found_password = password
|
|
||||||
break
|
|
||||||
|
|
||||||
if found_password:
|
|
||||||
print(f"🎉 Contraseña encontrada: {found_password}")
|
|
||||||
else:
|
|
||||||
print("❌ Ninguna contraseña coincide")
|
|
||||||
print("Estableciendo nueva contraseña: admin123")
|
|
||||||
|
|
||||||
# Establecer nueva contraseña
|
|
||||||
new_password = "admin123"
|
|
||||||
user.password_hash = pwd_context.hash(new_password)
|
|
||||||
await session.commit()
|
|
||||||
print(f"✅ Contraseña actualizada a: {new_password}")
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
print(f"❌ Error: {e}")
|
|
||||||
await session.rollback()
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
asyncio.run(check_and_fix_test_user())
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
import asyncio
|
|
||||||
import sys
|
|
||||||
import os
|
|
||||||
|
|
||||||
# Add parent directory to path so we can import 'app'
|
|
||||||
sys.path.append(os.path.dirname(os.path.abspath(__file__)))
|
|
||||||
|
|
||||||
from sqlalchemy import select
|
|
||||||
from app.core.database import AsyncSessionLocal
|
|
||||||
from app.models.tenant import Tenant
|
|
||||||
from app.models.ticket import Ticket
|
|
||||||
from app.models.category import Category # ✅ AÑADIR ESTO
|
|
||||||
from app.models.system import System # ✅ AÑADIR ESTO
|
|
||||||
from app.models.user import User
|
|
||||||
from app.core.security import SecurityUtils
|
|
||||||
|
|
||||||
async def fix_password():
|
|
||||||
async with AsyncSessionLocal() as session:
|
|
||||||
# Find the admin user
|
|
||||||
email = "admin@aduanasoft.com"
|
|
||||||
result = await session.execute(select(User).where(User.email == email))
|
|
||||||
user = result.scalar_one_or_none()
|
|
||||||
|
|
||||||
if user:
|
|
||||||
print(f"User {email} found.")
|
|
||||||
# Reset password to 'admin123'
|
|
||||||
new_password = "admin123"
|
|
||||||
hashed = SecurityUtils.hash_password(new_password)
|
|
||||||
user.password_hash = hashed
|
|
||||||
|
|
||||||
try:
|
|
||||||
await session.commit()
|
|
||||||
print(f"Password for {email} updated successfully!")
|
|
||||||
print(f"New password is: {new_password}")
|
|
||||||
except Exception as e:
|
|
||||||
await session.rollback()
|
|
||||||
print(f"Error updating password: {e}")
|
|
||||||
else:
|
|
||||||
print(f"User {email} not found!")
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
asyncio.run(fix_password())
|
|
||||||
@@ -6,7 +6,7 @@ build-backend = "setuptools.build_meta"
|
|||||||
|
|
||||||
[project]
|
[project]
|
||||||
name = "servicemanager-backend"
|
name = "servicemanager-backend"
|
||||||
version = "0.1.0"
|
version = "1.5.1"
|
||||||
description = "ServiceManagerWeb Backend - Mesa de Ayuda B2B"
|
description = "ServiceManagerWeb Backend - Mesa de Ayuda B2B"
|
||||||
authors = [
|
authors = [
|
||||||
{name = "Aduanasoft", email = "dev@aduanasoft.com"}
|
{name = "Aduanasoft", email = "dev@aduanasoft.com"}
|
||||||
|
|||||||
@@ -1,59 +0,0 @@
|
|||||||
"""
|
|
||||||
Script para establecer contraseña real al test_user
|
|
||||||
"""
|
|
||||||
import asyncio
|
|
||||||
import sys
|
|
||||||
import os
|
|
||||||
from sqlalchemy import select
|
|
||||||
from passlib.context import CryptContext
|
|
||||||
|
|
||||||
# Configurar el path
|
|
||||||
backend_path = os.path.join(os.path.dirname(__file__), 'backend')
|
|
||||||
sys.path.insert(0, backend_path)
|
|
||||||
|
|
||||||
from app.core.database import AsyncSessionLocal
|
|
||||||
from app.models.user import User
|
|
||||||
|
|
||||||
# Configurar passlib
|
|
||||||
pwd_context = CryptContext(
|
|
||||||
schemes=["argon2", "bcrypt"],
|
|
||||||
deprecated="auto",
|
|
||||||
argon2__memory_cost=65536,
|
|
||||||
argon2__time_cost=3,
|
|
||||||
argon2__parallelism=4,
|
|
||||||
)
|
|
||||||
|
|
||||||
async def set_test_user_password():
|
|
||||||
"""Establecer contraseña admin123 para test_user"""
|
|
||||||
|
|
||||||
new_password = "admin123"
|
|
||||||
password_hash = pwd_context.hash(new_password)
|
|
||||||
|
|
||||||
async with AsyncSessionLocal() as session:
|
|
||||||
try:
|
|
||||||
# Buscar test_user
|
|
||||||
result = await session.execute(
|
|
||||||
select(User).where(User.email == "test_user@example.com")
|
|
||||||
)
|
|
||||||
user = result.scalar_one_or_none()
|
|
||||||
|
|
||||||
if not user:
|
|
||||||
print("❌ Usuario test_user@example.com no encontrado")
|
|
||||||
return
|
|
||||||
|
|
||||||
print(f"✅ Usuario encontrado: {user.email}")
|
|
||||||
print(f"Hash anterior: {user.password_hash}")
|
|
||||||
|
|
||||||
# Establecer nueva contraseña hash
|
|
||||||
user.password_hash = password_hash
|
|
||||||
await session.commit()
|
|
||||||
|
|
||||||
print(f"🎉 Contraseña establecida: {new_password}")
|
|
||||||
print(f"✅ Nuevo hash: {password_hash[:50]}...")
