infrasynth-backend-kit/CHANGELOG.md
jcv-dev 5df0be1f5c feat: uniform extensibility across every module
Close the remaining places where an extension point was hardcoded, and
expose a stable public import surface for every app.

- files: register_storage_backend(...) / STORAGE_BACKENDS[name]["CLASS"];
  unknown backends now fail loudly instead of silently using local
- files: PipelineStepRegistry + @pipeline_step; PIPELINE_EXECUTOR setting
- billing: INVOICE_PDF_BUILDER setting
- security: TWO_FACTOR_SERVICE / TWO_FACTOR_RECOVERY_SERVICE settings
- all app packages expose lazy public exports (PEP 562); infrasynth.shared
  re-exports its primitives eagerly
- README documents the per-module extension-point table
- tests/test_extensibility.py pins each hook plus the public surface
2026-09-24 11:08:08 -05:00

84 lines
4.9 KiB
Markdown

# Changelog
All notable changes to `infrasynth-base` are documented here.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
Versions are derived from Conventional Commits by `python-semantic-release`; do
not hand-pick a version (see `../AGENTS.backend-packages.md` §8).
## [Unreleased]
### Added
- **Uniform extensibility across every module.** Storage backends can be
registered (`register_storage_backend` or `STORAGE_BACKENDS[name]["CLASS"]`),
pipeline steps via `PipelineStepRegistry`/`@pipeline_step`, the pipeline
executor via `PIPELINE_EXECUTOR`, the invoice PDF via `INVOICE_PDF_BUILDER`,
and the 2FA method via `TWO_FACTOR_SERVICE`/`TWO_FACTOR_RECOVERY_SERVICE` — all
through settings/registries, with no kit edits. The other modules already
resolved extensions through dotted paths (gateways, channels, tasks, inbound
handlers, scanner) and are now documented as such.
- **Lazy public API per app package.** `from infrasynth.security import
AuthorizationService`, `from infrasynth.billing import EntitlementService`,
etc. resolve via PEP 562 without importing models before the app registry is
ready; `infrasynth.shared` re-exports its primitives eagerly.
- **Composable per-endpoint gates** (`infrasynth.gates`): declare
`infrasynth_gates = [...]` (and/or `@gated(...)` on a viewset action) with
`TwoFactorGate`, `AltchaGate`, `EntitlementGate`, `FeatureGate`,
`PermissionGate`, or a custom `Gate`. Access is evaluated per endpoint, the
default is "gate nothing", and denials raise the correct namespaced error
(`AUTH_2FA_REQUIRED`, `ENTITLEMENT_PLAN_UPGRADE_REQUIRED`,
`VALIDATION_ALTCHA_REQUIRED`, …). `GatePermission` is a default permission
class and the kit's `HybridPermission` evaluates declared gates too.
- **`2fa` JWT claim** minted only after successful verification and preserved
across workspace selection, so `TwoFactorGate` works for multi-workspace users.
- **Verified inbound webhooks.** `InboundReceiveView` now enforces the shared
HMAC signature (or a provider-specific `BaseInboundHandler.verify`), payload
size limits, timestamp tolerance, and idempotent re-delivery via
`InboundEvent.external_id`; verified events are dispatched to the endpoint's
handler through `process_inbound_event` and marked `is_verified`/`is_processed`.
- **Working 2FA login flow.** Login now challenges users with a configured
second factor (pre-auth session + cookie) and only mints JWT cookies after
`2fa/verify/` (or `2fa/recovery/`) succeeds; `TwoFactorMiddleware` guards the
session-authenticated surface.
- **Permission enforcement.** `HybridPermission` / `require_permission` are now
wired into security and audit viewsets with documented codenames and a
tenant-owner bypass; `HybridPermission` takes tenant ownership into account.
- **API-key rotation** (`/api/v1/auth/api-keys/<id>/rotate/`) and
**user permission/role endpoints** (`/api/v1/auth/users/<id>/permissions/`,
`/users/<id>/roles/`).
- **Billing webhook processing.** Verified events are applied idempotently to
subscriptions, entitlements, invoices, and `PaymentTransaction` rows; replay
protection via `assert_fresh_webhook`.
- **Scheduled billing lifecycle** (`sync_subscriptions`,
`advance_entitlement_lifecycle`, `expire_entitlements`,
`generate_renewal_invoices`) and **notification retries** + log retention, all
wired into `CELERY_BEAT_SCHEDULE`.
- **Audit update diffs** are captured automatically via a `pre_save` snapshot;
**audit retention purge** task added.
- **Feature rollout** (`rollout_percentage`, `environments`,
`ROLLOUT_HASH_ALGORITHM`) and settings-driven flag registration.
- **Login brute-force guard** (per-credential rate limit + IP blacklist),
**configurable password policy** (`PasswordPolicyValidator`), and a correctly
enforced **ALTCHA** proof-of-work.
- **File hardening:** global upload-size limit, processing-pipeline toggle, and
a pluggable virus scanner (`noop`/`clamav`/custom) with `REQUIRE_VIRUS_SCAN`.
- **Workflow guards:** `MAX_INSTANCES_PER_WORKFLOW`, `ROUTE_MAX_DEPTH`,
`ALLOW_SELF_ASSIGNMENT`, `AUTO_CLONE_ASSIGNEES_ON_REENTRY`.
- **MercadoPago** webhook signature verification.
- `README.md`, `CHANGELOG.md`, and a CI format/coverage gate.
### Changed
- `TenantRateThrottle` and `RateLimitHeadersMiddleware` are active by default,
producing `X-RateLimit-*` headers on API responses.
- `EntitlementService` treats `past_due` as within grace (entitled) and merges
entitlement-level feature overrides over `plan.features`; `require_limit`
raises `ENTITLEMENT_LIMIT_REACHED`.
- `FeatureService` resolves the current tenant automatically and honors rollout
and environment targeting.
### Fixed
- API-key authentication no longer leaks tenant context.
- `EventRegistry.emit` no longer uses `__import__` and honors
`DELIVERY_BACKEND`.
- Test media artifacts no longer accumulate in the repository tree.