feat(identity): redesign identity module and introduce RBAC foundation
- Redesign the Identity module with a richer domain model. - Extend the User entity to support username, Authentik integration, activity tracking, and storage information. - Add Role and Permission domain models with many-to-many relationships. - Implement RBAC foundation using UserRole, RolePermission, and UserPermission mappings. - Add user storage quota and usage fields with default values. - Introduce Authentik identifiers and synchronization metadata. - Refactor user domain logic for role and permission management. - Update Prisma schema to support the new identity architecture. - Improve JWT authentication and permission guard integration. - Update repositories, handlers, controllers, mappers, DTOs, and Swagger configuration. - Refresh environment configuration and project dependencies.
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { AuthController } from './auth.controller';
|
||||
import { AuthService } from './auth.service';
|
||||
import { ConfigModule, ConfigService } from '@nestjs/config';
|
||||
import { JwtModule } from '@nestjs/jwt';
|
||||
import { PrismaService } from '../../shared/prisma.service';
|
||||
import { IUser } from '../identity/domain/repositories/user.interface';
|
||||
import { PrismaUserRepository } from '../identity/infrastructure/repositories/prisma-user.repository';
|
||||
import { SyncIdentityHandler } from '../identity/application/handlers/user/sync-identity.handler';
|
||||
import { IRole } from '../identity/domain/repositories/role.interface';
|
||||
import { PrismaRoleRepository } from '../identity/infrastructure/repositories/prisma-role.repository';
|
||||
import { IAuthConfig } from '../identity/application/config/i-auth-config';
|
||||
import { EnvAuthConfig } from '../identity/application/config/env-auth-config';
|
||||
import { RedisPkceStore } from './pkce/redis-pkce.store';
|
||||
import { InMemoryRefreshStore } from './refresh/inmemory-refresh.store';
|
||||
|
||||
@Module({
|
||||
imports: [
|
||||
ConfigModule,
|
||||
JwtModule.registerAsync({
|
||||
imports: [ConfigModule],
|
||||
useFactory: async (config: ConfigService) => ({
|
||||
secret: config.get('RAYLAB_JWT_SECRET') || 'raylab-secret',
|
||||
signOptions: { algorithm: 'HS256' },
|
||||
}),
|
||||
inject: [ConfigService],
|
||||
}),
|
||||
],
|
||||
controllers: [AuthController],
|
||||
providers: [
|
||||
AuthService,
|
||||
PrismaService,
|
||||
PrismaUserRepository,
|
||||
PrismaRoleRepository,
|
||||
SyncIdentityHandler,
|
||||
{ provide: IUser, useClass: PrismaUserRepository },
|
||||
{ provide: IRole, useClass: PrismaRoleRepository },
|
||||
{ provide: IAuthConfig, useClass: EnvAuthConfig },
|
||||
|
||||
// In-memory PKCE and Refresh stores (Redis removed)
|
||||
RedisPkceStore,
|
||||
InMemoryRefreshStore,
|
||||
],
|
||||
exports: [AuthService],
|
||||
})
|
||||
export class AuthModule {}
|
||||
Reference in New Issue
Block a user