
- Implemented comprehensive multi-tenant data isolation using database-level security - Built JWT authentication system with role-based access control (Super Admin, Org Admin, User, Viewer) - Created RESTful API endpoints for user and organization operations - Added complete audit logging for all data modifications with IP tracking - Implemented API rate limiting and input validation with security middleware - Built webhook processing engine with async event handling and retry logic - Created external API call handlers with circuit breaker pattern and error handling - Implemented data synchronization between external services and internal data - Added integration health monitoring and status tracking - Created three mock external services (User Management, Payment, Communication) - Implemented idempotency for webhook processing to handle duplicates gracefully - Added comprehensive security headers and XSS/CSRF protection - Set up Alembic database migrations with proper SQLite configuration - Included extensive documentation and API examples Architecture features: - Multi-tenant isolation at database level - Circuit breaker pattern for external API resilience - Async background task processing - Complete audit trail with user context - Role-based permission system - Webhook signature verification - Request validation and sanitization - Health monitoring endpoints Co-Authored-By: Claude <noreply@anthropic.com>
142 lines
7.6 KiB
Python
142 lines
7.6 KiB
Python
"""Initial migration
|
|
|
|
Revision ID: 001
|
|
Revises:
|
|
Create Date: 2024-01-01 00:00:00.000000
|
|
|
|
"""
|
|
from typing import Sequence, Union
|
|
|
|
from alembic import op
|
|
import sqlalchemy as sa
|
|
|
|
# revision identifiers, used by Alembic.
|
|
revision: str = '001'
|
|
down_revision: Union[str, None] = None
|
|
branch_labels: Union[str, Sequence[str], None] = None
|
|
depends_on: Union[str, Sequence[str], None] = None
|
|
|
|
|
|
def upgrade() -> None:
|
|
# Create organizations table
|
|
op.create_table('organizations',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('name', sa.String(length=255), nullable=False),
|
|
sa.Column('domain', sa.String(length=255), nullable=False),
|
|
sa.Column('subdomain', sa.String(length=100), nullable=False),
|
|
sa.Column('is_active', sa.Boolean(), nullable=True),
|
|
sa.Column('settings', sa.Text(), nullable=True),
|
|
sa.Column('created_at', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.Column('updated_at', sa.DateTime(timezone=True), nullable=True),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
op.create_index(op.f('ix_organizations_domain'), 'organizations', ['domain'], unique=True)
|
|
op.create_index(op.f('ix_organizations_id'), 'organizations', ['id'], unique=False)
|
|
op.create_index(op.f('ix_organizations_name'), 'organizations', ['name'], unique=False)
|
|
op.create_index(op.f('ix_organizations_subdomain'), 'organizations', ['subdomain'], unique=True)
|
|
|
|
# Create users table
|
|
op.create_table('users',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('email', sa.String(length=255), nullable=False),
|
|
sa.Column('username', sa.String(length=100), nullable=False),
|
|
sa.Column('hashed_password', sa.String(length=255), nullable=False),
|
|
sa.Column('first_name', sa.String(length=100), nullable=True),
|
|
sa.Column('last_name', sa.String(length=100), nullable=True),
|
|
sa.Column('role', sa.Enum('SUPER_ADMIN', 'ORG_ADMIN', 'USER', 'VIEWER', name='userrole'), nullable=True),
|
|
sa.Column('is_active', sa.Boolean(), nullable=True),
|
|
sa.Column('is_verified', sa.Boolean(), nullable=True),
|
|
sa.Column('organization_id', sa.Integer(), nullable=False),
|
|
sa.Column('last_login', sa.DateTime(timezone=True), nullable=True),
|
|
sa.Column('created_at', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.Column('updated_at', sa.DateTime(timezone=True), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
op.create_index(op.f('ix_users_email'), 'users', ['email'], unique=True)
|
|
op.create_index(op.f('ix_users_id'), 'users', ['id'], unique=False)
|
|
op.create_index(op.f('ix_users_username'), 'users', ['username'], unique=True)
|
|
|
|
# Create audit_logs table
|
|
