infrasynth-backend-kit/infrasynth/audit/migrations/0001_initial.py
jcv-dev 551b42eab5 feat: production-hardening pass across the kit
Close the gaps between the documented contract (API-STANDARD, TENANCY,
ENTITLEMENTS) and the implementation, and remove committed build artifacts.

Security:
- verify + process inbound webhooks (HMAC/handler verify, size limit,
  timestamp tolerance, idempotency via InboundEvent.external_id)
- real 2FA login flow (pre-auth challenge; tokens only after verify/recovery)
- wire HybridPermission into security/audit views; add API-key rotate and
  users/<id>/permissions|roles endpoints
- tenant-scoped throttling on by default; webhook replay protection
- verify MercadoPago webhook signatures
- login brute-force guard, configurable password policy, real ALTCHA PoW

Correctness:
- apply verified billing webhooks idempotently (subscription/entitlement/
  invoice/PaymentTransaction); scheduled payment lifecycle jobs
- capture audit update diffs automatically; add audit retention purge
- working notification retries, per-channel rate limits, log retention
- pluggable virus scanner, upload-size limit, pipeline toggle
- feature rollout %/environment targeting; settings-driven registrations
- workflow guards (instance cap, route depth, self-assignment, clone on re-entry)
- wire every previously-dead INFRASYNTH_* setting; drop truly dead ones

Delivery:
- README + CHANGELOG; CI format check + coverage gate
- keep test media out of the tree; untrack .coverage, __pycache__,
  egg-info, docs/ and invoice artifacts
2026-09-24 10:41:21 -05:00

127 lines
5.5 KiB
Python

# Generated by Django 5.2.17 on 2026-09-24 14:10
import django.db.models.deletion
from django.conf import settings
from django.db import migrations, models
class Migration(migrations.Migration):
initial = True
dependencies = [
("tenancy", "0001_initial"),
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
]
operations = [
migrations.CreateModel(
name="APIInteractionLog",
fields=[
("id", models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name="ID")),
("method", models.CharField(db_index=True, max_length=10)),
("path", models.CharField(db_index=True, max_length=500)),
("status_code", models.PositiveSmallIntegerField(db_index=True)),
("request_body", models.JSONField(blank=True, null=True)),
("response_body", models.JSONField(blank=True, null=True)),
("ip_address", models.GenericIPAddressField(null=True)),
("duration_ms", models.PositiveIntegerField()),
("timestamp", models.DateTimeField(auto_now_add=True, db_index=True)),
("request_id", models.CharField(db_index=True, max_length=64)),
("user_agent", models.TextField(blank=True, default="")),
(
"actor",
models.ForeignKey(
null=True, on_delete=django.db.models.deletion.SET_NULL, to=settings.AUTH_USER_MODEL
),
),
(
"tenant",
models.ForeignKey(
blank=True,
null=True,
on_delete=django.db.models.deletion.CASCADE,
related_name="+",
to="tenancy.tenant",
),
),
],
options={
"db_table": "audit_api_interaction_log",
"indexes": [models.Index(fields=["tenant_id", "timestamp"], name="audit_api_i_tenant__e12b1e_idx")],
},
),
migrations.CreateModel(
name="ModelChangeLog",
fields=[
("id", models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name="ID")),
("model_label", models.CharField(db_index=True, max_length=200)),
("object_id", models.CharField(db_index=True, max_length=200)),
(
"action",
models.CharField(
choices=[("create", "create"), ("update", "update"), ("delete", "delete")], max_length=10
),
),
("changes", models.JSONField(help_text="Dict with {field_name: [old_value, new_value]}")),
("timestamp", models.DateTimeField(auto_now_add=True, db_index=True)),
("request_id", models.CharField(help_text="UUID for request correlation", max_length=64)),
(
"actor",
models.ForeignKey(
null=True, on_delete=django.db.models.deletion.SET_NULL, to=settings.AUTH_USER_MODEL
),
),
(
"tenant",
models.ForeignKey(
blank=True,
help_text="Null = platform action; set for tenant-scoped actions.",
null=True,
on_delete=django.db.models.deletion.CASCADE,
related_name="+",
to="tenancy.tenant",
),
),
],
options={
"db_table": "audit_model_change_log",
"indexes": [
models.Index(
fields=["tenant_id", "model_label", "object_id"], name="audit_model_tenant__a189da_idx"
),
models.Index(fields=["tenant_id", "timestamp"], name="audit_model_tenant__3c17f6_idx"),
],
},
),
migrations.CreateModel(
name="SecurityEvent",
fields=[
("id", models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name="ID")),
("event_type", models.CharField(db_index=True, max_length=50)),
("ip_address", models.GenericIPAddressField(null=True)),
("metadata", models.JSONField(default=dict)),
("timestamp", models.DateTimeField(auto_now_add=True, db_index=True)),
("request_id", models.CharField(max_length=64)),
(
"actor",
models.ForeignKey(
null=True, on_delete=django.db.models.deletion.SET_NULL, to=settings.AUTH_USER_MODEL
),
),
(
"tenant",
models.ForeignKey(
blank=True,
null=True,
on_delete=django.db.models.deletion.CASCADE,
related_name="+",
to="tenancy.tenant",
),
),
],
options={
"db_table": "audit_security_event",
"indexes": [models.Index(fields=["tenant_id", "event_type"], name="audit_secur_tenant__64d72b_idx")],
},
),
]