```
feat(core): 添加多API密钥支持和配置字段 添加了api_keys、audit_api_keys、approval_api_keys等字段用于支持多个服务密钥, 新增masked_response_fields用于配置响应掩码字段,以及legacy相关配置项。 feat(core): 增强响应数据掩码功能 扩展mask_configured函数支持域名参数,实现更精确的敏感字段掩码控制, 添加自定义掩码字段配置验证器。 feat(scheduler): 添加遗留系统同步调度任务 集成遗留项目和任务同步到定时调度器中,支持通过配置启用或禁用同步功能, 并可设置不同的执行时间计划。 feat(security): 实现多服务密钥认证机制 重构API密钥验证逻辑,支持单个主密钥和多个配置密钥的混合验证模式, 增加服务密钥启用状态检查和角色映射功能。 feat(task_queue): 扩展现有队列任务处理 为日常简报和周报推送任务添加Celery异步处理支持,新增遗留项目和任务同步任务, 统一任务分发接口。 feat(business): 扩展业务模型字段 为工作任务模型添加外部系统标识和外部ID字段,为风险事件模型增加分配、解决、关闭 等相关字段,并创建风险事件操作记录表。 feat(legacy_mysql): 实现遗留任务同步功能 添加遗留任务查询和同步路由,支持从旧MySQL数据库同步任务数据到内部系统, 包括同步结果统计和运行记录。 refactor(dashboard): 更新仪表板统计数据 增加未分配风险和失败推送运行统计,在概览中显示最新的推送和同步运行记录, 完善数据序列化展示。 fix(feishu): 修复审批事件重复处理 实现审批卡片操作事件的唯一性检查,防止重复审批操作,添加事件审计日志记录。 ```
This commit is contained in:
@@ -24,18 +24,24 @@ class Settings(BaseSettings):
|
||||
api_prefix: str = "/api/v1"
|
||||
api_key: str | None = None
|
||||
api_actor: str = ActorValue.API
|
||||
api_keys: list[dict[str, Any]] = Field(default_factory=list)
|
||||
audit_api_key: str | None = None
|
||||
audit_api_actor: str = ActorValue.AUDITOR
|
||||
audit_api_keys: list[dict[str, Any]] = Field(default_factory=list)
|
||||
approval_api_key: str | None = None
|
||||
approval_api_actor: str = ActorValue.APPROVER
|
||||
approval_api_keys: list[dict[str, Any]] = Field(default_factory=list)
|
||||
cors_origins: list[str] = Field(default_factory=lambda: ["*"])
|
||||
mask_sensitive_responses: bool = True
|
||||
masked_response_fields: list[str] = Field(default_factory=list)
|
||||
|
||||
database_url: str = "sqlite:///./company_ai.db"
|
||||
legacy_database_url: str | None = None
|
||||
legacy_project_query: str | None = None
|
||||
legacy_task_query: str | None = None
|
||||
legacy_allowed_queries: dict[str, str] = Field(default_factory=dict)
|
||||
legacy_project_code_prefix: str = "LEGACY"
|
||||
legacy_task_code_prefix: str = "LEGACY-TASK"
|
||||
redis_url: str = "redis://127.0.0.1:6379/0"
|
||||
|
||||
feishu_base_url: str = "https://open.feishu.cn/open-apis"
|
||||
@@ -66,12 +72,17 @@ class Settings(BaseSettings):
|
||||
scheduler_enabled: bool = False
|
||||
task_queue_enabled: bool = False
|
||||
task_queue_always_eager: bool = False
|
||||
legacy_sync_enabled: bool = False
|
||||
celery_result_backend_url: str | None = None
|
||||
daily_brief_cron_hour: int = 9
|
||||
daily_brief_cron_minute: int = 0
|
||||
weekly_project_report_day_of_week: str = "mon"
|
||||
weekly_project_report_cron_hour: int = 9
|
||||
weekly_project_report_cron_minute: int = 30
|
||||
legacy_project_sync_cron_hour: int = 2
|
||||
legacy_project_sync_cron_minute: int = 0
