ef95250b7d
chore(ci): use uv for Python 3.12 (arm64) instead of actions/setup-python
CI / Tests (push) Successful in 59s
CI / Lint (push) Successful in 10s
CI / Type Check (push) Successful in 47s
2026-09-29 18:37:09 -05:00
775d7a8a13
chore(ci): move CI to Forgejo Actions, drop GitHub/Codecov references
CI / Tests (push) Failing after 1m3s
CI / Lint (push) Failing after 8s
CI / Type Check (push) Failing after 8s
CI / Docker Build (push) Has been cancelled
2026-09-29 18:01:31 -05:00
a2930426b4
feat: tenant configs, live signals, and automatic permission management
...
- infrasynth.configs: typed multi-tenant config store (registry, service,
secrets, cache) + public config_changed/config_reset signals and API
- emit the declared-but-dead signals (features flags/overrides, scheduler
task_completed/task_failed, tenancy tenant_updated, audit model_changed)
and per-model audit field exclusions
- security: permission catalog (security_permission), Django-style
model-derived AutoPermission, PermissionRegistry, RoleAssignment,
global-or-tenant Grant/Revoke, catalog API
- consolidate the permission surface: PermissionRegistry only (drop the
settings dict), IsAuthenticatedAndPermitted aliases HybridPermission,
require_permission replaced by required_permissions + require_all
- packaging: add [build-system]; add Forgejo publish workflow (.forgejo)
2026-09-29 17:06:54 -05:00
21731b9887
feat(gates): composable per-endpoint gating extension API
...
Make access gating a first-class, pip-consumable extension point so a
consuming app can gate any of its own views behind 2FA / ALTCHA /
entitlement / feature flag / permission, or gate nothing, without editing
the kit.
- infrasynth.gates: Gate, GateResult, GatePermission, @gated and built-ins
TwoFactorGate, AltchaGate, EntitlementGate, FeatureGate, PermissionGate;
denials raise the correct namespaced error/status (per-endpoint, opt-in,
default is no gating)
- mint a `2fa` JWT claim only after verification (preserved across workspace
selection) so TwoFactorGate is meaningful for API/multi-workspace clients
- GatePermission added to DEFAULT_PERMISSION_CLASSES; HybridPermission
evaluates declared gates so kit permissions gate automatically
- document the extension surface and stable import paths in README
2026-09-24 10:49:44 -05:00
551b42eab5
feat: production-hardening pass across the kit
...
Close the gaps between the documented contract (API-STANDARD, TENANCY,
ENTITLEMENTS) and the implementation, and remove committed build artifacts.
Security:
- verify + process inbound webhooks (HMAC/handler verify, size limit,
timestamp tolerance, idempotency via InboundEvent.external_id)
- real 2FA login flow (pre-auth challenge; tokens only after verify/recovery)
- wire HybridPermission into security/audit views; add API-key rotate and
users/<id>/permissions|roles endpoints
- tenant-scoped throttling on by default; webhook replay protection
- verify MercadoPago webhook signatures
- login brute-force guard, configurable password policy, real ALTCHA PoW
Correctness:
- apply verified billing webhooks idempotently (subscription/entitlement/
invoice/PaymentTransaction); scheduled payment lifecycle jobs
- capture audit update diffs automatically; add audit retention purge
- working notification retries, per-channel rate limits, log retention
- pluggable virus scanner, upload-size limit, pipeline toggle
- feature rollout %/environment targeting; settings-driven registrations
- workflow guards (instance cap, route depth, self-assignment, clone on re-entry)
- wire every previously-dead INFRASYNTH_* setting; drop truly dead ones
Delivery:
- README + CHANGELOG; CI format check + coverage gate
- keep test media out of the tree; untrack .coverage, __pycache__,
egg-info, docs/ and invoice artifacts
2026-09-24 10:41:21 -05:00
75c3c7b2c2
Lua update
2026-08-28 14:38:47 -05:00