feat(08-03): FavoriteLink schema + FavoritesModule (CRUD + SSRF icon discovery)

- Add FavoriteLink Prisma model (userId/tenantId/widgetId scope, iconUrl nullable, position)
- IconDiscoveryService: port SSRF-protected icon discovery with redirect: 'manual',
  private IP / blocked-hostname checks, 4000ms timeout, 200k HTML cap (T-08-05)
- FavoritesService: list/create/update/remove all scoped by userId (T-08-06 / Pitfall 3)
- FavoritesController: GET /favorites?widgetId, POST, PATCH :id, DELETE :id
- FavoritesModule registered in AppModule
- tsc --noEmit passes for @tessera/api
This commit is contained in:
2026-07-01 10:25:52 +02:00
parent a3bb3f2396
commit 758d246e98
8 changed files with 565 additions and 0 deletions
+17
View File
@@ -233,3 +233,20 @@ model SmtpConfig {
createdAt DateTime @default(now())
updatedAt DateTime @updatedAt
}
model FavoriteLink {
id String @id @default(uuid())
userId String
tenantId String
widgetId String
title String
url String
iconUrl String?
position Int @default(0)
createdAt DateTime @default(now())
updatedAt DateTime @updatedAt
@@index([userId])
@@index([tenantId])
@@index([widgetId])
}