feat(02-01): Prisma schema expansion, RLS migration, and PrismaModule
- Add User, Role enum, PasswordResetToken, LdapConfig, LdapFieldMapping models - Expand Tenant model with isActive, users relation, ldapConfig relation - Create RLS migration with tenant isolation policies on all tenant-scoped tables - Create PrismaModule (global), PrismaService, and forTenant extension - Add JWT_SECRET, TESSERA_ADMIN_*, TESSERA_FORCE_CHANGE env vars to docker-compose - Install @nestjs/jwt, @nestjs/passport, passport, argon2, class-validator deps
This commit is contained in:
@@ -11,6 +11,76 @@ model Tenant {
|
||||
id String @id @default(uuid())
|
||||
name String
|
||||
slug String @unique
|
||||
isActive Boolean @default(true)
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
users User[]
|
||||
ldapConfig LdapConfig?
|
||||
}
|
||||
|
||||
enum Role {
|
||||
SUPER_ADMIN
|
||||
ADMIN
|
||||
USER
|
||||
}
|
||||
|
||||
model User {
|
||||
id String @id @default(uuid())
|
||||
username String @unique
|
||||
email String @unique
|
||||
passwordHash String?
|
||||
displayName String?
|
||||
role Role @default(USER)
|
||||
isActive Boolean @default(true)
|
||||
mustChangePassword Boolean @default(false)
|
||||
ldapDn String?
|
||||
tenantId String
|
||||
tenant Tenant @relation(fields: [tenantId], references: [id])
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
lastLoginAt DateTime?
|
||||
passwordResetTokens PasswordResetToken[]
|
||||
|
||||
@@index([tenantId])
|
||||
@@index([username])
|
||||
@@index([email])
|
||||
}
|
||||
|
||||
model PasswordResetToken {
|
||||
id String @id @default(uuid())
|
||||
token String @unique
|
||||
userId String
|
||||
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
||||
expiresAt DateTime
|
||||
usedAt DateTime?
|
||||
createdAt DateTime @default(now())
|
||||
}
|
||||
|
||||
model LdapConfig {
|
||||
id String @id @default(uuid())
|
||||
tenantId String @unique
|
||||
tenant Tenant @relation(fields: [tenantId], references: [id])
|
||||
serverUrl String
|
||||
baseDn String
|
||||
bindDn String
|
||||
bindPassword String
|
||||
searchFilter String @default("(objectClass=person)")
|
||||
syncIntervalMin Int @default(60)
|
||||
isActive Boolean @default(true)
|
||||
lastSyncAt DateTime?
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
fieldMappings LdapFieldMapping[]
|
||||
}
|
||||
|
||||
model LdapFieldMapping {
|
||||
id String @id @default(uuid())
|
||||
ldapConfigId String
|
||||
ldapConfig LdapConfig @relation(fields: [ldapConfigId], references: [id], onDelete: Cascade)
|
||||
ldapField String
|
||||
tesseraField String
|
||||
isDefault Boolean @default(false)
|
||||
createdAt DateTime @default(now())
|
||||
|
||||
@@unique([ldapConfigId, ldapField])
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user