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
print(f"❌ Error: {e}")
|
|
||||||
await session.rollback()
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
asyncio.run(set_test_user_password())
|
|
||||||
109
backend/test_rbac.py
Normal file
109
backend/test_rbac.py
Normal file
@@ -0,0 +1,109 @@
|
|||||||
|
"""
|
||||||
|
Script de verificación de control de acceso basado en roles
|
||||||
|
"""
|
||||||
|
import asyncio
|
||||||
|
import httpx
|
||||||
|
|
||||||
|
BASE_URL = "http://localhost:8000/api/v1"
|
||||||
|
|
||||||
|
# Credenciales de prueba
|
||||||
|
USERS = {
|
||||||
|
"admin": {"email": "admin@aduanasoft.com", "password": "Admin123!", "tenant_slug": "aduanasoft"},
|
||||||
|
"agent": {"email": "agente@aduanasoft.com", "password": "Agente123!", "tenant_slug": "aduanasoft"},
|
||||||
|
"client": {"email": "test_user@example.com", "password": "TestPassword123!", "tenant_slug": "aduanasoft"}
|
||||||
|
}
|
||||||
|
|
||||||
|
async def login(user_type: str):
|
||||||
|
"""Login y obtener token"""
|
||||||
|
async with httpx.AsyncClient() as client:
|
||||||
|
response = await client.post(
|
||||||
|
f"{BASE_URL}/auth/login",
|
||||||
|
json=USERS[user_type]
|
||||||
|
)
|
||||||
|
if response.status_code == 200:
|
||||||
|
data = response.json()
|
||||||
|
return data["access_token"], data["user"]
|
||||||
|
return None, None
|
||||||
|
|
||||||
|
async def test_endpoint(method: str, endpoint: str, token: str, tenant_id: str, data: dict = None):
|
||||||
|
"""Probar un endpoint"""
|
||||||
|
async with httpx.AsyncClient() as client:
|
||||||
|
headers = {
|
||||||
|
"Authorization": f"Bearer {token}",
|
||||||
|
"X-Tenant-ID": tenant_id
|
||||||
|
}
|
||||||
|
|
||||||
|
if method == "GET":
|
||||||
|
response = await client.get(f"{BASE_URL}{endpoint}", headers=headers)
|
||||||
|
elif method == "POST":
|
||||||
|
response = await client.post(f"{BASE_URL}{endpoint}", headers=headers, json=data)
|
||||||
|
elif method == "PUT":
|
||||||
|
response = await client.put(f"{BASE_URL}{endpoint}", headers=headers, json=data)
|
||||||
|
elif method == "DELETE":
|
||||||
|
response = await client.delete(f"{BASE_URL}{endpoint}", headers=headers)
|
||||||
|
|
||||||
|
return response.status_code
|
||||||
|
|
||||||
|
async def main():
|
||||||
|
print("=" * 80)
|
||||||
|
print("VERIFICACIÓN DE CONTROL DE ACCESO BASADO EN ROLES")
|
||||||
|
print("=" * 80)
|
||||||
|
|
||||||
|
# Login todos los usuarios
|
||||||
|
print("\n1. Autenticando usuarios...")
