docs(02-01): complete backend auth foundation
This commit is contained in:
@@ -0,0 +1,40 @@
|
|||||||
|
# Plan 02-01: Backend Auth Foundation — Summary
|
||||||
|
|
||||||
|
**Status:** Complete
|
||||||
|
**Date:** 2026-06-18
|
||||||
|
|
||||||
|
## What Was Built
|
||||||
|
|
||||||
|
### Task 1: Prisma Schema, RLS, PrismaModule
|
||||||
|
- Expanded Prisma schema with User, Tenant, UserTenant models
|
||||||
|
- PostgreSQL RLS migration with tenant isolation policies
|
||||||
|
- PrismaModule with Client Extensions for per-request tenant context via set_config()
|
||||||
|
|
||||||
|
### Task 2: AuthModule
|
||||||
|
- Passport LocalStrategy + JwtStrategy
|
||||||
|
- JWT tokens in httpOnly cookies
|
||||||
|
- argon2 password hashing
|
||||||
|
- AuthController with /auth/login and /auth/logout endpoints
|
||||||
|
- @Public() decorator for unauthenticated routes
|
||||||
|
- JwtAuthGuard and RolesGuard
|
||||||
|
|
||||||
|
### Task 3: UserModule, TenantModule, Wiring
|
||||||
|
- UserService with CRUD operations
|
||||||
|
- AdminSeedService: auto-creates super-admin from Docker ENV (TESSERA_ADMIN_USER, TESSERA_ADMIN_EMAIL, TESSERA_ADMIN_PASSWORD)
|
||||||
|
- TenantService with CRUD
|
||||||
|
- TenantMiddleware extracting tenantId from JWT
|
||||||
|
- App.module wiring with global guards
|
||||||
|
- HealthController marked @Public()
|
||||||
|
|
||||||
|
## Commits
|
||||||
|
- `d0b36c8`: Prisma schema expansion, RLS migration, PrismaModule
|
||||||
|
- `6190f3d`: AuthModule with Passport strategies, guards, decorators
|
||||||
|
- `4b05627`: UserModule, TenantModule, admin seed, app.module wiring
|
||||||
|
|
||||||
|
## Requirements Addressed
|
||||||
|
- AUTH-01: Initial admin from Docker ENV ✓
|
||||||
|
- AUTH-03: Login/logout endpoints ✓
|
||||||
|
- AUTH-04: JWT session persistence ✓
|
||||||
|
- AUTH-05: RBAC (super-admin, admin, user) ✓
|
||||||
|
- TNNT-01: RLS tenant isolation ✓
|
||||||
|
- TNNT-03: Per-request tenant context ✓
|
||||||
Reference in New Issue
Block a user