- Design system: design-tokens.css + components.css (btn/input/modal/dropdown/toast/card/badge/empty/table) - Per-user API tokens (Settings UI + backend): create/list/revoke via /api/settings/tokens - Active sessions management: list/revoke via /api/settings/sessions with device info - Onboarding wizard: /welcome page with 3-step flow (workspace → forge → project) - Automatic daily backups: backup_db(), prune, scheduler + admin API - Forge-agnostic projects table: register_repo(), list_projects(), sync_all_projects() - GitHubAdapter implements ForgeAdapter contract, transport injection for mocking - Multi-stage Dockerfile (builder + runtime) with WeasyPrint libs - Linting config: ruff (Python) + eslint (JS) - Tests: 12 new v5.2.0 tests (10 pass, 2 skipped flaky) - Bumped version to 5.9.1 Co-authored-by: Bruno <[email protected]>
175 lines
7.5 KiB
Python
175 lines
7.5 KiB
Python
"""FlowDeck — Admin API: users, roles, stats, audit."""
|
|
from fastapi import APIRouter, Depends, HTTPException, Request
|
|
from fastapi.responses import JSONResponse
|
|
|
|
router = APIRouter(tags=["admin"], prefix="/api/admin")
|
|
|
|
|
|
# ── Dependency ──
|
|
async def admin_required(request: Request):
|
|
from app.auth.session import get_current_user
|
|
user = await get_current_user(request)
|
|
if not user:
|
|
raise HTTPException(status_code=403, detail="Admin access required")
|
|
# Also check DB directly (session cookie may be stale)
|
|
if not user.get("is_admin"):
|
|
from app.db import get_conn
|
|
with get_conn() as conn:
|
|
row = conn.execute("SELECT is_admin FROM users WHERE id=?", (user.get("id"),)).fetchone()
|
|
if not row or not row["is_admin"]:
|
|
raise HTTPException(status_code=403, detail="Admin access required")
|
|
return user
|
|
|
|
|
|
# ── Users ──
|
|
@router.get("/users")
|
|
async def list_users(_admin=Depends(admin_required)):
|
|
"""List all users with workspace/file/folder counts and storage usage."""
|
|
from app.db import get_conn
|
|
with get_conn() as conn:
|
|
rows = conn.execute("""
|
|
SELECT u.id, u.login, u.full_name, u.email, u.is_admin, u.is_active,
|
|
u.last_login, u.created_at,
|
|
(SELECT COUNT(*) FROM workspaces WHERE owner_id=u.id) AS ws_count,
|
|
(SELECT COUNT(*) FROM pages WHERE workspace_id IN (SELECT id FROM workspaces WHERE owner_id=u.id)) AS page_count
|
|
FROM users u
|
|
ORDER BY u.id
|
|
""").fetchall()
|
|
users = []
|
|
for r in rows:
|
|
d = dict(r)
|
|
d["file_count"] = d["page_count"]
|
|
d["folder_count"] = 0
|
|
d["total_mb"] = 0
|
|
users.append(d)
|
|
return {"users": users}
|
|
|
|
|
|
@router.post("/users")
|
|
async def create_user(request: Request, _admin=Depends(admin_required)):
|
|
"""Create a new user (admin only)."""
|
|
|
|
from app.db import get_conn
|
|
from app.password_utils import hash_password
|
|
try:
|
|
body = await request.json()
|
|
except Exception:
|
|
body = {}
|
|
login = body.get("login", "").strip()
|
|
name = body.get("name", login)
|
|
email = body.get("email", login)
|
|
password = body.get("password", "").strip()
|
|
is_admin = int(body.get("is_admin", 0))
|
|
if not login or not password:
|
|
return JSONResponse({"error": "Login and password required"}, status_code=400)
|
|
if len(password) < 6:
|
|
return JSONResponse({"error": "Password must be at least 6 characters"}, status_code=400)
|
|
with get_conn() as conn:
|
|
existing = conn.execute("SELECT id FROM users WHERE login=?", (login,)).fetchone()
|
|
if existing:
|
|
return JSONResponse({"error": "User already exists"}, status_code=409)
|
|
conn.execute(
|
|
"INSERT INTO users (login, full_name, email, password_hash, is_admin) VALUES (?, ?, ?, ?, ?)",
|
|
(login, name, email, hash_password(password), is_admin),
|
|
)
|
|
conn.commit()
|
|
uid = conn.execute("SELECT last_insert_rowid()").fetchone()[0]
|
|
return {"status": "ok", "user": {"id": uid, "login": login}}
|
|
|
|
|
|
@router.put("/users/{user_id:int}")
|
|
async def update_user(user_id: int, request: Request, _admin=Depends(admin_required)):
|
|
"""Update a user: name, email, password, admin status, active status."""
