Implement NetKingdom identity shell for coulomb.social (CSOC-WP-0002)
Django scaffold aligned with the business delivery lane: tenant-keyed Member model without passwords, identity app as sole OIDC/session boundary, dev-claims login, authenticated /app/ shell, ADR-0001, and tests. T01/T02/T05/T06 done; OIDC registration, real user-engine HTTP, flex-auth, and packaging remain open.
This commit is contained in:
parent
2ec7761504
commit
01da195c13
51 changed files with 2215 additions and 41 deletions
0
coulomb_social/settings/__init__.py
Normal file
0
coulomb_social/settings/__init__.py
Normal file
113
coulomb_social/settings/base.py
Normal file
113
coulomb_social/settings/base.py
Normal file
|
|
@ -0,0 +1,113 @@
|
|||
"""Shared Django settings for coulomb.social."""
|
||||
|
||||
from pathlib import Path
|
||||
|
||||
from decouple import Csv, config
|
||||
from dj_database_url import parse as parse_db_url
|
||||
|
||||
BASE_DIR = Path(__file__).resolve().parent.parent.parent
|
||||
|
||||
SECRET_KEY = config("SECRET_KEY", default="django-insecure-change-me-in-production")
|
||||
DEBUG = config("DEBUG", default=False, cast=bool)
|
||||
ALLOWED_HOSTS = config("ALLOWED_HOSTS", default="localhost,127.0.0.1", cast=Csv())
|
||||
|
||||
INSTALLED_APPS = [
|
||||
"django.contrib.admin",
|
||||
"django.contrib.auth",
|
||||
"django.contrib.contenttypes",
|
||||
"django.contrib.sessions",
|
||||
"django.contrib.messages",
|
||||
"django.contrib.staticfiles",
|
||||
"coulomb_social.apps.core",
|
||||
"coulomb_social.apps.members",
|
||||
"coulomb_social.apps.identity",
|
||||
]
|
||||
|
||||
MIDDLEWARE = [
|
||||
"django.middleware.security.SecurityMiddleware",
|
||||
"whitenoise.middleware.WhiteNoiseMiddleware",
|
||||
"django.contrib.sessions.middleware.SessionMiddleware",
|
||||
"django.middleware.common.CommonMiddleware",
|
||||
"django.middleware.csrf.CsrfViewMiddleware",
|
||||
"django.contrib.auth.middleware.AuthenticationMiddleware",
|
||||
"django.contrib.messages.middleware.MessageMiddleware",
|
||||
"django.middleware.clickjacking.XFrameOptionsMiddleware",
|
||||
]
|
||||
|
||||
ROOT_URLCONF = "coulomb_social.urls"
|
||||
|
||||
TEMPLATES = [
|
||||
{
|
||||
"BACKEND": "django.template.backends.django.DjangoTemplates",
|
||||
"DIRS": [BASE_DIR / "coulomb_social" / "templates"],
|
||||
"APP_DIRS": True,
|
||||
"OPTIONS": {
|
||||
"context_processors": [
|
||||
"django.template.context_processors.debug",
|
||||
"django.template.context_processors.request",
|
||||
"django.contrib.auth.context_processors.auth",
|
||||
"django.contrib.messages.context_processors.messages",
|
||||
"coulomb_social.apps.core.context_processors.site_context",
|
||||
],
|
||||
},
|
||||
},
|
||||
]
|
||||
|
||||
WSGI_APPLICATION = "coulomb_social.wsgi.application"
|
||||
ASGI_APPLICATION = "coulomb_social.asgi.application"
|
||||
|
||||
DATABASES = {
|
||||
"default": parse_db_url(
|
||||
config(
|
||||
"DATABASE_URL",
|
||||
default=f"sqlite:///{BASE_DIR / 'db.sqlite3'}",
|
||||
)
|
||||
)
|
||||
}
|
||||
|
||||
AUTH_USER_MODEL = "members.User"
|
||||
|
||||
AUTH_PASSWORD_VALIDATORS: list[dict[str, str]] = [] # no local passwords
|
||||
|
||||
LANGUAGE_CODE = "en-us"
|
||||
TIME_ZONE = "Europe/Berlin"
|
||||
USE_I18N = True
|
||||
USE_TZ = True
|
||||
|
||||
STATIC_URL = "/static/"
|
||||
STATIC_ROOT = BASE_DIR / "staticfiles"
|
||||
STATICFILES_DIRS = [BASE_DIR / "static"] if (BASE_DIR / "static").exists() else []
|
||||
STORAGES = {
|
||||
"staticfiles": {
|
||||
"BACKEND": "whitenoise.storage.CompressedManifestStaticFilesStorage",
|
||||
},
|
||||
}
|
||||
|
||||
DEFAULT_AUTO_FIELD = "django.db.models.BigAutoField"
|
||||
|
||||
LOGIN_URL = "identity:login"
|
||||
LOGIN_REDIRECT_URL = "core:app_home"
|
||||
LOGOUT_REDIRECT_URL = "core:landing"
|
||||
|
||||
# ── Tenant (Binky = client #1) ──────────────────────────────────────────────
|
||||
DEFAULT_TENANT_ID = config("DEFAULT_TENANT_ID", default="binky")