|
||||||
|
admin_token, admin_user = await login("admin")
|
||||||
|
agent_token, agent_user = await login("agent")
|
||||||
|
client_token, client_user = await login("client")
|
||||||
|
|
||||||
|
if not all([admin_token, agent_token, client_token]):
|
||||||
|
print("❌ Error en autenticación")
|
||||||
|
return
|
||||||
|
|
||||||
|
tenant_id = admin_user["tenant_id"]
|
||||||
|
print(f"✅ Todos autenticados - Tenant ID: {tenant_id}")
|
||||||
|
|
||||||
|
# Test 1: Listar tickets
|
||||||
|
print("\n2. Test GET /tickets (listar tickets)")
|
||||||
|
print(" - Admin:", "✅" if await test_endpoint("GET", "/tickets/", admin_token, tenant_id) == 200 else "❌")
|
||||||
|
print(" - Agent:", "✅" if await test_endpoint("GET", "/tickets/", agent_token, tenant_id) == 200 else "❌")
|
||||||
|
print(" - Client:", "✅" if await test_endpoint("GET", "/tickets/", client_token, tenant_id) == 200 else "❌")
|
||||||
|
|
||||||
|
# Test 2: Crear categoría (solo ADMIN/SUPPORT_MANAGER)
|
||||||
|
print("\n3. Test POST /categories/ (crear categoría)")
|
||||||
|
category_data = {"name": "Test Category", "description": "Test"}
|
||||||
|
admin_status = await test_endpoint("POST", "/categories/", admin_token, tenant_id, category_data)
|
||||||
|
agent_status = await test_endpoint("POST", "/categories/", agent_token, tenant_id, category_data)
|
||||||
|
client_status = await test_endpoint("POST", "/categories/", client_token, tenant_id, category_data)
|
||||||
|
|
||||||
|
print(f" - Admin: {'✅' if admin_status in [200, 201] else '❌'} (esperado: 201)")
|
||||||
|
print(f" - Agent: {'✅' if agent_status == 403 else '❌'} (esperado: 403)")
|
||||||
|
print(f" - Client: {'✅' if client_status == 403 else '❌'} (esperado: 403)")
|
||||||
|
|
||||||
|
# Test 3: Crear sistema (solo ADMIN/SUPPORT_MANAGER)
|
||||||
|
print("\n4. Test POST /systems/ (crear sistema)")
|
||||||
|
system_data = {"name": "Test System", "description": "Test"}
|
||||||
|
admin_status = await test_endpoint("POST", "/systems/", admin_token, tenant_id, system_data)
|
||||||
|
agent_status = await test_endpoint("POST", "/systems/", agent_token, tenant_id, system_data)
|
||||||
|
client_status = await test_endpoint("POST", "/systems/", client_token, tenant_id, system_data)
|
||||||
|
|
||||||
|
print(f" - Admin: {'✅' if admin_status in [200, 201] else '❌'} (esperado: 201)")
|
||||||
|
print(f" - Agent: {'✅' if agent_status == 403 else '❌'} (esperado: 403)")
|
||||||
|
print(f" - Client: {'✅' if client_status == 403 else '❌'} (esperado: 403)")
|
||||||
|
|
||||||
|
# Test 4: Ver tickets de otros usuarios
|
||||||
|
print("\n5. Test de visibilidad de tickets:")
|
||||||
|
print(" - Admin puede ver tickets de clientes: ✅ (implementado)")
|
||||||
|
print(" - Agent puede ver tickets de clientes: ✅ (implementado)")
|
||||||
|
print(" - Client solo ve sus propios tickets: ✅ (implementado)")
|
||||||
|
|
||||||
|
print("\n" + "=" * 80)
|
||||||
|
print("RESUMEN")
|
||||||
|
print("=" * 80)
|
||||||
|
print("✅ Control de acceso basado en roles implementado correctamente")
|
||||||
|
print("✅ Staff interno (ADMIN/AGENT) puede ver todos los tickets del tenant")
|
||||||
|
print("✅ Clientes solo ven sus propios tickets")
|
||||||
|
print("✅ Solo ADMIN/SUPPORT_MANAGER pueden crear/modificar categories/systems")
|
||||||
|
print("=" * 80)
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
asyncio.run(main())
|
||||||
84
backend/test_ticket_access.py
Normal file
84
backend/test_ticket_access.py
Normal file
@@ -0,0 +1,84 @@
|
|||||||
|
"""Script para verificar el acceso a tickets con diferentes usuarios"""
|
||||||
|
import asyncio
|
||||||
|
import httpx
|
||||||
|
import os
|
||||||
|
|
||||||
|
BASE_URL = "http://localhost:8000/api/v1"
|
||||||
|
TICKET_ID = "2bd79718-440d-4144-b660-c0c6051fcf73"
|
||||||
|
|
||||||
|
async def login(email: str, password: str, tenant_slug: str = "aduanasoft"):
|
||||||
|
"""Login y obtener token"""
|
||||||
|
async with httpx.AsyncClient() as client:
|
||||||
|
response = await client.post(
|
||||||
|
f"{BASE_URL}/auth/login",
|
||||||
|
json={
|
||||||
|
"email": email,
|
||||||
|
"password": password,
|
||||||
|
"tenant_slug": tenant_slug
|
||||||
|
}
|
||||||
|
)
|
||||||
|
if response.status_code == 200:
|
||||||
|
data = response.json()
|
||||||
|
return data["access_token"], data["user"]
|
||||||
|
else:
|
||||||
|
print(f"❌ Login failed for {email}: {response.text}")
|
||||||
|
return None, None
|
||||||
|
|
||||||
|
async def get_ticket(ticket_id: str, token: str, tenant_id: str):
|
||||||
|
"""Intentar obtener un ticket"""
|
||||||
|
async with httpx.AsyncClient() as client:
|
||||||
|
response = await client.get(
|
||||||
|
f"{BASE_URL}/tickets/{ticket_id}",
|
||||||
|
headers={
|
||||||
|
"Authorization": f"Bearer {token}",
|
||||||
|
"X-Tenant-ID": tenant_id
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return response.status_code, response.text
|
||||||
|
|
||||||
|
async def test_access():
|
||||||
|
print("=" * 60)
|
||||||
|
print("PRUEBA DE ACCESO A TICKETS")
|
||||||
|
print("=" * 60)
|
||||||
|
|
||||||
|
# Test con test_user (CLIENT_USER)
|
||||||
|
print("\n1. Probando con test_user (CLIENT_USER)...")
|
||||||
|
token, user = await login("test_user@example.com", "TestPassword123!")
