feat(identity): redesign identity module and introduce RBAC foundation

- Redesign the Identity module with a richer domain model.
- Extend the User entity to support username, Authentik integration, activity tracking, and storage information.
- Add Role and Permission domain models with many-to-many relationships.
- Implement RBAC foundation using UserRole, RolePermission, and UserPermission mappings.
- Add user storage quota and usage fields with default values.
- Introduce Authentik identifiers and synchronization metadata.
- Refactor user domain logic for role and permission management.
- Update Prisma schema to support the new identity architecture.
- Improve JWT authentication and permission guard integration.
- Update repositories, handlers, controllers, mappers, DTOs, and Swagger configuration.
- Refresh environment configuration and project dependencies.
This commit is contained in:
Rayyan
2026-08-02 00:25:36 +07:00
parent fdbfb34842
commit 7ce0de4e91
132 changed files with 7754 additions and 2037 deletions
+53 -7
View File
@@ -1,10 +1,56 @@
APP_ENV=development #development / test / prod
PORT=3069
DATABASE_URL=postgresql://USERNAME:PASSWORD@HOST:5432/DATABASE?schema=public
# Application
BASE_URL=http://localhost:3069 PORT=3000 NODE_ENV=development
JWT_SECRET=GANTI_DENGAN_SECRET
JWT_REFRESH_SECRET=GANTI_DENGAN_REFRESH_SECRET
# Database (PostgreSQL)
DATABASE_URL=postgresql://user:password@localhost:5432/Database?shema=public
SWAGGER_ENABLED=true
# Authentik (OIDC discovery base)
# Used by OIDC discovery and token exchange (AuthService)
AUTHENTIK_URL=https://auth.raylab.site
LOG_LEVEL=debug
# Authentik Admin API (provisioning identities & groups)
# Example: https://auth.raylab.site/api
AUTHENTIK_API_BASE=https://auth.raylab.site/api
# Bearer token for Authentik Admin API (admin service account)
AUTHENTIK_API_TOKEN=changeme_admin_api_token
# Default group name format: RL-{object}
# RayLab will use this group to gate access (default RL-RayLab-Users)
AUTHENTIK_DEFAULT_GROUP=RL-RayLab-Users
# OIDC / JWKS / Issuer settings for verifying Authentik tokens (if needed)
AUTHENTIK_JWKS_URI=https://auth.raylab.site/.well-known/jwks.json AUTHENTIK_ISSUER=https://auth.raylab.site/application/o/ray-lab-core/ AUTHENTIK_AUDIENCE=ray-lab-core
# OIDC client credentials (used when RayLab needs to call token endpoint)
AUTHENTIK_CLIENT_ID=raylab-client AUTHENTIK_CLIENT_SECRET=raylab-client-secret
# RayLab internal JWT (used to sign internal tokens)
RAYLAB_JWT_SECRET=replace_with_a_long_random_secret
# Token lifetime in seconds
RAYLAB_JWT_EXPIRES_IN=3600
# Sync / reconciliation
# Interval in seconds for reconciler to retry PENDING/FAILED syncs
AUTH_RECONCILE_INTERVAL_SECONDS=3600
# Auth / sync behavior
# Disable auto-creation of users on login (must remain false per design)
AUTH_AUTO_CREATE_USER=false AUTH_SYNC_EMAIL=true AUTH_SYNC_USERNAME=false
# Test accounts for integration tests (must exist in Authentik and RayLab DB before tests,
# or be provisioned via RayLab Admin endpoints during test run)
ADMIN_USERNAME=admin@example.com ADMIN_PASSWORD=changeme_admin_password
OWNER_USERNAME=owner@example.com OWNER_PASSWORD=changeme_owner_password
EMPLOYEE_USERNAME=employee@example.com EMPLOYEE_PASSWORD=changeme_employee_password
# Optional: integration test user (overrides defaults used by tests)
TEST_USER_EMAIL=test-integration@example.com TEST_USER_USERNAME=test-integration TEST_USER_PASSWORD=StrongP@ssw0rd!
# Optional: adjust logging or other runtime flags
LOG_LEVEL=info
SWAGGER_ENABLED=true