infrasynth-backend-kit/CHANGELOG.md
jcv-dev 21731b9887 feat(gates): composable per-endpoint gating extension API
Make access gating a first-class, pip-consumable extension point so a
consuming app can gate any of its own views behind 2FA / ALTCHA /
entitlement / feature flag / permission, or gate nothing, without editing
the kit.

- infrasynth.gates: Gate, GateResult, GatePermission, @gated and built-ins
  TwoFactorGate, AltchaGate, EntitlementGate, FeatureGate, PermissionGate;
  denials raise the correct namespaced error/status (per-endpoint, opt-in,
  default is no gating)
- mint a `2fa` JWT claim only after verification (preserved across workspace
  selection) so TwoFactorGate is meaningful for API/multi-workspace clients
- GatePermission added to DEFAULT_PERMISSION_CLASSES; HybridPermission
  evaluates declared gates so kit permissions gate automatically
- document the extension surface and stable import paths in README
2026-09-24 10:49:44 -05:00

4.1 KiB

Changelog

All notable changes to infrasynth-base are documented here.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Versions are derived from Conventional Commits by python-semantic-release; do not hand-pick a version (see ../AGENTS.backend-packages.md §8).

[Unreleased]

Added

  • Composable per-endpoint gates (infrasynth.gates): declare infrasynth_gates = [...] (and/or @gated(...) on a viewset action) with TwoFactorGate, AltchaGate, EntitlementGate, FeatureGate, PermissionGate, or a custom Gate. Access is evaluated per endpoint, the default is "gate nothing", and denials raise the correct namespaced error (AUTH_2FA_REQUIRED, ENTITLEMENT_PLAN_UPGRADE_REQUIRED, VALIDATION_ALTCHA_REQUIRED, …). GatePermission is a default permission class and the kit's HybridPermission evaluates declared gates too.
  • 2fa JWT claim minted only after successful verification and preserved across workspace selection, so TwoFactorGate works for multi-workspace users.
  • Verified inbound webhooks. InboundReceiveView now enforces the shared HMAC signature (or a provider-specific BaseInboundHandler.verify), payload size limits, timestamp tolerance, and idempotent re-delivery via InboundEvent.external_id; verified events are dispatched to the endpoint's handler through process_inbound_event and marked is_verified/is_processed.
  • Working 2FA login flow. Login now challenges users with a configured second factor (pre-auth session + cookie) and only mints JWT cookies after 2fa/verify/ (or 2fa/recovery/) succeeds; TwoFactorMiddleware guards the session-authenticated surface.
  • Permission enforcement. HybridPermission / require_permission are now wired into security and audit viewsets with documented codenames and a tenant-owner bypass; HybridPermission takes tenant ownership into account.
  • API-key rotation (/api/v1/auth/api-keys/<id>/rotate/) and user permission/role endpoints (/api/v1/auth/users/<id>/permissions/, /users/<id>/roles/).
  • Billing webhook processing. Verified events are applied idempotently to subscriptions, entitlements, invoices, and PaymentTransaction rows; replay protection via assert_fresh_webhook.
  • Scheduled billing lifecycle (sync_subscriptions, advance_entitlement_lifecycle, expire_entitlements, generate_renewal_invoices) and notification retries + log retention, all wired into CELERY_BEAT_SCHEDULE.
  • Audit update diffs are captured automatically via a pre_save snapshot; audit retention purge task added.
  • Feature rollout (rollout_percentage, environments, ROLLOUT_HASH_ALGORITHM) and settings-driven flag registration.
  • Login brute-force guard (per-credential rate limit + IP blacklist), configurable password policy (PasswordPolicyValidator), and a correctly enforced ALTCHA proof-of-work.
  • File hardening: global upload-size limit, processing-pipeline toggle, and a pluggable virus scanner (noop/clamav/custom) with REQUIRE_VIRUS_SCAN.
  • Workflow guards: MAX_INSTANCES_PER_WORKFLOW, ROUTE_MAX_DEPTH, ALLOW_SELF_ASSIGNMENT, AUTO_CLONE_ASSIGNEES_ON_REENTRY.
  • MercadoPago webhook signature verification.
  • README.md, CHANGELOG.md, and a CI format/coverage gate.

Changed

  • TenantRateThrottle and RateLimitHeadersMiddleware are active by default, producing X-RateLimit-* headers on API responses.
  • EntitlementService treats past_due as within grace (entitled) and merges entitlement-level feature overrides over plan.features; require_limit raises ENTITLEMENT_LIMIT_REACHED.
  • FeatureService resolves the current tenant automatically and honors rollout and environment targeting.

Fixed

  • API-key authentication no longer leaks tenant context.
  • EventRegistry.emit no longer uses __import__ and honors DELIVERY_BACKEND.
  • Test media artifacts no longer accumulate in the repository tree.