feat(core): 添加多API密钥支持和配置字段

添加了api_keys、audit_api_keys、approval_api_keys等字段用于支持多个服务密钥,
新增masked_response_fields用于配置响应掩码字段,以及legacy相关配置项。

feat(core): 增强响应数据掩码功能

扩展mask_configured函数支持域名参数,实现更精确的敏感字段掩码控制,
添加自定义掩码字段配置验证器。

feat(scheduler): 添加遗留系统同步调度任务

集成遗留项目和任务同步到定时调度器中,支持通过配置启用或禁用同步功能,
并可设置不同的执行时间计划。

feat(security): 实现多服务密钥认证机制

重构API密钥验证逻辑,支持单个主密钥和多个配置密钥的混合验证模式,
增加服务密钥启用状态检查和角色映射功能。

feat(task_queue): 扩展现有队列任务处理

为日常简报和周报推送任务添加Celery异步处理支持,新增遗留项目和任务同步任务,
统一任务分发接口。

feat(business): 扩展业务模型字段

为工作任务模型添加外部系统标识和外部ID字段,为风险事件模型增加分配、解决、关闭
等相关字段,并创建风险事件操作记录表。

feat(legacy_mysql): 实现遗留任务同步功能

添加遗留任务查询和同步路由,支持从旧MySQL数据库同步任务数据到内部系统,
包括同步结果统计和运行记录。

refactor(dashboard): 更新仪表板统计数据

增加未分配风险和失败推送运行统计,在概览中显示最新的推送和同步运行记录,
完善数据序列化展示。

fix(feishu): 修复审批事件重复处理

实现审批卡片操作事件的唯一性检查,防止重复审批操作,添加事件审计日志记录。
```
This commit is contained in:
2026-07-08 12:05:09 +08:00
parent 4d09d8e2e3
commit 92f490b97e
28 changed files with 1746 additions and 35 deletions

View File

@@ -24,18 +24,24 @@ class Settings(BaseSettings):
api_prefix: str = "/api/v1"
api_key: str | None = None
api_actor: str = ActorValue.API
api_keys: list[dict[str, Any]] = Field(default_factory=list)
audit_api_key: str | None = None
audit_api_actor: str = ActorValue.AUDITOR
audit_api_keys: list[dict[str, Any]] = Field(default_factory=list)
approval_api_key: str | None = None
approval_api_actor: str = ActorValue.APPROVER
approval_api_keys: list[dict[str, Any]] = Field(default_factory=list)
cors_origins: list[str] = Field(default_factory=lambda: ["*"])
mask_sensitive_responses: bool = True
masked_response_fields: list[str] = Field(default_factory=list)
database_url: str = "sqlite:///./company_ai.db"
legacy_database_url: str | None = None
legacy_project_query: str | None = None
legacy_task_query: str | None = None
legacy_allowed_queries: dict[str, str] = Field(default_factory=dict)
legacy_project_code_prefix: str = "LEGACY"
legacy_task_code_prefix: str = "LEGACY-TASK"
redis_url: str = "redis://127.0.0.1:6379/0"
feishu_base_url: str = "https://open.feishu.cn/open-apis"
@@ -66,12 +72,17 @@ class Settings(BaseSettings):
scheduler_enabled: bool = False
task_queue_enabled: bool = False
task_queue_always_eager: bool = False
legacy_sync_enabled: bool = False
celery_result_backend_url: str | None = None
daily_brief_cron_hour: int = 9
daily_brief_cron_minute: int = 0
weekly_project_report_day_of_week: str = "mon"
weekly_project_report_cron_hour: int = 9
weekly_project_report_cron_minute: int = 30
legacy_project_sync_cron_hour: int = 2
legacy_project_sync_cron_minute: int = 0
legacy_task_sync_cron_hour: int = 2
legacy_task_sync_cron_minute: int = 30
@field_validator("cors_origins", mode="before")
@classmethod
@@ -95,6 +106,39 @@ class Settings(BaseSettings):
return value
return [item.strip() for item in value.split(",") if item.strip()]
@field_validator("masked_response_fields", mode="before")
@classmethod
def parse_masked_response_fields(cls, value: Any) -> list[str]:
if isinstance(value, list):
return [str(item).strip() for item in value if str(item).strip()]
if value is None:
return []
text = str(value).strip()
if not text:
return []
if text.startswith("["):
data = json.loads(text)
if not isinstance(data, list):
raise ValueError(ConfigErrorDetail.CORS_ORIGINS_FORMAT)
return [str(item).strip() for item in data if str(item).strip()]
return [item.strip() for item in text.split(",") if item.strip()]
@field_validator("api_keys", "audit_api_keys", "approval_api_keys", mode="before")
@classmethod
def parse_service_keys(cls, value: Any) -> list[dict[str, Any]]:
if value is None or value == "":
return []
if isinstance(value, list):
return [dict(item) for item in value if isinstance(item, dict)]
if isinstance(value, str):
data = json.loads(value)
if not isinstance(data, list):
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
if not all(isinstance(item, dict) for item in data):
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
return [dict(item) for item in data]
raise ValueError(ConfigErrorDetail.SERVICE_KEYS_FORMAT)
