docs(02-01): complete backend auth foundation

This commit is contained in:
2026-06-18 13:29:59 +02:00
parent 4b05627f3d
commit 47f765ca99
@@ -0,0 +1,40 @@
# Plan 02-01: Backend Auth Foundation — Summary
**Status:** Complete
**Date:** 2026-06-18
## What Was Built
### Task 1: Prisma Schema, RLS, PrismaModule
- Expanded Prisma schema with User, Tenant, UserTenant models
- PostgreSQL RLS migration with tenant isolation policies
- PrismaModule with Client Extensions for per-request tenant context via set_config()
### Task 2: AuthModule
- Passport LocalStrategy + JwtStrategy
- JWT tokens in httpOnly cookies
- argon2 password hashing
- AuthController with /auth/login and /auth/logout endpoints
- @Public() decorator for unauthenticated routes
- JwtAuthGuard and RolesGuard
### Task 3: UserModule, TenantModule, Wiring
- UserService with CRUD operations
- AdminSeedService: auto-creates super-admin from Docker ENV (TESSERA_ADMIN_USER, TESSERA_ADMIN_EMAIL, TESSERA_ADMIN_PASSWORD)
- TenantService with CRUD
- TenantMiddleware extracting tenantId from JWT
- App.module wiring with global guards
- HealthController marked @Public()
## Commits
- `d0b36c8`: Prisma schema expansion, RLS migration, PrismaModule
- `6190f3d`: AuthModule with Passport strategies, guards, decorators
- `4b05627`: UserModule, TenantModule, admin seed, app.module wiring
## Requirements Addressed
- AUTH-01: Initial admin from Docker ENV ✓
- AUTH-03: Login/logout endpoints ✓
- AUTH-04: JWT session persistence ✓
- AUTH-05: RBAC (super-admin, admin, user) ✓
- TNNT-01: RLS tenant isolation ✓
- TNNT-03: Per-request tenant context ✓