|
||||
legacy_task_sync_cron_hour: int = 2
|
||||
legacy_task_sync_cron_minute: int = 30
|
||||
|
||||
@field_validator("cors_origins", mode="before")
|
||||
@classmethod
|
||||
@@ -95,6 +106,39 @@ class Settings(BaseSettings):
|
||||
return value
|
||||
return [item.strip() for item in value.split(",") if item.strip()]
|
||||
|
||||
@field_validator("masked_response_fields", mode="before")
|
||||
@classmethod
|
||||
def parse_masked_response_fields(cls, value: Any) -> list[str]:
|
||||
if isinstance(value, list):
|
||||
return [str(item).strip() for item in value if str(item).strip()]
|
||||
if value is None:
|
||||
return []
|
||||
text = str(value).strip()
|
||||
if not text:
|
||||
return []
|
||||
if text.startswith("["):
|
||||
data = json.loads(text)
|
||||
if not isinstance(data, list):
|
||||
raise ValueError(ConfigErrorDetail.CORS_ORIGINS_FORMAT)
|
||||
return [str(item).strip() for item in data if str(item).strip()]
|
||||
return [item.strip() for item in text.split(",") if item.strip()]
|
||||
|
||||
@field_validator("api_keys", "audit_api_keys", "approval_api_keys", mode="before")
|
||||
@classmethod
|
||||
def parse_service_keys(cls, value: Any) -> list[dict[str, Any]]:
|
||||
if value is None or value == "":
|
||||
return []
|
||||
if isinstance(value, list):
|
||||
return [dict(item) for item in value if isinstance(item, dict)]
|
||||
if isinstance(value, str):
|
||||
data = json.loads(value)
|
||||
if not isinstance(data, list):
|
||||
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
|
||||
if not all(isinstance(item, dict) for item in data):
|
||||
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
|
||||
return [dict(item) for item in data]
|
||||
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
|
||||
|
||||
@field_validator("legacy_allowed_queries", mode="before")
|
||||
@classmethod
|
||||
def parse_legacy_allowed_queries(cls, value: Any) -> dict[str, str]:
|
||||
|
||||
@@ -37,6 +37,7 @@ class SecurityErrorDetail(StrEnum):
|
||||
class ConfigErrorDetail(StrEnum):
|
||||
CORS_ORIGINS_FORMAT = "CORS_ORIGINS must be a CSV string or JSON list"
|
||||
LEGACY_ALLOWED_QUERIES_FORMAT = "LEGACY_ALLOWED_QUERIES must be a JSON object"
|
||||
SERVICE_KEYS_FORMAT = "Service keys must be a JSON list of objects"
|
||||
|
||||
|
||||
BEARER_TOKEN_TEMPLATE = "Bearer {token}"
|
||||
|
||||
@@ -28,27 +28,41 @@ SENSITIVE_RESPONSE_KEYS = frozenset(
|
||||
)
|
||||
|
||||
|
||||
def mask_configured(value: Any) -> Any:
|
||||
def mask_configured(value: Any, domain: str | None = None) -> Any:
|
||||
"""Mask sensitive response fields when response masking is enabled."""
