M0: backend skeleton — Quart factory, async DB, auth, ACL spine, migrations
Foundation & Identity backend for ThoughtSync: - Quart app factory (create_app) with /api/health + SPA history-fallback - async SQLAlchemy 2.0 + asyncpg engine/session (lazy; boots without a DB) - native email+password auth via signed-cookie session (register/login/logout/me + login_required guard); bcrypt password hashing (72-byte safe) - multi-user sharing-ACL spine (rule 47): users, groups, group_members, and a polymorphic shares table + visible_to_user() SQL predicate (owner OR direct share OR group share) that M1's notes will scope through - Alembic async env (adapted from family pattern) + 0001 foundation migration - DB-free unit tests (app/health/auth-guard, password roundtrip, ACL compile) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import uuid
|
||||
|
||||
from sqlalchemy import ColumnElement, exists, or_, select
|
||||
|
||||
from .models.group import GroupMember
|
||||
from .models.share import Share
|
||||
|
||||
|
||||
def visible_to_user(
|
||||
resource_type: str,
|
||||
owner_column,
|
||||
resource_id_column,
|
||||
user_id: uuid.UUID,
|
||||
) -> ColumnElement[bool]:
|
||||
"""Boolean SQL predicate: is this resource visible to ``user_id``?
|
||||
|
||||
A resource is visible if the user OWNS it, OR it is shared DIRECTLY with the
|
||||
user, OR it is shared with a GROUP the user belongs to. Scope every read (and
|
||||
mutation) of shareable user data through this — never assume a single operator
|
||||
(family rule 47).
|
||||
|
||||
Usage (M1+), e.g. for notes::
|
||||
|
||||
stmt = select(Note).where(visible_to_user("note", Note.owner_id, Note.id, uid))
|
||||
|
||||
Args:
|
||||
resource_type: the ``Share.resource_type`` tag for this entity (e.g. "note").
|
||||
owner_column: the resource's owner column (e.g. ``Note.owner_id``).
|
||||
resource_id_column: the resource's primary-key column (e.g. ``Note.id``).
|
||||
user_id: the viewer.
|
||||
"""
|
||||
user_group_ids = select(GroupMember.group_id).where(GroupMember.user_id == user_id)
|
||||
|
||||
direct_share = exists().where(
|
||||
Share.resource_type == resource_type,
|
||||
Share.resource_id == resource_id_column,
|
||||
Share.shared_with_user_id == user_id,
|
||||
)
|
||||
group_share = exists().where(
|
||||
Share.resource_type == resource_type,
|
||||
Share.resource_id == resource_id_column,
|
||||
Share.shared_with_group_id.in_(user_group_ids),
|
||||
)
|
||||
return or_(owner_column == user_id, direct_share, group_share)
|
||||
Reference in New Issue
Block a user