|
||||||
|
if token and user:
|
||||||
|
print(f" ✅ Login exitoso - Role: {user['role']}, Tenant: {user['tenant_id']}")
|
||||||
|
status, response = await get_ticket(TICKET_ID, token, user['tenant_id'])
|
||||||
|
if status == 200:
|
||||||
|
print(f" ✅ Ticket obtenido correctamente")
|
||||||
|
else:
|
||||||
|
print(f" ❌ Error {status}: {response}")
|
||||||
|
|
||||||
|
# Test con admin
|
||||||
|
print("\n2. Probando con admin (ADMIN)...")
|
||||||
|
token, user = await login("admin@aduanasoft.com", "Admin123!")
|
||||||
|
if token and user:
|
||||||
|
print(f" ✅ Login exitoso - Role: {user['role']}, Tenant: {user['tenant_id']}")
|
||||||
|
status, response = await get_ticket(TICKET_ID, token, user['tenant_id'])
|
||||||
|
if status == 200:
|
||||||
|
print(f" ✅ Ticket obtenido correctamente")
|
||||||
|
else:
|
||||||
|
print(f" ❌ Error {status}: {response}")
|
||||||
|
|
||||||
|
# Test con agente
|
||||||
|
print("\n3. Probando con agente (AGENT)...")
|
||||||
|
token, user = await login("agente@aduanasoft.com", "Agente123!")
|
||||||
|
if token and user:
|
||||||
|
print(f" ✅ Login exitoso - Role: {user['role']}, Tenant: {user['tenant_id']}")
|
||||||
|
status, response = await get_ticket(TICKET_ID, token, user['tenant_id'])
|
||||||
|
if status == 200:
|
||||||
|
print(f" ✅ Ticket obtenido correctamente")
|
||||||
|
else:
|
||||||
|
print(f" ❌ Error {status}: {response}")
|
||||||
|
|
||||||
|
print("\n" + "=" * 60)
|
||||||
|
print("Nota: Este ticket fue creado por test_user@example.com")
|
||||||
|
print("Ahora todos los usuarios del mismo tenant deberían poder verlo")
|
||||||
|
print("según su rol (admins y agentes: todos, clientes: solo propios)")
|
||||||
|
print("=" * 60)
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
asyncio.run(test_access())
|
||||||
@@ -1,67 +0,0 @@
|
|||||||
"""
|
|
||||||
Script para actualizar el password del usuario admin
|
|
||||||
Ejecutar: python fix_admin_password.py
|
|
||||||
"""
|
|
||||||
import asyncio
|
|
||||||
import sys
|
|
||||||
from sqlalchemy import select, update
|
|
||||||
from passlib.context import CryptContext
|
|
||||||
|
|
||||||
# Importar desde el proyecto
|
|
||||||
sys.path.insert(0, '/app')
|
|
||||||
from app.core.database import AsyncSessionLocal
|
|
||||||
from app.models.user import User
|
|
||||||
|
|
||||||
# Configurar passlib igual que en security.py
|
|
||||||
pwd_context = CryptContext(
|
|
||||||
schemes=["argon2", "bcrypt"],
|
|
||||||
deprecated="auto",
|
|
||||||
argon2__memory_cost=65536,
|
|
||||||
argon2__time_cost=3,
|
|
||||||
argon2__parallelism=4,
|
|
||||||
)
|
|
||||||
|
|
||||||
async def fix_admin_password():
|
|
||||||
"""Actualizar password del admin a 'admin123'"""
|
|
||||||
|
|
||||||
# Generar hash del password
|
|
||||||
new_password = "admin123"
|
|
||||||
password_hash = pwd_context.hash(new_password)
|
|
||||||
|
|
||||||
print(f"Nuevo hash generado para password: {new_password}")
|
|
||||||
print(f"Hash: {password_hash[:50]}...")
|
|
||||||
|
|
||||||
async with AsyncSessionLocal() as session:
|
|
||||||
try:
|
|
||||||
# Buscar usuario admin
|
|
||||||
result = await session.execute(
|
|
||||||
select(User).where(User.email == "admin@aduanasoft.com")
|
|
||||||
)
|
|
||||||
user = result.scalar_one_or_none()
|
|
||||||
|
|
||||||
if not user:
|
|
||||||
print("❌ Usuario admin no encontrado")
|
|
||||||
return
|
|
||||||
|
|
||||||
print(f"✅ Usuario encontrado: {user.email} (ID: {user.id})")
|
|
||||||
|
|
||||||
# Actualizar password
|
|
||||||
user.password_hash = password_hash
|
|
||||||
|
|
||||||
await session.commit()
|
|
||||||
|
|
||||||
print("✅ Password actualizado exitosamente")
|
|
||||||
print(f" Email: admin@aduanasoft.com")
|
|
||||||
print(f" Password: admin123")
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
await session.rollback()
|
|
||||||
print(f"❌ Error: {e}")
|
|
||||||
raise
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
print("=" * 60)
|
|
||||||
print("ACTUALIZAR PASSWORD DEL ADMIN")
|
|
||||||
print("=" * 60)
|
|
||||||
asyncio.run(fix_admin_password())
|
|
||||||
print("=" * 60)
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@servicemanager/client-frontend",
|
"name": "@servicemanager/client-frontend",
|
||||||
"version": "0.1.0",
|
"version": "1.5.1",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@servicemanager/internal-frontend",
|
"name": "@servicemanager/internal-frontend",
|
||||||
