docs(02-01): complete backend auth foundation
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# Plan 02-01: Backend Auth Foundation — Summary
|
||||
|
||||
**Status:** Complete
|
||||
**Date:** 2026-06-18
|
||||
|
||||
## What Was Built
|
||||
|
||||
### Task 1: Prisma Schema, RLS, PrismaModule
|
||||
- Expanded Prisma schema with User, Tenant, UserTenant models
|
||||
- PostgreSQL RLS migration with tenant isolation policies
|
||||
- PrismaModule with Client Extensions for per-request tenant context via set_config()
|
||||
|
||||
### Task 2: AuthModule
|
||||
- Passport LocalStrategy + JwtStrategy
|
||||
- JWT tokens in httpOnly cookies
|
||||
- argon2 password hashing
|
||||
- AuthController with /auth/login and /auth/logout endpoints
|
||||
- @Public() decorator for unauthenticated routes
|
||||
- JwtAuthGuard and RolesGuard
|
||||
|
||||
### Task 3: UserModule, TenantModule, Wiring
|
||||
- UserService with CRUD operations
|
||||
- AdminSeedService: auto-creates super-admin from Docker ENV (TESSERA_ADMIN_USER, TESSERA_ADMIN_EMAIL, TESSERA_ADMIN_PASSWORD)
|
||||
- TenantService with CRUD
|
||||
- TenantMiddleware extracting tenantId from JWT
|
||||
- App.module wiring with global guards
|
||||
- HealthController marked @Public()
|
||||
|
||||
## Commits
|
||||
- `d0b36c8`: Prisma schema expansion, RLS migration, PrismaModule
|
||||
- `6190f3d`: AuthModule with Passport strategies, guards, decorators
|
||||
- `4b05627`: UserModule, TenantModule, admin seed, app.module wiring
|
||||
|
||||
## Requirements Addressed
|
||||
- AUTH-01: Initial admin from Docker ENV ✓
|
||||
- AUTH-03: Login/logout endpoints ✓
|
||||
- AUTH-04: JWT session persistence ✓
|
||||
- AUTH-05: RBAC (super-admin, admin, user) ✓
|
||||
- TNNT-01: RLS tenant isolation ✓
|
||||
- TNNT-03: Per-request tenant context ✓
|
||||
Reference in New Issue
Block a user