|
||||
|
||||
settings = get_settings()
|
||||
if not settings.mask_sensitive_responses:
|
||||
return value
|
||||
return mask_sensitive(value)
|
||||
configured_fields = {item.lower() for item in settings.masked_response_fields}
|
||||
return mask_sensitive(value, domain=domain, configured_fields=configured_fields)
|
||||
|
||||
|
||||
def mask_sensitive(value: Any) -> Any:
|
||||
def mask_sensitive(
|
||||
value: Any,
|
||||
domain: str | None = None,
|
||||
configured_fields: set[str] | None = None,
|
||||
) -> Any:
|
||||
if isinstance(value, dict):
|
||||
masked: dict[str, Any] = {}
|
||||
for key, item in value.items():
|
||||
key_text = str(key)
|
||||
if key_text.lower() in SENSITIVE_RESPONSE_KEYS:
|
||||
if _should_mask(key_text, domain, configured_fields or set()):
|
||||
masked[key_text] = MASKED_VALUE
|
||||
else:
|
||||
masked[key_text] = mask_sensitive(item)
|
||||
masked[key_text] = mask_sensitive(item, domain, configured_fields)
|
||||
return masked
|
||||
if isinstance(value, list):
|
||||
return [mask_sensitive(item) for item in value]
|
||||
return [mask_sensitive(item, domain, configured_fields) for item in value]
|
||||
if isinstance(value, tuple):
|
||||
return [mask_sensitive(item) for item in value]
|
||||
return [mask_sensitive(item, domain, configured_fields) for item in value]
|
||||
return value
|
||||
|
||||
|
||||
def _should_mask(key: str, domain: str | None, configured_fields: set[str]) -> bool:
|
||||
field = key.lower()
|
||||
if field in SENSITIVE_RESPONSE_KEYS or field in configured_fields:
|
||||
return True
|
||||
if f"*.{field}" in configured_fields:
|
||||
return True
|
||||
return bool(domain and f"{domain.lower()}.{field}" in configured_fields)
|
||||
|
||||
@@ -15,7 +15,12 @@ def attach_scheduler(app: FastAPI) -> None:
|
||||
from apscheduler.schedulers.background import BackgroundScheduler
|
||||
|
||||
from app.core.database import SessionLocal
|
||||
from app.core.task_queue import enqueue_daily_brief_push, enqueue_project_weekly_push
|
||||
from app.core.task_queue import (
|
||||
enqueue_daily_brief_push,
|
||||
enqueue_legacy_project_sync,
|
||||
enqueue_legacy_task_sync,
|
||||
enqueue_project_weekly_push,
|
||||
)
|
||||
from app.modules.reports.service import ReportService
|
||||
|
||||
scheduler = BackgroundScheduler(timezone="Asia/Shanghai")
|
||||
@@ -72,6 +77,16 @@ def attach_scheduler(app: FastAPI) -> None:
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
def run_legacy_project_sync() -> None:
|
||||
app.state.last_legacy_project_sync_dispatch = enqueue_legacy_project_sync(
|
||||
actor=ActorValue.SCHEDULER,
|
||||
)
|
||||
|
||||
def run_legacy_task_sync() -> None:
|
||||
app.state.last_legacy_task_sync_dispatch = enqueue_legacy_task_sync(
|
||||
actor=ActorValue.SCHEDULER,
|
||||
)
|
||||
|
||||
scheduler.add_job(
|
||||
run_daily_brief,
|
||||
trigger="cron",
|
||||
@@ -89,6 +104,24 @@ def attach_scheduler(app: FastAPI) -> None:
|
||||
id="project_weekly_push",
|
||||
replace_existing=True,
|
||||
)
|
||||
if settings.legacy_sync_enabled and settings.legacy_project_query:
|
||||
scheduler.add_job(
|
||||
run_legacy_project_sync,
|
||||
trigger="cron",
|
||||
hour=settings.legacy_project_sync_cron_hour,
|
||||
minute=settings.legacy_project_sync_cron_minute,
|
||||
id="legacy_project_sync",
|
||||
replace_existing=True,
|
||||
)
|
||||
if settings.legacy_sync_enabled and settings.legacy_task_query:
|
||||
scheduler.add_job(
|
||||
run_legacy_task_sync,
|
||||
trigger="cron",
|
||||
hour=settings.legacy_task_sync_cron_hour,
|
||||
minute=settings.legacy_task_sync_cron_minute,
|
||||
id="legacy_task_sync",
|
||||
replace_existing=True,
|
||||
)
|
||||
|
||||
@app.on_event("startup")
|
||||
def start_scheduler() -> None:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
from dataclasses import dataclass
|
||||
from secrets import compare_digest
|
||||
from typing import Any
|
||||
|
||||
from fastapi import Header, HTTPException, status
|
||||
|
||||
@@ -20,17 +21,23 @@ def require_api_key(
|
||||
"""Validate the internal API key header and return its service principal."""
