infrasynth-backend-kit/CHANGELOG.md
jcv-dev 5df0be1f5c feat: uniform extensibility across every module
Close the remaining places where an extension point was hardcoded, and
expose a stable public import surface for every app.

- files: register_storage_backend(...) / STORAGE_BACKENDS[name]["CLASS"];
  unknown backends now fail loudly instead of silently using local
- files: PipelineStepRegistry + @pipeline_step; PIPELINE_EXECUTOR setting
- billing: INVOICE_PDF_BUILDER setting
- security: TWO_FACTOR_SERVICE / TWO_FACTOR_RECOVERY_SERVICE settings
- all app packages expose lazy public exports (PEP 562); infrasynth.shared
  re-exports its primitives eagerly
- README documents the per-module extension-point table
- tests/test_extensibility.py pins each hook plus the public surface
2026-09-24 11:08:08 -05:00

4.9 KiB

Changelog

All notable changes to infrasynth-base are documented here.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Versions are derived from Conventional Commits by python-semantic-release; do not hand-pick a version (see ../AGENTS.backend-packages.md §8).

[Unreleased]

Added

  • Uniform extensibility across every module. Storage backends can be registered (register_storage_backend or STORAGE_BACKENDS[name]["CLASS"]), pipeline steps via PipelineStepRegistry/@pipeline_step, the pipeline executor via PIPELINE_EXECUTOR, the invoice PDF via INVOICE_PDF_BUILDER, and the 2FA method via TWO_FACTOR_SERVICE/TWO_FACTOR_RECOVERY_SERVICE — all through settings/registries, with no kit edits. The other modules already resolved extensions through dotted paths (gateways, channels, tasks, inbound handlers, scanner) and are now documented as such.
  • Lazy public API per app package. from infrasynth.security import AuthorizationService, from infrasynth.billing import EntitlementService, etc. resolve via PEP 562 without importing models before the app registry is ready; infrasynth.shared re-exports its primitives eagerly.
  • Composable per-endpoint gates (infrasynth.gates): declare infrasynth_gates = [...] (and/or @gated(...) on a viewset action) with TwoFactorGate, AltchaGate, EntitlementGate, FeatureGate, PermissionGate, or a custom Gate. Access is evaluated per endpoint, the default is "gate nothing", and denials raise the correct namespaced error (AUTH_2FA_REQUIRED, ENTITLEMENT_PLAN_UPGRADE_REQUIRED, VALIDATION_ALTCHA_REQUIRED, …). GatePermission is a default permission class and the kit's HybridPermission evaluates declared gates too.
  • 2fa JWT claim minted only after successful verification and preserved across workspace selection, so TwoFactorGate works for multi-workspace users.
  • Verified inbound webhooks. InboundReceiveView now enforces the shared HMAC signature (or a provider-specific BaseInboundHandler.verify), payload size limits, timestamp tolerance, and idempotent re-delivery via InboundEvent.external_id; verified events are dispatched to the endpoint's handler through process_inbound_event and marked is_verified/is_processed.
  • Working 2FA login flow. Login now challenges users with a configured second factor (pre-auth session + cookie) and only mints JWT cookies after 2fa/verify/ (or 2fa/recovery/) succeeds; TwoFactorMiddleware guards the session-authenticated surface.
  • Permission enforcement. HybridPermission / require_permission are now wired into security and audit viewsets with documented codenames and a tenant-owner bypass; HybridPermission takes tenant ownership into account.
  • API-key rotation (/api/v1/auth/api-keys/<id>/rotate/) and user permission/role endpoints (/api/v1/auth/users/<id>/permissions/, /users/<id>/roles/).
  • Billing webhook processing. Verified events are applied idempotently to subscriptions, entitlements, invoices, and PaymentTransaction rows; replay protection via assert_fresh_webhook.
  • Scheduled billing lifecycle (sync_subscriptions, advance_entitlement_lifecycle, expire_entitlements, generate_renewal_invoices) and notification retries + log retention, all wired into CELERY_BEAT_SCHEDULE.
  • Audit update diffs are captured automatically via a pre_save snapshot; audit retention purge task added.
  • Feature rollout (rollout_percentage, environments, ROLLOUT_HASH_ALGORITHM) and settings-driven flag registration.
  • Login brute-force guard (per-credential rate limit + IP blacklist), configurable password policy (PasswordPolicyValidator), and a correctly enforced ALTCHA proof-of-work.
  • File hardening: global upload-size limit, processing-pipeline toggle, and a pluggable virus scanner (noop/clamav/custom) with REQUIRE_VIRUS_SCAN.
  • Workflow guards: MAX_INSTANCES_PER_WORKFLOW, ROUTE_MAX_DEPTH, ALLOW_SELF_ASSIGNMENT, AUTO_CLONE_ASSIGNEES_ON_REENTRY.
  • MercadoPago webhook signature verification.
  • README.md, CHANGELOG.md, and a CI format/coverage gate.

Changed

  • TenantRateThrottle and RateLimitHeadersMiddleware are active by default, producing X-RateLimit-* headers on API responses.
  • EntitlementService treats past_due as within grace (entitled) and merges entitlement-level feature overrides over plan.features; require_limit raises ENTITLEMENT_LIMIT_REACHED.
  • FeatureService resolves the current tenant automatically and honors rollout and environment targeting.

Fixed

  • API-key authentication no longer leaks tenant context.
  • EventRegistry.emit no longer uses __import__ and honors DELIVERY_BACKEND.
  • Test media artifacts no longer accumulate in the repository tree.