|
||||
|
||||
# ── NetKingdom identity (see ADR-0001) ──────────────────────────────────────
|
||||
# When OIDC_ENABLED is false, only the DEBUG dev-login path is available.
|
||||
OIDC_ENABLED = config("OIDC_ENABLED", default=False, cast=bool)
|
||||
OIDC_ISSUER = config("OIDC_ISSUER", default="")
|
||||
OIDC_CLIENT_ID = config("OIDC_CLIENT_ID", default="")
|
||||
OIDC_CLIENT_SECRET = config("OIDC_CLIENT_SECRET", default="")
|
||||
OIDC_REDIRECT_URI = config("OIDC_REDIRECT_URI", default="")
|
||||
OIDC_SCOPES = config("OIDC_SCOPES", default="openid profile email")
|
||||
OIDC_DISCOVERY_URL = config("OIDC_DISCOVERY_URL", default="") # optional override
|
||||
|
||||
# user-engine HTTP base (empty → in-process stub)
|
||||
USER_ENGINE_BASE_URL = config("USER_ENGINE_BASE_URL", default="")
|
||||
USER_ENGINE_APPLICATION_ID = config("USER_ENGINE_APPLICATION_ID", default="coulomb-social")
|
||||
|
||||
# flex-auth (empty → local fail-closed stub for sensitive checks; shell view allowed)
|
||||
FLEX_AUTH_BASE_URL = config("FLEX_AUTH_BASE_URL", default="")
|
||||
FLEX_AUTH_PROTECTED_SYSTEM_ID = config(
|
||||
"FLEX_AUTH_PROTECTED_SYSTEM_ID", default="coulomb-social"
|
||||
)
|
||||
13
coulomb_social/settings/dev.py
Normal file
13
coulomb_social/settings/dev.py
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
from .base import * # noqa: F403
|
||||
|
||||
DEBUG = True
|
||||
ALLOWED_HOSTS = ["*"]
|
||||
|
||||
# SQLite by default for zero-deps local shell; override with DATABASE_URL.
|
||||
EMAIL_BACKEND = "django.core.mail.backends.console.EmailBackend"
|
||||
|
||||
STORAGES = {
|
||||
"staticfiles": {
|
||||
"BACKEND": "django.contrib.staticfiles.storage.StaticFilesStorage",
|
||||
},
|
||||
}
|
||||
9
coulomb_social/settings/prod.py
Normal file
9
coulomb_social/settings/prod.py
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
from decouple import config
|
||||
|
||||
from .base import * # noqa: F403
|
||||
|
||||
DEBUG = False
|
||||
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
|
||||
SESSION_COOKIE_SECURE = True
|
||||
CSRF_COOKIE_SECURE = True
|
||||
SECURE_SSL_REDIRECT = config("SECURE_SSL_REDIRECT", default=True, cast=bool)
|
||||
23
coulomb_social/settings/test.py
Normal file
23
coulomb_social/settings/test.py
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
from .base import * # noqa: F403
|
||||
|
||||
DEBUG = False
|
||||
SECRET_KEY = "test-secret-key"
|
||||
PASSWORD_HASHERS = ["django.contrib.auth.hashers.MD5PasswordHasher"]
|
||||
|
||||
DATABASES = {
|
||||
"default": {
|
||||
"ENGINE": "django.db.backends.sqlite3",
|
||||
"NAME": ":memory:",
|
||||
}
|
||||
}
|
||||
|
||||
OIDC_ENABLED = False
|
||||
USER_ENGINE_BASE_URL = ""
|
||||
FLEX_AUTH_BASE_URL = ""
|
||||
|
||||
# Whitenoise manifest not required in tests
|
||||
STORAGES = {
|
||||
"staticfiles": {
|
||||
"BACKEND": "django.contrib.staticfiles.storage.StaticFilesStorage",
|
||||
},
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue