Close the gaps between the documented contract (API-STANDARD, TENANCY, ENTITLEMENTS) and the implementation, and remove committed build artifacts. Security: - verify + process inbound webhooks (HMAC/handler verify, size limit, timestamp tolerance, idempotency via InboundEvent.external_id) - real 2FA login flow (pre-auth challenge; tokens only after verify/recovery) - wire HybridPermission into security/audit views; add API-key rotate and users/<id>/permissions|roles endpoints - tenant-scoped throttling on by default; webhook replay protection - verify MercadoPago webhook signatures - login brute-force guard, configurable password policy, real ALTCHA PoW Correctness: - apply verified billing webhooks idempotently (subscription/entitlement/ invoice/PaymentTransaction); scheduled payment lifecycle jobs - capture audit update diffs automatically; add audit retention purge - working notification retries, per-channel rate limits, log retention - pluggable virus scanner, upload-size limit, pipeline toggle - feature rollout %/environment targeting; settings-driven registrations - workflow guards (instance cap, route depth, self-assignment, clone on re-entry) - wire every previously-dead INFRASYNTH_* setting; drop truly dead ones Delivery: - README + CHANGELOG; CI format check + coverage gate - keep test media out of the tree; untrack .coverage, __pycache__, egg-info, docs/ and invoice artifacts
62 lines
3.3 KiB
Markdown
62 lines
3.3 KiB
Markdown
# Changelog
|
|
|
|
All notable changes to `infrasynth-base` are documented here.
|
|
|
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
|
|
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|
Versions are derived from Conventional Commits by `python-semantic-release`; do
|
|
not hand-pick a version (see `../AGENTS.backend-packages.md` §8).
|
|
|
|
## [Unreleased]
|
|
|
|
### Added
|
|
- **Verified inbound webhooks.** `InboundReceiveView` now enforces the shared
|
|
HMAC signature (or a provider-specific `BaseInboundHandler.verify`), payload
|
|
size limits, timestamp tolerance, and idempotent re-delivery via
|
|
`InboundEvent.external_id`; verified events are dispatched to the endpoint's
|
|
handler through `process_inbound_event` and marked `is_verified`/`is_processed`.
|
|
- **Working 2FA login flow.** Login now challenges users with a configured
|
|
second factor (pre-auth session + cookie) and only mints JWT cookies after
|
|
`2fa/verify/` (or `2fa/recovery/`) succeeds; `TwoFactorMiddleware` guards the
|
|
session-authenticated surface.
|
|
- **Permission enforcement.** `HybridPermission` / `require_permission` are now
|
|
wired into security and audit viewsets with documented codenames and a
|
|
tenant-owner bypass; `HybridPermission` takes tenant ownership into account.
|
|
- **API-key rotation** (`/api/v1/auth/api-keys/<id>/rotate/`) and
|
|
**user permission/role endpoints** (`/api/v1/auth/users/<id>/permissions/`,
|
|
`/users/<id>/roles/`).
|
|
- **Billing webhook processing.** Verified events are applied idempotently to
|
|
subscriptions, entitlements, invoices, and `PaymentTransaction` rows; replay
|
|
protection via `assert_fresh_webhook`.
|
|
- **Scheduled billing lifecycle** (`sync_subscriptions`,
|
|
`advance_entitlement_lifecycle`, `expire_entitlements`,
|
|
`generate_renewal_invoices`) and **notification retries** + log retention, all
|
|
wired into `CELERY_BEAT_SCHEDULE`.
|
|
- **Audit update diffs** are captured automatically via a `pre_save` snapshot;
|
|
**audit retention purge** task added.
|
|
- **Feature rollout** (`rollout_percentage`, `environments`,
|
|
`ROLLOUT_HASH_ALGORITHM`) and settings-driven flag registration.
|
|
- **Login brute-force guard** (per-credential rate limit + IP blacklist),
|
|
**configurable password policy** (`PasswordPolicyValidator`), and a correctly
|
|
enforced **ALTCHA** proof-of-work.
|
|
- **File hardening:** global upload-size limit, processing-pipeline toggle, and
|
|
a pluggable virus scanner (`noop`/`clamav`/custom) with `REQUIRE_VIRUS_SCAN`.
|
|
- **Workflow guards:** `MAX_INSTANCES_PER_WORKFLOW`, `ROUTE_MAX_DEPTH`,
|
|
`ALLOW_SELF_ASSIGNMENT`, `AUTO_CLONE_ASSIGNEES_ON_REENTRY`.
|
|
- **MercadoPago** webhook signature verification.
|
|
- `README.md`, `CHANGELOG.md`, and a CI format/coverage gate.
|
|
|
|
### Changed
|
|
- `TenantRateThrottle` and `RateLimitHeadersMiddleware` are active by default,
|
|
producing `X-RateLimit-*` headers on API responses.
|
|
- `EntitlementService` treats `past_due` as within grace (entitled) and merges
|
|
entitlement-level feature overrides over `plan.features`; `require_limit`
|
|
raises `ENTITLEMENT_LIMIT_REACHED`.
|
|
- `FeatureService` resolves the current tenant automatically and honors rollout
|
|
and environment targeting.
|
|
|
|
### Fixed
|
|
- API-key authentication no longer leaks tenant context.
|
|
- `EventRegistry.emit` no longer uses `__import__` and honors
|
|
`DELIVERY_BACKEND`.
|
|
- Test media artifacts no longer accumulate in the repository tree.
|