feat(domain): 领域模块——项目/角色/工作流/Agent - #150
Conversation
- Add backend/Dockerfile with multi-stage build (uv + Python 3.12) - Add docker-compose.yml with backend and PostgreSQL services - Add db/init.sql for automatic database table initialization - Add .env.example with configuration template - PostgreSQL configured with port 7856 and secure password
…browser 三处让部署跑不起来的问题,都在这台服务器上实测定位: 1. 构建阶段 uv sync 超时。宿主机访问 pypi.org 需 8s,构建容器内默认超时会在 下载大包(uvloop)时 "operation timed out" 直接失败。改走国内镜像源并把 UV_HTTP_TIMEOUT 拉到 180s。 2. 容器起来即反复重启,报 "exec /app/.venv/bin/uvicorn: no such file or directory"。 文件其实存在,报的是它 shebang 指向的解释器——uv 装出来的 venv 里 shebang 与 .pth 都是绝对路径,builder 在 /build、runtime 在 /app,跨路径拷贝后解释器与 workspace 包全部失效。把 builder 的 WORKDIR 也改成 /app 即可。 3. 七牛上传 TLS 握手超时、媒体上传请求挂死。宿主机网卡 MTU 1480,而 compose 自建网络不继承 daemon 的 mtu 设置、默认仍是 1500,大包被丢。显式给网络设 1450 后,up-z0.qiniup.com 从握手超时 14s 变为 1.0s,上传恢复正常。 4. 浏览器跨域被全部拦下:OPTIONS 预检返回 405、响应无 access-control-* 头, 后端日志里连请求都看不到。挂上 CORSMiddleware,允许来源用 WINDUP_CORS_ORIGINS 覆盖,并放行 Vercel 预览域名。 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
后端验证码/refresh_token 依赖 Redis,原 compose 只有 Postgres。 新增 redis:7-alpine 服务(含健康检查),backend depends_on 等待就绪, 环境变量 REDIS_URL=redis://redis:6379/0。
ORM 声明了 UniqueConstraint(user_id, project_name),但 init.sql 建表时遗漏。 生产 Postgres 并发创建同名项目不会触发 IntegrityError,API 兜底失效。 补上 CONSTRAINT uq_windup_project_user_name UNIQUE (user_id, project_name)。
…imiting - 注册/登录(邮箱+验证码+密码)、免密登录、刷新 token、登出、改密 - JWT 鉴权中间件(白名单放行 + request.state.current_user 注入) - 邮箱验证码(Redis 存储 + 冷却计时) - 接口限流中间件(Redis 滑动窗口 + 降级策略) - Redis 连接配置与客户端单例 - 22 个集成测试覆盖完整认证链路
- Add auth_client fixture with valid JWT token - Update test_project_api.py to use auth_client - Fix CI failures caused by auth middleware blocking unauthenticated requests
- workflow_run 模块:接口、ORM 模型、JSONB 节点树 schema - agent 模块:SSE 会话管理骨架 - project/character 模块:接口、ORM 模型、service 实现 - 统一异常处理器(BizException 继承体系) - media 上传 API
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
| # ── 端点 ───────────────────────────────────────────────────────────────────── | ||
|
|
||
|
|
||
| @router.post("", response_model=Response[CharacterOut]) |
There was a problem hiding this comment.
High: this module never checks that project_id belongs to request.state.current_user, so an authenticated user can create and mutate characters in another user's project. The same gap applies to the list/get/update/delete handlers below, which also trust raw IDs without ownership validation.
| if user is None: | ||
| raise BizException("邮箱或密码错误", code=BizCode.BAD_REQUEST) | ||
|
|
||
| if not _verify_password(input.password, user.password_hash): |
There was a problem hiding this comment.
High: code-login accounts are created with password_hash="" at line 284, so this bcrypt check can raise instead of returning the documented business error. That leaves both the password-login and change-password flows with a 500 for code-only accounts.
| POSTGRES_HOST: postgres | ||
| POSTGRES_PORT: 5432 | ||
| POSTGRES_USER: ${POSTGRES_USER:-root} | ||
| POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-admin123} |
There was a problem hiding this comment.
High: this backend default password (admin123) does not match the postgres service default above (W1ndup@2026!Secure). A plain docker compose up therefore starts a backend that cannot authenticate to Postgres unless the operator overrides one of the defaults.
概述
领域业务层:项目、角色、工作流运行、智能体四个模块的接口定义、ORM 模型、Service 实现与 API 端点。
包含内容
项目模块(server/project + web/api/project)
角色模块(server/character + web/api/character)
工作流运行(server/workflow_run)
智能体(web/api/agent)
统一异常处理(web/handler)
测试
test_project_api.py:9 用例test_character_api.py:3 用例关联