|
||||
|
||||
settings = get_settings()
|
||||
if not settings.api_key:
|
||||
if not settings.api_key and not _has_enabled_keys(settings.api_keys):
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
|
||||
detail=SecurityErrorDetail.API_KEY_REQUIRED,
|
||||
)
|
||||
if not x_api_key or not compare_digest(x_api_key, settings.api_key):
|
||||
principal = _match_service_key(
|
||||
x_api_key,
|
||||
settings.api_key,
|
||||
settings.api_actor,
|
||||
settings.api_keys,
|
||||
)
|
||||
if principal is None:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail=SecurityErrorDetail.INVALID_API_KEY,
|
||||
)
|
||||
return ApiPrincipal(actor=settings.api_actor)
|
||||
return principal
|
||||
|
||||
|
||||
def require_approval_api_key(
|
||||
@@ -42,20 +49,23 @@ def require_approval_api_key(
|
||||
"""Validate the approval API key and return the approval principal."""
|
||||
|
||||
settings = get_settings()
|
||||
if not settings.approval_api_key:
|
||||
if not settings.approval_api_key and not _has_enabled_keys(settings.approval_api_keys):
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
|
||||
detail=SecurityErrorDetail.APPROVAL_API_KEY_REQUIRED,
|
||||
)
|
||||
if (
|
||||
not x_approval_api_key
|
||||
or not compare_digest(x_approval_api_key, settings.approval_api_key)
|
||||
):
|
||||
principal = _match_service_key(
|
||||
x_approval_api_key,
|
||||
settings.approval_api_key,
|
||||
settings.approval_api_actor,
|
||||
settings.approval_api_keys,
|
||||
)
|
||||
if principal is None:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail=SecurityErrorDetail.INVALID_APPROVAL_API_KEY,
|
||||
)
|
||||
return ApiPrincipal(actor=settings.approval_api_actor)
|
||||
return principal
|
||||
|
||||
|
||||
def require_audit_api_key(
|
||||
@@ -67,14 +77,50 @@ def require_audit_api_key(
|
||||
"""Validate the audit API key and return the audit principal."""
|
||||
|
||||
settings = get_settings()
|
||||
if not settings.audit_api_key:
|
||||
if not settings.audit_api_key and not _has_enabled_keys(settings.audit_api_keys):
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
|
||||
detail=SecurityErrorDetail.AUDIT_API_KEY_REQUIRED,
|
||||
)
|
||||
if not x_audit_api_key or not compare_digest(x_audit_api_key, settings.audit_api_key):
|
||||
principal = _match_service_key(
|
||||
x_audit_api_key,
|
||||
settings.audit_api_key,
|
||||
settings.audit_api_actor,
|
||||
settings.audit_api_keys,
|
||||
)
|
||||
if principal is None:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail=SecurityErrorDetail.INVALID_AUDIT_API_KEY,
|
||||
)
|
||||
return ApiPrincipal(actor=settings.audit_api_actor)
|
||||
return principal
|
||||
|
||||
|
||||
def _has_enabled_keys(configured_keys: list[dict[str, Any]]) -> bool:
|
||||
return any(_key_enabled(item) and item.get("key") for item in configured_keys)
|
||||
|
||||
|
||||
def _match_service_key(
|
||||
provided_key: str | None,
|
||||
legacy_key: str | None,
|
||||
legacy_actor: str,
|
||||
configured_keys: list[dict[str, Any]],
|
||||
) -> ApiPrincipal | None:
|
||||
if not provided_key:
|
||||
return None
|
||||
if legacy_key and compare_digest(provided_key, legacy_key):
|
||||