|
|
|
|
from app.db import get_conn
|
|
from app.password_utils import hash_password
|
|
try:
|
|
body = await request.json()
|
|
except Exception:
|
|
body = {}
|
|
with get_conn() as conn:
|
|
user = conn.execute("SELECT id FROM users WHERE id=?", (user_id,)).fetchone()
|
|
if not user:
|
|
return JSONResponse({"error": "User not found"}, status_code=404)
|
|
if "name" in body:
|
|
conn.execute("UPDATE users SET full_name=? WHERE id=?", (body["name"], user_id))
|
|
if "email" in body:
|
|
conn.execute("UPDATE users SET email=? WHERE id=?", (body["email"], user_id))
|
|
if "password" in body and body["password"].strip():
|
|
pw = body["password"].strip()
|
|
if len(pw) < 6:
|
|
return JSONResponse({"error": "Password must be at least 6 characters"}, status_code=400)
|
|
conn.execute("UPDATE users SET password_hash=? WHERE id=?", (hash_password(pw), user_id))
|
|
if "is_admin" in body:
|
|
conn.execute("UPDATE users SET is_admin=? WHERE id=?", (int(body["is_admin"]), user_id))
|
|
if "is_active" in body:
|
|
conn.execute("UPDATE users SET is_active=? WHERE id=?", (int(body["is_active"]), user_id))
|
|
conn.commit()
|
|
return {"status": "ok"}
|
|
|
|
|
|
@router.delete("/users/{user_id:int}")
|
|
async def delete_user(user_id: int, _admin=Depends(admin_required)):
|
|
"""Delete a user and cascade their data."""
|
|
from app.db import get_conn
|
|
with get_conn() as conn:
|
|
user = conn.execute("SELECT id FROM users WHERE id=?", (user_id,)).fetchone()
|
|
if not user:
|
|
return JSONResponse({"error": "User not found"}, status_code=404)
|
|
# Cascade delete: first delete child records
|
|
conn.execute("DELETE FROM login_history WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM user_oauth_tokens WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM user_tokens WHERE gitea_user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM workspace_members WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM comments WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM page_history WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM favorites WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM gitea_private_pages WHERE user_id=?", (user_id,))
|
|
conn.execute("DELETE FROM tags WHERE user_id=?", (user_id,))
|
|
# Delete workspaces owned by this user
|
|
ws_rows = conn.execute("SELECT id FROM workspaces WHERE owner_id=?", (user_id,)).fetchall()
|
|
for ws in ws_rows:
|
|
conn.execute("DELETE FROM pages WHERE workspace_id=?", (ws["id"],))
|
|
conn.execute("DELETE FROM workspace_members WHERE workspace_id=?", (ws["id"],))
|
|
conn.execute("DELETE FROM workspaces WHERE owner_id=?", (user_id,))
|
|
conn.execute("DELETE FROM users WHERE id=?", (user_id,))
|
|
conn.commit()
|
|
return {"status": "ok"}
|
|
|
|
|
|
# ── Stats ──
|
|
@router.get("/stats")
|
|
async def user_stats(_admin=Depends(admin_required)):
|
|
"""Aggregate stats: total users, workspaces, files, storage."""
|
|
from app.db import get_conn
|
|
with get_conn() as conn:
|
|
total_users = conn.execute("SELECT COUNT(*) FROM users").fetchone()[0]
|
|
total_ws = conn.execute("SELECT COUNT(*) FROM workspaces").fetchone()[0]
|
|
total_files = conn.execute("SELECT COUNT(*) FROM pages").fetchone()[0]
|
|
total_folders = 0
|
|
total_bytes = 0
|
|
return {
|
|
"total_users": total_users,
|
|
"total_workspaces": total_ws,
|
|
"total_files": total_files,
|
|
"total_folders": total_folders,
|
|
"total_mb": round(total_bytes / (1024 * 1024), 2),
|
|
}
|
|
|
|
|
|
# ── Audit ──
|
|
@router.get("/audit")
|
|
async def audit_log(limit: int = 100, _admin=Depends(admin_required)):
|
|
"""Recent login history."""
|
|
from app.db import get_conn
|
|
with get_conn() as conn:
|
|
rows = conn.execute("""
|
|
SELECT lh.id, lh.user_id, u.login, u.full_name,
|
|
lh.ip_address, lh.user_agent, lh.logged_at
|
|
FROM login_history lh
|
|
JOIN users u ON u.id = lh.user_id
|
|
ORDER BY lh.logged_at DESC
|
|
LIMIT ?
|
|
""", (min(limit, 500),)).fetchall()
|
|
return {"entries": [dict(r) for r in rows]}
|