feat(02-01): UserModule, TenantModule, admin seed, and app.module wiring

- Create UserService with findByUsername (unscoped), create, update, deactivate, delete
- Create AdminSeedService that seeds Super-Admin from Docker ENV on bootstrap (D-05/D-07/D-13)
- Create TenantService with findAll, findById, create, update
- Create TenantMiddleware extracting tenantId from JWT with Super-Admin tenant switching (D-08/D-10)
- Wire PrismaModule, AuthModule, UserModule, TenantModule into AppModule
- Register JwtAuthGuard and RolesGuard as global APP_GUARD providers
- Apply TenantMiddleware to all routes via NestModule.configure
- Add @Public() decorator to HealthController for unauthenticated access
This commit is contained in:
2026-06-18 13:28:04 +02:00
parent 6190f3dd39
commit 4b05627f3d
8 changed files with 285 additions and 2 deletions
+68
View File
@@ -0,0 +1,68 @@
import { Injectable, Logger, OnApplicationBootstrap } from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import * as argon2 from 'argon2';
import { PrismaService } from '../prisma/prisma.service';
/**
* Creates the initial Super-Admin account from Docker ENV variables on first boot.
* Per D-05, D-07, D-13.
*/
@Injectable()
export class AdminSeedService implements OnApplicationBootstrap {
private readonly logger = new Logger(AdminSeedService.name);
constructor(
private prisma: PrismaService,
private configService: ConfigService,
) {}
async onApplicationBootstrap() {
const username = this.configService.get<string>('TESSERA_ADMIN_USER');
const email = this.configService.get<string>('TESSERA_ADMIN_EMAIL');
const password = this.configService.get<string>('TESSERA_ADMIN_PASSWORD');
const forceChange =
this.configService.get<string>('TESSERA_FORCE_CHANGE') === 'true';
if (!username || !email || !password) {
this.logger.log(
'Admin seed skipped: TESSERA_ADMIN_USER, TESSERA_ADMIN_EMAIL, or TESSERA_ADMIN_PASSWORD not set',
);
return;
}
// Check if admin already exists
const exists = await this.prisma.user.findUnique({
where: { username },
});
if (exists) {
this.logger.log(`Admin user "${username}" already exists, skipping seed`);
return;
}
// Upsert default tenant
const tenant = await this.prisma.tenant.upsert({
where: { slug: 'default' },
update: {},
create: { name: 'Default', slug: 'default' },
});
// Create Super-Admin user
const passwordHash = await argon2.hash(password);
await this.prisma.user.create({
data: {
username,
email,
passwordHash,
role: 'SUPER_ADMIN',
tenantId: tenant.id,
mustChangePassword: forceChange,
isActive: true,
},
});
this.logger.log(
`Admin user "${username}" seeded as SUPER_ADMIN in tenant "${tenant.slug}"`,
);
}
}