Major changes: - Add Keycloak integration via token introspection endpoint - Implement RBAC system with roles: admin, user, guest - Add role-based permissions for post operations - Add pagination support (default limit: 10) to list endpoints - Add published_only filter with admin-only override for unpublished posts Security improvements: - Remove hardcoded default secrets (SECRET_KEY, KEYCLOAK_CLIENT_SECRET) - Update .env.example with proper security placeholders - Add comprehensive RBAC unit tests Infrastructure: - Add httpx dependency for HTTP client - Add KeycloakAuthClient with token caching (TTL: 60s) - Add role-based dependencies (RequireAdmin, RequireUser, etc.) - Update DI container with Keycloak provider Endpoints updated: - GET /posts: filter by published status (admin can see all) - Add pagination params (limit, offset) to list endpoints - Enforce RBAC on post operations Tests: - Add 16 auth infrastructure tests - Add 13 RBAC role tests - Update existing tests for new required settings Breaking changes: - SECRET_KEY and KEYCLOAK_CLIENT_SECRET now required (no defaults)
79 lines
2.5 KiB
Python
79 lines
2.5 KiB
Python
"""List posts use case."""
|
|
|
|
from app.application.dtos.post import PostResponseDTO
|
|
from app.application.interfaces import TransactionManager
|
|
from app.domain.entities import Post
|
|
from app.domain.repositories import PostRepository
|
|
|
|
|
|
class ListPostsUseCase:
|
|
"""Use case for listing blog posts with filtering."""
|
|
|
|
def __init__(
|
|
self,
|
|
post_repo: PostRepository,
|
|
tx_manager: TransactionManager,
|
|
) -> None:
|
|
self._post_repo = post_repo
|
|
self._tx_manager = tx_manager
|
|
|
|
async def all_posts(self) -> list[PostResponseDTO]:
|
|
"""Get all posts."""
|
|
posts = await self._post_repo.get_all()
|
|
return [self._map_to_dto(post) for post in posts]
|
|
|
|
async def published_posts(
|
|
self,
|
|
limit: int | None = None,
|
|
offset: int | None = None,
|
|
) -> list[PostResponseDTO]:
|
|
"""Get all published posts."""
|
|
posts = await self._post_repo.get_published(limit=limit, offset=offset)
|
|
return [self._map_to_dto(post) for post in posts]
|
|
|
|
async def by_author(
|
|
self,
|
|
author_id: str,
|
|
limit: int | None = None,
|
|
offset: int | None = None,
|
|
) -> list[PostResponseDTO]:
|
|
"""Get posts by author."""
|
|
posts = await self._post_repo.get_by_author(
|
|
author_id, limit=limit, offset=offset
|
|
)
|
|
return [self._map_to_dto(post) for post in posts]
|
|
|
|
async def by_tag(
|
|
self,
|
|
tag: str,
|
|
limit: int | None = None,
|
|
offset: int | None = None,
|
|
) -> list[PostResponseDTO]:
|
|
"""Get posts by tag."""
|
|
posts = await self._post_repo.get_by_tag(tag, limit=limit, offset=offset)
|
|
return [self._map_to_dto(post) for post in posts]
|
|
|
|
async def search(
|
|
self,
|
|
query: str,
|
|
limit: int | None = None,
|
|
offset: int | None = None,
|
|
) -> list[PostResponseDTO]:
|
|
"""Search posts."""
|
|
posts = await self._post_repo.search(query, limit=limit, offset=offset)
|
|
return [self._map_to_dto(post) for post in posts]
|
|
|
|
def _map_to_dto(self, post: Post) -> PostResponseDTO:
|
|
"""Map domain entity to response DTO."""
|
|
return PostResponseDTO(
|
|
id=post.id,
|
|
title=post.title.value,
|
|
content=post.content.value,
|
|
slug=post.slug.value,
|
|
author_id=post.author_id,
|
|
published=post.published,
|
|
tags=post.tags.copy(),
|
|
created_at=post.created_at,
|
|
updated_at=post.updated_at,
|
|
)
|