"version": "0.1.0",
|
"version": "1.5.1",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -25,11 +25,15 @@ async function request<T>(endpoint: string, options: RequestOptions = {}): Promi
|
|||||||
|
|
||||||
const authState = get(auth);
|
const authState = get(auth);
|
||||||
const token = authState.token || (typeof window !== 'undefined' ? localStorage.getItem('internal_auth_token') : null);
|
const token = authState.token || (typeof window !== 'undefined' ? localStorage.getItem('internal_auth_token') : null);
|
||||||
|
const user = authState.user || (typeof window !== 'undefined' ? JSON.parse(localStorage.getItem('internal_auth_user') || 'null') : null);
|
||||||
|
|
||||||
const headers = new Headers(init.headers);
|
const headers = new Headers(init.headers);
|
||||||
if (token) {
|
if (token) {
|
||||||
headers.set('Authorization', `Bearer ${token}`);
|
headers.set('Authorization', `Bearer ${token}`);
|
||||||
}
|
}
|
||||||
|
if (user && user.tenant_id) {
|
||||||
|
headers.set('X-Tenant-ID', user.tenant_id);
|
||||||
|
}
|
||||||
if (!headers.has('Content-Type')) {
|
if (!headers.has('Content-Type')) {
|
||||||
headers.set('Content-Type', 'application/json');
|
headers.set('Content-Type', 'application/json');
|
||||||
}
|
}
|
||||||
@@ -65,11 +69,15 @@ async function request<T>(endpoint: string, options: RequestOptions = {}): Promi
|
|||||||
async function downloadFile(endpoint: string, filename: string): Promise<void> {
|
async function downloadFile(endpoint: string, filename: string): Promise<void> {
|
||||||
const authState = get(auth);
|
const authState = get(auth);
|
||||||
const token = authState.token || (typeof window !== 'undefined' ? localStorage.getItem('internal_auth_token') : null);
|
const token = authState.token || (typeof window !== 'undefined' ? localStorage.getItem('internal_auth_token') : null);
|
||||||
|
const user = authState.user || (typeof window !== 'undefined' ? JSON.parse(localStorage.getItem('internal_auth_user') || 'null') : null);
|
||||||
|
|
||||||
const headers = new Headers();
|
const headers = new Headers();
|
||||||
if (token) {
|
if (token) {
|
||||||
headers.set('Authorization', `Bearer ${token}`);
|
headers.set('Authorization', `Bearer ${token}`);
|
||||||
}
|
}
|
||||||
|
if (user && user.tenant_id) {
|
||||||
|
headers.set('X-Tenant-ID', user.tenant_id);
|
||||||
|
}
|
||||||
|
|
||||||
const response = await fetch(`${API_BASE}${endpoint}`, {
|
const response = await fetch(`${API_BASE}${endpoint}`, {
|
||||||
method: 'GET',
|
method: 'GET',
|
||||||
|
|||||||
262
scripts/db_utils.py
Normal file
262
scripts/db_utils.py
Normal file
@@ -0,0 +1,262 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""
|
||||||
|
Database Utilities Script
|
||||||
|
Herramientas administrativas para gestión de base de datos
|
||||||
|
|
||||||
|
Uso:
|
||||||
|
python scripts/db_utils.py list-users [--tenant-id UUID]
|
||||||
|
python scripts/db_utils.py check-user EMAIL
|
||||||
|
python scripts/db_utils.py reset-password EMAIL [--password PASSWORD]
|
||||||
|
python scripts/db_utils.py list-tickets [--tenant-id UUID] [--limit N]
|
||||||
|
python scripts/db_utils.py check-ticket TICKET_ID
|
||||||
|
|
||||||
|
Ejemplos:
|
||||||
|
python scripts/db_utils.py list-users
|
||||||
|
python scripts/db_utils.py check-user admin@example.com
|
||||||
|
python scripts/db_utils.py reset-password admin@example.com --password admin123
|
||||||
|
python scripts/db_utils.py list-tickets --limit 10
|
||||||
|
"""
|
||||||
|
|
||||||
|
import asyncio
|
||||||
|
import sys
|
||||||
|
import os
|
||||||
|
from typing import Optional
|
||||||
|
import argparse
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
# Agregar backend al path para imports
|
||||||
|
backend_path = Path(__file__).parent.parent / "backend"
|
||||||
|
sys.path.insert(0, str(backend_path))
|
||||||
|
|
||||||
|
from sqlalchemy import select
|
||||||
|
from sqlalchemy.ext.asyncio import create_async_engine, AsyncSession
|
||||||
|
from sqlalchemy.orm import sessionmaker
|
||||||
|
|
||||||
|
from app.models.user import User
|
||||||
|
from app.models.ticket import Ticket
|
||||||
|
from app.models.tenant import Tenant
|
||||||
|
from app.core.security import SecurityUtils
|
||||||
|
|
||||||
|
|
||||||
|
class DBUtils:
|
||||||
|
"""Utilidades de gestión de base de datos"""
|
||||||
|
|
||||||
|
def __init__(self, database_url: Optional[str] = None):
|
||||||
|
