M0: backend skeleton — Quart factory, async DB, auth, ACL spine, migrations
Foundation & Identity backend for ThoughtSync: - Quart app factory (create_app) with /api/health + SPA history-fallback - async SQLAlchemy 2.0 + asyncpg engine/session (lazy; boots without a DB) - native email+password auth via signed-cookie session (register/login/logout/me + login_required guard); bcrypt password hashing (72-byte safe) - multi-user sharing-ACL spine (rule 47): users, groups, group_members, and a polymorphic shares table + visible_to_user() SQL predicate (owner OR direct share OR group share) that M1's notes will scope through - Alembic async env (adapted from family pattern) + 0001 foundation migration - DB-free unit tests (app/health/auth-guard, password roundtrip, ACL compile) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import secrets
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
class Config:
|
||||
"""Runtime configuration.
|
||||
|
||||
Values come from environment variables with working local-dev defaults, so the
|
||||
app boots with zero configuration (family rule 26 — integrations default to
|
||||
working, never coerce setup). As the product grows, anything an operator wants
|
||||
to tune moves into a DB-backed Settings UI (rule 25); env is bootstrap only.
|
||||
"""
|
||||
|
||||
# Where runtime-generated secrets + uploaded media live.
|
||||
DATA_DIR = os.environ.get("THOUGHTSYNC_DATA_DIR", "/var/thoughtsync")
|
||||
# Empty -> defaults to <DATA_DIR>/media (see media_root()).
|
||||
MEDIA_ROOT = os.environ.get("THOUGHTSYNC_MEDIA_ROOT", "")
|
||||
|
||||
# postgresql+asyncpg URL. Mirrors alembic.ini's local-dev default.
|
||||
DATABASE_URL = os.environ.get(
|
||||
"THOUGHTSYNC_DATABASE_URL",
|
||||
"postgresql+asyncpg://thoughtsync:thoughtsync@localhost:5432/thoughtsync",
|
||||
)
|
||||
|
||||
# Auth session cookie: a capture app should rarely log you out, so keep it long.
|
||||
AUTH_TTL_SECONDS = 60 * 60 * 24 * 30 # 30 days
|
||||
|
||||
@classmethod
|
||||
def media_root(cls) -> Path:
|
||||
return Path(cls.MEDIA_ROOT or os.path.join(cls.DATA_DIR, "media"))
|
||||
|
||||
@classmethod
|
||||
def secret_key(cls) -> bytes:
|
||||
"""Secret used to sign the auth session cookie.
|
||||
|
||||
Read from env if set; otherwise read/generate a persistent key file under
|
||||
DATA_DIR so signed sessions survive restarts (no forced re-login on deploy).
|
||||
"""
|
||||
env = os.environ.get("THOUGHTSYNC_SECRET_KEY")
|
||||
if env:
|
||||
return env.encode()
|
||||
data_dir = Path(cls.DATA_DIR)
|
||||
data_dir.mkdir(parents=True, exist_ok=True)
|
||||
key_file = data_dir / "secret_key"
|
||||
if key_file.exists():
|
||||
return key_file.read_bytes()
|
||||
key = secrets.token_bytes(32)
|
||||
key_file.write_bytes(key)
|
||||
return key
|
||||
Reference in New Issue
Block a user