Major changes: - Add Keycloak integration via token introspection endpoint - Implement RBAC system with roles: admin, user, guest - Add role-based permissions for post operations - Add pagination support (default limit: 10) to list endpoints - Add published_only filter with admin-only override for unpublished posts Security improvements: - Remove hardcoded default secrets (SECRET_KEY, KEYCLOAK_CLIENT_SECRET) - Update .env.example with proper security placeholders - Add comprehensive RBAC unit tests Infrastructure: - Add httpx dependency for HTTP client - Add KeycloakAuthClient with token caching (TTL: 60s) - Add role-based dependencies (RequireAdmin, RequireUser, etc.) - Update DI container with Keycloak provider Endpoints updated: - GET /posts: filter by published status (admin can see all) - Add pagination params (limit, offset) to list endpoints - Enforce RBAC on post operations Tests: - Add 16 auth infrastructure tests - Add 13 RBAC role tests - Update existing tests for new required settings Breaking changes: - SECRET_KEY and KEYCLOAK_CLIENT_SECRET now required (no defaults)
22 lines
333 B
Python
22 lines
333 B
Python
"""Infrastructure configuration."""
|
|
|
|
from app.infrastructure.config.settings import (
|
|
AppConfig,
|
|
DBConfig,
|
|
Environment,
|
|
KCConfig,
|
|
SecurityConfig,
|
|
Settings,
|
|
settings,
|
|
)
|
|
|
|
__all__ = [
|
|
"AppConfig",
|
|
"DBConfig",
|
|
"KCConfig",
|
|
"SecurityConfig",
|
|
"Environment",
|
|
"Settings",
|
|
"settings",
|
|
]
|