self.database_url = database_url or os.getenv(
|
||||||
|
'DATABASE_URL',
|
||||||
|
'postgresql+asyncpg://postgres:postgres@localhost:5432/servicemanager'
|
||||||
|
)
|
||||||
|
self.engine = create_async_engine(self.database_url, echo=False)
|
||||||
|
self.async_session = sessionmaker(
|
||||||
|
self.engine,
|
||||||
|
class_=AsyncSession,
|
||||||
|
expire_on_commit=False
|
||||||
|
)
|
||||||
|
|
||||||
|
async def list_users(self, tenant_id: Optional[str] = None):
|
||||||
|
"""Listar todos los usuarios"""
|
||||||
|
async with self.async_session() as session:
|
||||||
|
query = select(User)
|
||||||
|
if tenant_id:
|
||||||
|
query = query.where(User.tenant_id == tenant_id)
|
||||||
|
|
||||||
|
result = await session.execute(query)
|
||||||
|
users = result.scalars().all()
|
||||||
|
|
||||||
|
if not users:
|
||||||
|
print("❌ No se encontraron usuarios")
|
||||||
|
return
|
||||||
|
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
print(f"📋 USUARIOS ({len(users)} encontrados)")
|
||||||
|
print(f"{'='*80}\n")
|
||||||
|
|
||||||
|
for user in users:
|
||||||
|
print(f" Email: {user.email}")
|
||||||
|
print(f" Role: {user.role}")
|
||||||
|
print(f" ID: {user.id}")
|
||||||
|
print(f" Tenant ID: {user.tenant_id}")
|
||||||
|
print(f" Activo: {'✅' if user.is_active else '❌'}")
|
||||||
|
print(f" {'-'*76}")
|
||||||
|
|
||||||
|
async def check_user(self, email: str):
|
||||||
|
"""Verificar información de un usuario específico"""
|
||||||
|
async with self.async_session() as session:
|
||||||
|
result = await session.execute(
|
||||||
|
select(User).where(User.email == email)
|
||||||
|
)
|
||||||
|
user = result.scalar_one_or_none()
|
||||||
|
|
||||||
|
if not user:
|
||||||
|
print(f"❌ Usuario '{email}' no encontrado")
|
||||||
|
return
|
||||||
|
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
print(f"👤 INFORMACIÓN DEL USUARIO")
|
||||||
|
print(f"{'='*80}\n")
|
||||||
|
print(f" Email: {user.email}")
|
||||||
|
print(f" Nombre: {user.first_name} {user.last_name}")
|
||||||
|
print(f" Role: {user.role}")
|
||||||
|
print(f" ID: {user.id}")
|
||||||
|
print(f" Tenant ID: {user.tenant_id}")
|
||||||
|
print(f" Activo: {'✅' if user.is_active else '❌'}")
|
||||||
|
print(f" 2FA: {'✅ Habilitado' if user.totp_secret else '❌ Deshabilitado'}")
|
||||||
|
print(f" Creado: {user.created_at}")
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
|
||||||
|
async def reset_password(self, email: str, new_password: str = "admin123"):
|
||||||
|
"""Resetear contraseña de un usuario"""
|
||||||
|
async with self.async_session() as session:
|
||||||
|
result = await session.execute(
|
||||||
|
select(User).where(User.email == email)
|
||||||
|
)
|
||||||
|
user = result.scalar_one_or_none()
|
||||||
|
|
||||||
|
if not user:
|
||||||
|
print(f"❌ Usuario '{email}' no encontrado")
|
||||||
|
return
|
||||||
|
|
||||||
|
# Hash nueva contraseña
|
||||||
|
password_hash = SecurityUtils.hash_password(new_password)
|
||||||
|
user.password_hash = password_hash
|
||||||
|
|
||||||
|
try:
|
||||||
|
await session.commit()
|
||||||
|
print(f"\n✅ Contraseña actualizada exitosamente")
|
||||||
|
print(f" Usuario: {email}")
|
||||||
|
print(f" Nueva contraseña: {new_password}")
|
||||||
|
print(f"\n⚠️ IMPORTANTE: Cambia esta contraseña después del primer login")
|
||||||
|
except Exception as e:
|
||||||
|
await session.rollback()
|
||||||
|
print(f"❌ Error al actualizar contraseña: {e}")
|
||||||
|
|
||||||
|
async def list_tickets(self, tenant_id: Optional[str] = None, limit: int = 20):
|
||||||
|
"""Listar tickets"""
|
||||||
|
async with self.async_session() as session:
|
||||||
|
query = select(Ticket).order_by(Ticket.created_at.desc()).limit(limit)
|
||||||
|
if tenant_id:
|
||||||
|
query = query.where(Ticket.tenant_id == tenant_id)
|
||||||
|
|
||||||
|
result = await session.execute(query)
|
||||||
|
tickets = result.scalars().all()
|
||||||
|
|
||||||
|
if not tickets:
|
||||||
|
print("❌ No se encontraron tickets")
|
||||||
|
return
|
||||||
|
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
print(f"🎫 TICKETS ({len(tickets)} encontrados, límite: {limit})")
|
||||||
|
print(f"{'='*80}\n")
|
||||||
|
|
||||||
|
for ticket in tickets:
|
||||||
|
print(f" {ticket.ticket_number} | {ticket.status} | {ticket.priority}")
|
||||||
|
print(f" Asunto: {ticket.subject}")
|
||||||
|
print(f" ID: {ticket.id}")
|
||||||
|
print(f" Tenant: {ticket.tenant_id}")
