infrasynth-backend-kit/CHANGELOG.md
jcv-dev 551b42eab5 feat: production-hardening pass across the kit
Close the gaps between the documented contract (API-STANDARD, TENANCY,
ENTITLEMENTS) and the implementation, and remove committed build artifacts.

Security:
- verify + process inbound webhooks (HMAC/handler verify, size limit,
  timestamp tolerance, idempotency via InboundEvent.external_id)
- real 2FA login flow (pre-auth challenge; tokens only after verify/recovery)
- wire HybridPermission into security/audit views; add API-key rotate and
  users/<id>/permissions|roles endpoints
- tenant-scoped throttling on by default; webhook replay protection
- verify MercadoPago webhook signatures
- login brute-force guard, configurable password policy, real ALTCHA PoW

Correctness:
- apply verified billing webhooks idempotently (subscription/entitlement/
  invoice/PaymentTransaction); scheduled payment lifecycle jobs
- capture audit update diffs automatically; add audit retention purge
- working notification retries, per-channel rate limits, log retention
- pluggable virus scanner, upload-size limit, pipeline toggle
- feature rollout %/environment targeting; settings-driven registrations
- workflow guards (instance cap, route depth, self-assignment, clone on re-entry)
- wire every previously-dead INFRASYNTH_* setting; drop truly dead ones

Delivery:
- README + CHANGELOG; CI format check + coverage gate
- keep test media out of the tree; untrack .coverage, __pycache__,
  egg-info, docs/ and invoice artifacts
2026-09-24 10:41:21 -05:00

3.3 KiB

Changelog

All notable changes to infrasynth-base are documented here.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Versions are derived from Conventional Commits by python-semantic-release; do not hand-pick a version (see ../AGENTS.backend-packages.md §8).

[Unreleased]

Added

  • Verified inbound webhooks. InboundReceiveView now enforces the shared HMAC signature (or a provider-specific BaseInboundHandler.verify), payload size limits, timestamp tolerance, and idempotent re-delivery via InboundEvent.external_id; verified events are dispatched to the endpoint's handler through process_inbound_event and marked is_verified/is_processed.
  • Working 2FA login flow. Login now challenges users with a configured second factor (pre-auth session + cookie) and only mints JWT cookies after 2fa/verify/ (or 2fa/recovery/) succeeds; TwoFactorMiddleware guards the session-authenticated surface.
  • Permission enforcement. HybridPermission / require_permission are now wired into security and audit viewsets with documented codenames and a tenant-owner bypass; HybridPermission takes tenant ownership into account.
  • API-key rotation (/api/v1/auth/api-keys/<id>/rotate/) and user permission/role endpoints (/api/v1/auth/users/<id>/permissions/, /users/<id>/roles/).
  • Billing webhook processing. Verified events are applied idempotently to subscriptions, entitlements, invoices, and PaymentTransaction rows; replay protection via assert_fresh_webhook.
  • Scheduled billing lifecycle (sync_subscriptions, advance_entitlement_lifecycle, expire_entitlements, generate_renewal_invoices) and notification retries + log retention, all wired into CELERY_BEAT_SCHEDULE.
  • Audit update diffs are captured automatically via a pre_save snapshot; audit retention purge task added.
  • Feature rollout (rollout_percentage, environments, ROLLOUT_HASH_ALGORITHM) and settings-driven flag registration.
  • Login brute-force guard (per-credential rate limit + IP blacklist), configurable password policy (PasswordPolicyValidator), and a correctly enforced ALTCHA proof-of-work.
  • File hardening: global upload-size limit, processing-pipeline toggle, and a pluggable virus scanner (noop/clamav/custom) with REQUIRE_VIRUS_SCAN.
  • Workflow guards: MAX_INSTANCES_PER_WORKFLOW, ROUTE_MAX_DEPTH, ALLOW_SELF_ASSIGNMENT, AUTO_CLONE_ASSIGNEES_ON_REENTRY.
  • MercadoPago webhook signature verification.
  • README.md, CHANGELOG.md, and a CI format/coverage gate.

Changed

  • TenantRateThrottle and RateLimitHeadersMiddleware are active by default, producing X-RateLimit-* headers on API responses.
  • EntitlementService treats past_due as within grace (entitled) and merges entitlement-level feature overrides over plan.features; require_limit raises ENTITLEMENT_LIMIT_REACHED.
  • FeatureService resolves the current tenant automatically and honors rollout and environment targeting.

Fixed

  • API-key authentication no longer leaks tenant context.
  • EventRegistry.emit no longer uses __import__ and honors DELIVERY_BACKEND.
  • Test media artifacts no longer accumulate in the repository tree.