return ApiPrincipal(actor=legacy_actor)
|
||||
for item in configured_keys:
|
||||
key = item.get("key")
|
||||
if not key or not _key_enabled(item):
|
||||
continue
|
||||
if compare_digest(provided_key, str(key)):
|
||||
return ApiPrincipal(actor=str(item.get("actor") or legacy_actor))
|
||||
return None
|
||||
|
||||
|
||||
def _key_enabled(item: dict[str, Any]) -> bool:
|
||||
value = item.get("enabled", True)
|
||||
if isinstance(value, bool):
|
||||
return value
|
||||
return str(value).strip().lower() not in {"0", "false", "no", "off", "disabled"}
|
||||
|
||||
@@ -7,6 +7,8 @@ from app.modules.feishu.constants import FeishuReceiveIdType
|
||||
TASK_PUSH_DAILY_BRIEF = "reports.push_daily_brief"
|
||||
TASK_PUSH_PROJECT_WEEKLY = "reports.push_project_weekly"
|
||||
TASK_GENERATE_RISK_EVENTS = "risks.generate_events"
|
||||
TASK_SYNC_LEGACY_PROJECTS = "legacy.sync_projects"
|
||||
TASK_SYNC_LEGACY_TASKS = "legacy.sync_tasks"
|
||||
|
||||
|
||||
def dispatch_task(
|
||||
@@ -40,6 +42,47 @@ def enqueue_daily_brief_push(
|
||||
receive_id_type: str = FeishuReceiveIdType.CHAT_ID,
|
||||
actor: str = "scheduler",
|
||||
) -> dict[str, Any]:
|
||||
settings = get_settings()
|
||||
if settings.task_queue_enabled:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.reports.constants import ReportPushStatus, ReportTitle, ReportType
|
||||
from app.modules.reports.service import ReportService
|
||||
from app.tasks import celery_app
|
||||
|
||||
db = SessionLocal()
|
||||
try:
|
||||
push_run = ReportService(db).create_push_run(
|
||||
report_type=ReportType.DAILY,
|
||||
title=ReportTitle.DAILY_BRIEF,
|
||||
receive_id=receive_id,
|
||||
receive_id_type=receive_id_type,
|
||||
actor=actor,
|
||||
status=ReportPushStatus.QUEUED,
|
||||
)
|
||||
async_result = celery_app.signature(
|
||||
TASK_PUSH_DAILY_BRIEF,
|
||||
kwargs={
|
||||
"receive_id": receive_id,
|
||||
"receive_id_type": receive_id_type,
|
||||
"actor": actor,
|
||||
"push_run_code": push_run.code,
|
||||
},
|
||||
).apply_async()
|
||||
ReportService(db).update_push_run(
|
||||
push_run.code,
|
||||
ReportPushStatus.QUEUED,
|
||||
task_id=async_result.id,
|
||||
)
|
||||
finally:
|
||||
db.close()
|
||||
return {
|
||||
"queued": True,
|
||||
"mode": "celery",
|
||||
"task_name": TASK_PUSH_DAILY_BRIEF,
|
||||
"task_id": async_result.id,
|
||||
"push_run_code": push_run.code,
|
||||
}
|
||||
|
||||
def inline() -> Any:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.reports.service import ReportService
|
||||
@@ -67,6 +110,47 @@ def enqueue_project_weekly_push(
|
||||
receive_id_type: str = FeishuReceiveIdType.CHAT_ID,
|
||||
actor: str = "scheduler",
|
||||
) -> dict[str, Any]:
|
||||
settings = get_settings()
|
||||
if settings.task_queue_enabled:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.reports.constants import ReportPushStatus, ReportTitle, ReportType
|
||||
from app.modules.reports.service import ReportService
|
||||
from app.tasks import celery_app
|
||||
|
||||
db = SessionLocal()
|
||||
try:
|
||||
push_run = ReportService(db).create_push_run(
|
||||
report_type=ReportType.WEEKLY,
|
||||
title=ReportTitle.PROJECT_WEEKLY,
|
||||
receive_id=receive_id,
|
||||