op.create_table('audit_logs',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('organization_id', sa.Integer(), nullable=False),
|
|
sa.Column('user_id', sa.Integer(), nullable=True),
|
|
sa.Column('action', sa.Enum('CREATE', 'UPDATE', 'DELETE', 'LOGIN', 'LOGOUT', 'VIEW', name='auditaction'), nullable=False),
|
|
sa.Column('resource_type', sa.String(length=100), nullable=False),
|
|
sa.Column('resource_id', sa.String(length=100), nullable=True),
|
|
sa.Column('details', sa.Text(), nullable=True),
|
|
sa.Column('ip_address', sa.String(length=45), nullable=True),
|
|
sa.Column('user_agent', sa.Text(), nullable=True),
|
|
sa.Column('timestamp', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.ForeignKeyConstraint(['user_id'], ['users.id'], ),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
|
|
# Create external_integrations table
|
|
op.create_table('external_integrations',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('organization_id', sa.Integer(), nullable=False),
|
|
sa.Column('name', sa.String(length=255), nullable=False),
|
|
sa.Column('type', sa.Enum('USER_MANAGEMENT', 'PAYMENT', 'COMMUNICATION', name='integrationtype'), nullable=False),
|
|
sa.Column('endpoint_url', sa.String(length=500), nullable=False),
|
|
sa.Column('api_key', sa.String(length=500), nullable=True),
|
|
sa.Column('is_active', sa.Boolean(), nullable=True),
|
|
sa.Column('config', sa.Text(), nullable=True),
|
|
sa.Column('last_sync', sa.DateTime(timezone=True), nullable=True),
|
|
sa.Column('created_at', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.Column('updated_at', sa.DateTime(timezone=True), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
|
|
# Create webhook_events table
|
|
op.create_table('webhook_events',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('organization_id', sa.Integer(), nullable=False),
|
|
sa.Column('integration_id', sa.Integer(), nullable=False),
|
|
sa.Column('external_id', sa.String(length=255), nullable=False),
|
|
sa.Column('event_type', sa.String(length=100), nullable=False),
|
|
sa.Column('payload', sa.Text(), nullable=False),
|
|
sa.Column('status', sa.Enum('PENDING', 'PROCESSING', 'SUCCESS', 'FAILED', 'RETRY', name='webhookstatus'), nullable=True),
|
|
sa.Column('retry_count', sa.Integer(), nullable=True),
|
|
sa.Column('max_retries', sa.Integer(), nullable=True),
|
|
sa.Column('error_message', sa.Text(), nullable=True),
|
|
sa.Column('processed_at', sa.DateTime(timezone=True), nullable=True),
|
|
sa.Column('created_at', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.Column('updated_at', sa.DateTime(timezone=True), nullable=True),
|
|
sa.ForeignKeyConstraint(['integration_id'], ['external_integrations.id'], ),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
op.create_index(op.f('ix_webhook_events_external_id'), 'webhook_events', ['external_id'], unique=False)
|
|
|
|
# Create integration_health table
|
|
op.create_table('integration_health',
|
|
sa.Column('id', sa.Integer(), nullable=False),
|
|
sa.Column('integration_id', sa.Integer(), nullable=False),
|
|
sa.Column('status', sa.String(length=50), nullable=False),
|
|
sa.Column('response_time', sa.Integer(), nullable=True),
|
|
sa.Column('error_message', sa.Text(), nullable=True),
|
|
sa.Column('checked_at', sa.DateTime(timezone=True), server_default=sa.text('(CURRENT_TIMESTAMP)'), nullable=True),
|
|
sa.ForeignKeyConstraint(['integration_id'], ['external_integrations.id'], ),
|
|
sa.PrimaryKeyConstraint('id')
|
|
)
|
|
|
|
|
|
def downgrade() -> None:
|
|
op.drop_table('integration_health')
|
|
op.drop_index(op.f('ix_webhook_events_external_id'), table_name='webhook_events')
|
|
op.drop_table('webhook_events')
|
|
op.drop_table('external_integrations')
|
|
op.drop_table('audit_logs')
|
|
op.drop_index(op.f('ix_users_username'), table_name='users')
|
|
op.drop_index(op.f('ix_users_id'), table_name='users')
|
|
op.drop_index(op.f('ix_users_email'), table_name='users')
|
|
op.drop_table('users')
|
|
op.drop_index(op.f('ix_organizations_subdomain'), table_name='organizations')
|
|
op.drop_index(op.f('ix_organizations_name'), table_name='organizations')
|
|
op.drop_index(op.f('ix_organizations_id'), table_name='organizations')
|
|
op.drop_index(op.f('ix_organizations_domain'), table_name='organizations')
|
|
op.drop_table('organizations') |