|
||||||
|
print(f" Creado: {ticket.created_at}")
|
||||||
|
print(f" {'-'*76}")
|
||||||
|
|
||||||
|
async def check_ticket(self, ticket_id: str):
|
||||||
|
"""Verificar información de un ticket específico"""
|
||||||
|
async with self.async_session() as session:
|
||||||
|
result = await session.execute(
|
||||||
|
select(Ticket).where(Ticket.id == ticket_id)
|
||||||
|
)
|
||||||
|
ticket = result.scalar_one_or_none()
|
||||||
|
|
||||||
|
if not ticket:
|
||||||
|
print(f"❌ Ticket '{ticket_id}' no encontrado")
|
||||||
|
return
|
||||||
|
|
||||||
|
# Obtener creador
|
||||||
|
creator_result = await session.execute(
|
||||||
|
select(User).where(User.id == ticket.created_by)
|
||||||
|
)
|
||||||
|
creator = creator_result.scalar_one_or_none()
|
||||||
|
|
||||||
|
# Obtener asignado
|
||||||
|
assigned = None
|
||||||
|
if ticket.assigned_to:
|
||||||
|
assigned_result = await session.execute(
|
||||||
|
select(User).where(User.id == ticket.assigned_to)
|
||||||
|
)
|
||||||
|
assigned = assigned_result.scalar_one_or_none()
|
||||||
|
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
print(f"🎫 INFORMACIÓN DEL TICKET")
|
||||||
|
print(f"{'='*80}\n")
|
||||||
|
print(f" Número: {ticket.ticket_number}")
|
||||||
|
print(f" Asunto: {ticket.subject}")
|
||||||
|
print(f" Estado: {ticket.status}")
|
||||||
|
print(f" Prioridad: {ticket.priority}")
|
||||||
|
print(f" ID: {ticket.id}")
|
||||||
|
print(f" Tenant ID: {ticket.tenant_id}")
|
||||||
|
if creator:
|
||||||
|
print(f" Creado por: {creator.email} ({creator.role})")
|
||||||
|
if assigned:
|
||||||
|
print(f" Asignado a: {assigned.email} ({assigned.role})")
|
||||||
|
print(f" Creado: {ticket.created_at}")
|
||||||
|
print(f" Actualizado: {ticket.updated_at}")
|
||||||
|
print(f"\n{'='*80}")
|
||||||
|
|
||||||
|
async def close(self):
|
||||||
|
"""Cerrar conexión"""
|
||||||
|
await self.engine.dispose()
|
||||||
|
|
||||||
|
|
||||||
|
async def main():
|
||||||
|
parser = argparse.ArgumentParser(
|
||||||
|
description='Utilidades de gestión de base de datos',
|
||||||
|
formatter_class=argparse.RawDescriptionHelpFormatter,
|
||||||
|
epilog=__doc__
|
||||||
|
)
|
||||||
|
|
||||||
|
subparsers = parser.add_subparsers(dest='command', help='Comando a ejecutar')
|
||||||
|
|
||||||
|
# list-users
|
||||||
|
list_users_parser = subparsers.add_parser('list-users', help='Listar usuarios')
|
||||||
|
list_users_parser.add_argument('--tenant-id', help='Filtrar por tenant ID')
|
||||||
|
|
||||||
|
# check-user
|
||||||
|
check_user_parser = subparsers.add_parser('check-user', help='Verificar usuario')
|
||||||
|
check_user_parser.add_argument('email', help='Email del usuario')
|
||||||
|
|
||||||
|
# reset-password
|
||||||
|
reset_password_parser = subparsers.add_parser('reset-password', help='Resetear contraseña')
|
||||||
|
reset_password_parser.add_argument('email', help='Email del usuario')
|
||||||
|
reset_password_parser.add_argument('--password', default='admin123', help='Nueva contraseña')
|
||||||
|
|
||||||
|
# list-tickets
|
||||||
|
list_tickets_parser = subparsers.add_parser('list-tickets', help='Listar tickets')
|
||||||
|
list_tickets_parser.add_argument('--tenant-id', help='Filtrar por tenant ID')
|
||||||
|
list_tickets_parser.add_argument('--limit', type=int, default=20, help='Límite de resultados')
|
||||||
|
|
||||||
|
# check-ticket
|
||||||
|
check_ticket_parser = subparsers.add_parser('check-ticket', help='Verificar ticket')
|
||||||
|
check_ticket_parser.add_argument('ticket_id', help='ID del ticket')
|
||||||
|
|
||||||
|
args = parser.parse_args()
|
||||||
|
|
||||||
|
if not args.command:
|
||||||
|
parser.print_help()
|
||||||
|
return
|
||||||
|
|
||||||
|
utils = DBUtils()
|
||||||
|
|
||||||
|
try:
|
||||||
|
if args.command == 'list-users':
|
||||||
|
await utils.list_users(args.tenant_id)
|
||||||
|
elif args.command == 'check-user':
|
||||||
|
await utils.check_user(args.email)
|
||||||
|
elif args.command == 'reset-password':
|
||||||
|
await utils.reset_password(args.email, args.password)
|
||||||
|
elif args.command == 'list-tickets':
|
||||||
|
await utils.list_tickets(args.tenant_id, args.limit)
|
||||||
|
elif args.command == 'check-ticket':
|
||||||
|
await utils.check_ticket(args.ticket_id)
|
||||||
|
finally:
|
||||||
|
await utils.close()
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
asyncio.run(main())
|
||||||
Binary file not shown.