receive_id_type=receive_id_type,
|
||||
actor=actor,
|
||||
status=ReportPushStatus.QUEUED,
|
||||
)
|
||||
async_result = celery_app.signature(
|
||||
TASK_PUSH_PROJECT_WEEKLY,
|
||||
kwargs={
|
||||
"receive_id": receive_id,
|
||||
"receive_id_type": receive_id_type,
|
||||
"actor": actor,
|
||||
"push_run_code": push_run.code,
|
||||
},
|
||||
).apply_async()
|
||||
ReportService(db).update_push_run(
|
||||
push_run.code,
|
||||
ReportPushStatus.QUEUED,
|
||||
task_id=async_result.id,
|
||||
)
|
||||
finally:
|
||||
db.close()
|
||||
return {
|
||||
"queued": True,
|
||||
"mode": "celery",
|
||||
"task_name": TASK_PUSH_PROJECT_WEEKLY,
|
||||
"task_id": async_result.id,
|
||||
"push_run_code": push_run.code,
|
||||
}
|
||||
|
||||
def inline() -> Any:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.reports.service import ReportService
|
||||
@@ -105,3 +189,81 @@ def enqueue_risk_event_generation(actor: str = "scheduler") -> dict[str, Any]:
|
||||
{"actor": actor},
|
||||
inline,
|
||||
)
|
||||
|
||||
|
||||
def enqueue_legacy_project_sync(
|
||||
source_query: str | None = None,
|
||||
source_query_name: str | None = None,
|
||||
field_map: dict[str, str] | None = None,
|
||||
limit: int = 100,
|
||||
dry_run: bool = False,
|
||||
actor: str = "scheduler",
|
||||
) -> dict[str, Any]:
|
||||
def inline() -> Any:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.legacy_mysql.service import LegacyMySQLService
|
||||
|
||||
db = SessionLocal()
|
||||
try:
|
||||
return LegacyMySQLService(db).sync_projects(
|
||||
source_query=source_query,
|
||||
source_query_name=source_query_name,
|
||||
field_map=field_map or {},
|
||||
limit=limit,
|
||||
dry_run=dry_run,
|
||||
actor=actor,
|
||||
)
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
return dispatch_task(
|
||||
TASK_SYNC_LEGACY_PROJECTS,
|
||||
{
|
||||
"source_query": source_query,
|
||||
"source_query_name": source_query_name,
|
||||
"field_map": field_map or {},
|
||||
"limit": limit,
|
||||
"dry_run": dry_run,
|
||||
"actor": actor,
|
||||
},
|
||||
inline,
|
||||
)
|
||||
|
||||
|
||||
def enqueue_legacy_task_sync(
|
||||
source_query: str | None = None,
|
||||
source_query_name: str | None = None,
|
||||
field_map: dict[str, str] | None = None,
|
||||
limit: int = 100,
|
||||
dry_run: bool = False,
|
||||
actor: str = "scheduler",
|
||||
) -> dict[str, Any]:
|
||||
def inline() -> Any:
|
||||
from app.core.database import SessionLocal
|
||||
from app.modules.legacy_mysql.service import LegacyMySQLService
|
||||
|
||||
db = SessionLocal()
|
||||
try:
|
||||
return LegacyMySQLService(db).sync_tasks(
|
||||
source_query=source_query,
|
||||
source_query_name=source_query_name,
|
||||
field_map=field_map or {},
|
||||
limit=limit,
|
||||
dry_run=dry_run,
|
||||
actor=actor,
|
||||
)
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
return dispatch_task(
|
||||
TASK_SYNC_LEGACY_TASKS,
|
||||
{
|
||||
"source_query": source_query,
|
||||
"source_query_name": source_query_name,
|
||||
"field_map": field_map or {},
|
||||
"limit": limit,
|
||||
"dry_run": dry_run,
|
||||
"actor": actor,
|
||||
},
|
||||
inline,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user