d0b36c8f22
- Add User, Role enum, PasswordResetToken, LdapConfig, LdapFieldMapping models - Expand Tenant model with isActive, users relation, ldapConfig relation - Create RLS migration with tenant isolation policies on all tenant-scoped tables - Create PrismaModule (global), PrismaService, and forTenant extension - Add JWT_SECRET, TESSERA_ADMIN_*, TESSERA_FORCE_CHANGE env vars to docker-compose - Install @nestjs/jwt, @nestjs/passport, passport, argon2, class-validator deps
87 lines
2.4 KiB
Plaintext
87 lines
2.4 KiB
Plaintext
datasource db {
|
|
provider = "postgresql"
|
|
url = env("DATABASE_URL")
|
|
}
|
|
|
|
generator client {
|
|
provider = "prisma-client-js"
|
|
}
|
|
|
|
model Tenant {
|
|
id String @id @default(uuid())
|
|
name String
|
|
slug String @unique
|
|
isActive Boolean @default(true)
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
users User[]
|
|
ldapConfig LdapConfig?
|
|
}
|
|
|
|
enum Role {
|
|
SUPER_ADMIN
|
|
ADMIN
|
|
USER
|
|
}
|
|
|
|
model User {
|
|
id String @id @default(uuid())
|
|
username String @unique
|
|
email String @unique
|
|
passwordHash String?
|
|
displayName String?
|
|
role Role @default(USER)
|
|
isActive Boolean @default(true)
|
|
mustChangePassword Boolean @default(false)
|
|
ldapDn String?
|
|
tenantId String
|
|
tenant Tenant @relation(fields: [tenantId], references: [id])
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
lastLoginAt DateTime?
|
|
passwordResetTokens PasswordResetToken[]
|
|
|
|
@@index([tenantId])
|
|
@@index([username])
|
|
@@index([email])
|
|
}
|
|
|
|
model PasswordResetToken {
|
|
id String @id @default(uuid())
|
|
token String @unique
|
|
userId String
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
expiresAt DateTime
|
|
usedAt DateTime?
|
|
createdAt DateTime @default(now())
|
|
}
|
|
|
|
model LdapConfig {
|
|
id String @id @default(uuid())
|
|
tenantId String @unique
|
|
tenant Tenant @relation(fields: [tenantId], references: [id])
|
|
serverUrl String
|
|
baseDn String
|
|
bindDn String
|
|
bindPassword String
|
|
searchFilter String @default("(objectClass=person)")
|
|
syncIntervalMin Int @default(60)
|
|
isActive Boolean @default(true)
|
|
lastSyncAt DateTime?
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
fieldMappings LdapFieldMapping[]
|
|
}
|
|
|
|
model LdapFieldMapping {
|
|
id String @id @default(uuid())
|
|
ldapConfigId String
|
|
ldapConfig LdapConfig @relation(fields: [ldapConfigId], references: [id], onDelete: Cascade)
|
|
ldapField String
|
|
tesseraField String
|
|
isDefault Boolean @default(false)
|
|
createdAt DateTime @default(now())
|
|
|
|
@@unique([ldapConfigId, ldapField])
|
|
}
|