feat(identity): redesign identity module and introduce RBAC foundation

- Redesign the Identity module with a richer domain model.
- Extend the User entity to support username, Authentik integration, activity tracking, and storage information.
- Add Role and Permission domain models with many-to-many relationships.
- Implement RBAC foundation using UserRole, RolePermission, and UserPermission mappings.
- Add user storage quota and usage fields with default values.
- Introduce Authentik identifiers and synchronization metadata.
- Refactor user domain logic for role and permission management.
- Update Prisma schema to support the new identity architecture.
- Improve JWT authentication and permission guard integration.
- Update repositories, handlers, controllers, mappers, DTOs, and Swagger configuration.
- Refresh environment configuration and project dependencies.
This commit is contained in:
Rayyan
2026-08-02 00:25:36 +07:00
parent fdbfb34842
commit 7ce0de4e91
132 changed files with 7754 additions and 2037 deletions
+46
View File
@@ -0,0 +1,46 @@
import { Module } from '@nestjs/common';
import { AuthController } from './auth.controller';
import { AuthService } from './auth.service';
import { ConfigModule, ConfigService } from '@nestjs/config';
import { JwtModule } from '@nestjs/jwt';
import { PrismaService } from '../../shared/prisma.service';
import { IUser } from '../identity/domain/repositories/user.interface';
import { PrismaUserRepository } from '../identity/infrastructure/repositories/prisma-user.repository';
import { SyncIdentityHandler } from '../identity/application/handlers/user/sync-identity.handler';
import { IRole } from '../identity/domain/repositories/role.interface';
import { PrismaRoleRepository } from '../identity/infrastructure/repositories/prisma-role.repository';
import { IAuthConfig } from '../identity/application/config/i-auth-config';
import { EnvAuthConfig } from '../identity/application/config/env-auth-config';
import { RedisPkceStore } from './pkce/redis-pkce.store';
import { InMemoryRefreshStore } from './refresh/inmemory-refresh.store';
@Module({
imports: [
ConfigModule,
JwtModule.registerAsync({
imports: [ConfigModule],
useFactory: async (config: ConfigService) => ({
secret: config.get('RAYLAB_JWT_SECRET') || 'raylab-secret',
signOptions: { algorithm: 'HS256' },
}),
inject: [ConfigService],
}),
],
controllers: [AuthController],
providers: [
AuthService,
PrismaService,
PrismaUserRepository,
PrismaRoleRepository,
SyncIdentityHandler,
{ provide: IUser, useClass: PrismaUserRepository },
{ provide: IRole, useClass: PrismaRoleRepository },
{ provide: IAuthConfig, useClass: EnvAuthConfig },
// In-memory PKCE and Refresh stores (Redis removed)
RedisPkceStore,
InMemoryRefreshStore,
],
exports: [AuthService],
})
export class AuthModule {}