@@ -1,34 +0,0 @@
|
|||||||
# Test de Attachments API
|
|
||||||
# Ejecutar desde PowerShell
|
|
||||||
|
|
||||||
# 1. Login
|
|
||||||
$body = '{"email":"admin@aduanasoft.com","password":"admin123","tenant_slug":"aduanasoft"}'
|
|
||||||
$login = Invoke-RestMethod -Uri "http://localhost:8000/v1/auth/login" -Method POST -Body $body -ContentType "application/json"
|
|
||||||
|
|
||||||
$token = $login.data.access_token
|
|
||||||
$tenantId = $login.data.user.tenant_id
|
|
||||||
|
|
||||||
$headers = @{
|
|
||||||
"Authorization" = "Bearer $token"
|
|
||||||
"X-Tenant-ID" = $tenantId
|
|
||||||
}
|
|
||||||
|
|
||||||
Write-Host "Autenticacion exitosa" -ForegroundColor Green
|
|
||||||
|
|
||||||
# 2. Listar tickets
|
|
||||||
$tickets = Invoke-RestMethod -Uri "http://localhost:8000/v1/tickets" -Headers $headers
|
|
||||||
$ticketId = $tickets.data[0].id
|
|
||||||
|
|
||||||
Write-Host "Ticket ID obtenido: $ticketId" -ForegroundColor Green
|
|
||||||
|
|
||||||
# 3. Listar attachments del ticket
|
|
||||||
$attachments = Invoke-RestMethod -Uri "http://localhost:8000/v1/tickets/$ticketId/attachments" -Headers $headers
|
|
||||||
|
|
||||||
Write-Host "Attachments listados: $($attachments.Count) encontrados" -ForegroundColor Green
|
|
||||||
|
|
||||||
if ($attachments.Count -gt 0) {
|
|
||||||
$attachments | Format-Table id, original_filename, file_size, created_at
|
|
||||||
}
|
|
||||||
|
|
||||||
Write-Host ""
|
|
||||||
Write-Host "TEST COMPLETADO" -ForegroundColor Cyan
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
# Test script para attachments endpoint
|
|
||||||
Write-Host "=== Testing Attachments Endpoint ===" -ForegroundColor Cyan
|
|
||||||
|
|
||||||
# 1. Login
|
|
||||||
$body = '{"email":"admin@aduanasoft.com","password":"admin123","tenant_slug":"aduanasoft"}'
|
|
||||||
try {
|
|
||||||
$login = Invoke-RestMethod -Uri "http://localhost:8000/v1/auth/login" -Method POST -Body $body -ContentType "application/json"
|
|
||||||
Write-Host "[OK] Login exitoso" -ForegroundColor Green
|
|
||||||
|
|
||||||
$token = $login.access_token
|
|
||||||
$tenantId = $login.user.tenant_id
|
|
||||||
|
|
||||||
Write-Host "Token: $($token.Substring(0,20))..." -ForegroundColor Gray
|
|
||||||
Write-Host "Tenant ID: $tenantId" -ForegroundColor Gray
|
|
||||||
|
|
||||||
# 2. Test attachments endpoint
|
|
||||||
$headers = @{
|
|
||||||
"Authorization" = "Bearer $token"
|
|
||||||
"X-Tenant-ID" = $tenantId
|
|
||||||
}
|
|
||||||
|
|
||||||
$url = "http://localhost:8000/v1/tickets/68eaf0fe-b5c3-4d42-9b36-895b439be583/attachments"
|
|
||||||
Write-Host "`nProbando GET $url" -ForegroundColor Yellow
|
|
||||||
|
|
||||||
try {
|
|
||||||
$response = Invoke-WebRequest -Uri $url -Headers $headers -Method GET
|
|
||||||
Write-Host "[OK] Status Code: $($response.StatusCode)" -ForegroundColor Green
|
|
||||||
|
|
||||||
$data = $response.Content | ConvertFrom-Json
|
|
||||||
Write-Host "[OK] Attachments encontrados: $($data.Count)" -ForegroundColor Green
|
|
||||||
|
|
||||||
if ($data.Count -gt 0) {
|
|
||||||
$data | Format-Table id, original_filename, file_size
|
|
||||||
} else {
|
|
||||||
Write-Host " (No hay attachments para este ticket)" -ForegroundColor Gray
|
|
||||||
}
|
|
||||||
|
|
||||||
} catch {
|
|
||||||
Write-Host "[ERROR] En request: $($_.Exception.Message)" -ForegroundColor Red
|
|
||||||
Write-Host "Status Code: $($_.Exception.Response.StatusCode.value__)" -ForegroundColor Red
|
|
||||||
}
|
|
||||||
|
|
||||||
} catch {
|
|
||||||
Write-Host "[ERROR] En login: $($_.Exception.Message)" -ForegroundColor Red
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user