feat(02-01): UserModule, TenantModule, admin seed, and app.module wiring

- Create UserService with findByUsername (unscoped), create, update, deactivate, delete
- Create AdminSeedService that seeds Super-Admin from Docker ENV on bootstrap (D-05/D-07/D-13)
- Create TenantService with findAll, findById, create, update
- Create TenantMiddleware extracting tenantId from JWT with Super-Admin tenant switching (D-08/D-10)
- Wire PrismaModule, AuthModule, UserModule, TenantModule into AppModule
- Register JwtAuthGuard and RolesGuard as global APP_GUARD providers
- Apply TenantMiddleware to all routes via NestModule.configure
- Add @Public() decorator to HealthController for unauthenticated access
This commit is contained in:
2026-06-18 13:28:04 +02:00
parent 6190f3dd39
commit 4b05627f3d
8 changed files with 285 additions and 2 deletions
+90
View File
@@ -0,0 +1,90 @@
import { Injectable } from '@nestjs/common';
import * as argon2 from 'argon2';
import { PrismaService } from '../prisma/prisma.service';
@Injectable()
export class UserService {
constructor(private prisma: PrismaService) {}
/**
* Find user by username. Uses UNSCOPED Prisma (not tenant-scoped)
* because login must work across all tenants.
*/
async findByUsername(username: string) {
return this.prisma.user.findUnique({ where: { username } });
}
/**
* Find user by ID.
*/
async findById(id: string) {
return this.prisma.user.findUnique({ where: { id } });
}
/**
* Create a new user with hashed password.
*/
async create(data: {
username: string;
email: string;
password?: string;
displayName?: string;
role?: 'SUPER_ADMIN' | 'ADMIN' | 'USER';
tenantId: string;
mustChangePassword?: boolean;
ldapDn?: string;
}) {
const { password, ...rest } = data;
return this.prisma.user.create({
data: {
...rest,
passwordHash: password ? await argon2.hash(password) : null,
},
});
}
/**
* Update user. If password is provided, hash it.
*/
async update(
id: string,
data: {
username?: string;
email?: string;
password?: string;
displayName?: string;
role?: 'SUPER_ADMIN' | 'ADMIN' | 'USER';
isActive?: boolean;
mustChangePassword?: boolean;
},
) {
const { password, ...rest } = data;
const updateData: any = { ...rest };
if (password) {
updateData.passwordHash = await argon2.hash(password);
}
return this.prisma.user.update({
where: { id },
data: updateData,
});
}
/**
* Deactivate a user (soft delete).
*/
async deactivate(id: string) {
return this.prisma.user.update({
where: { id },
data: { isActive: false },
});
}
/**
* Hard delete a user.
*/
async delete(id: string) {
return this.prisma.user.delete({ where: { id } });
}
}