@field_validator("legacy_allowed_queries", mode="before")
@classmethod
def parse_legacy_allowed_queries(cls, value: Any) -> dict[str, str]:

View File

@@ -37,6 +37,7 @@ class SecurityErrorDetail(StrEnum):
class ConfigErrorDetail(StrEnum):
CORS_ORIGINS_FORMAT = "CORS_ORIGINS must be a CSV string or JSON list"
LEGACY_ALLOWED_QUERIES_FORMAT = "LEGACY_ALLOWED_QUERIES must be a JSON object"
SERVICE_KEYS_FORMAT = "Service keys must be a JSON list of objects"
BEARER_TOKEN_TEMPLATE = "Bearer {token}"

View File

@@ -28,27 +28,41 @@ SENSITIVE_RESPONSE_KEYS = frozenset(
)
def mask_configured(value: Any) -> Any:
def mask_configured(value: Any, domain: str | None = None) -> Any:
"""Mask sensitive response fields when response masking is enabled."""
settings = get_settings()
if not settings.mask_sensitive_responses:
return value
return mask_sensitive(value)
configured_fields = {item.lower() for item in settings.masked_response_fields}
return mask_sensitive(value, domain=domain, configured_fields=configured_fields)
def mask_sensitive(value: Any) -> Any:
def mask_sensitive(
value: Any,
domain: str | None = None,
configured_fields: set[str] | None = None,
) -> Any:
if isinstance(value, dict):
masked: dict[str, Any] = {}
for key, item in value.items():
key_text = str(key)
if key_text.lower() in SENSITIVE_RESPONSE_KEYS:
if _should_mask(key_text, domain, configured_fields or set()):
masked[key_text] = MASKED_VALUE
else:
masked[key_text] = mask_sensitive(item)
masked[key_text] = mask_sensitive(item, domain, configured_fields)
return masked
if isinstance(value, list):
return [mask_sensitive(item) for item in value]
return [mask_sensitive(item, domain, configured_fields) for item in value]
if isinstance(value, tuple):
return [mask_sensitive(item) for item in value]
return [mask_sensitive(item, domain, configured_fields) for item in value]
return value
def _should_mask(key: str, domain: str | None, configured_fields: set[str]) -> bool:
field = key.lower()
if field in SENSITIVE_RESPONSE_KEYS or field in configured_fields:
return True
if f"*.{field}" in configured_fields:
return True
return bool(domain and f"{domain.lower()}.{field}" in configured_fields)

View File

@@ -15,7 +15,12 @@ def attach_scheduler(app: FastAPI) -> None:
from apscheduler.schedulers.background import BackgroundScheduler
from app.core.database import SessionLocal
from app.core.task_queue import enqueue_daily_brief_push, enqueue_project_weekly_push
from app.core.task_queue import (
enqueue_daily_brief_push,
enqueue_legacy_project_sync,
enqueue_legacy_task_sync,
enqueue_project_weekly_push,
)
from app.modules.reports.service import ReportService
scheduler = BackgroundScheduler(timezone="Asia/Shanghai")
@@ -72,6 +77,16 @@ def attach_scheduler(app: FastAPI) -> None:
finally:
db.close()
def run_legacy_project_sync() -> None:
app.state.last_legacy_project_sync_dispatch = enqueue_legacy_project_sync(
actor=ActorValue.SCHEDULER,
)
def run_legacy_task_sync() -> None:
app.state.last_legacy_task_sync_dispatch = enqueue_legacy_task_sync(
actor=ActorValue.SCHEDULER,
)
scheduler.add_job(
run_daily_brief,
trigger="cron",
@@ -89,6 +104,24 @@ def attach_scheduler(app: FastAPI) -> None:
id="project_weekly_push",
replace_existing=True,
)
if settings.legacy_sync_enabled and settings.legacy_project_query:
scheduler.add_job(
run_legacy_project_sync,
trigger="cron",
hour=settings.legacy_project_sync_cron_hour,
minute=settings.legacy_project_sync_cron_minute,
id="legacy_project_sync",
replace_existing=True,
)
if settings.legacy_sync_enabled and settings.legacy_task_query:
scheduler.add_job(
run_legacy_task_sync,
trigger="cron",
hour=settings.legacy_task_sync_cron_hour,
minute=settings.legacy_task_sync_cron_minute,
id="legacy_task_sync",
replace_existing=True,
)
@app.on_event("startup")
def start_scheduler() -> None:

View File

@@ -1,5 +1,6 @@
from dataclasses import dataclass
from secrets import compare_digest
from typing import Any
from fastapi import Header, HTTPException, status
@@ -20,17 +21,23 @@ def require_api_key(
"""Validate the internal API key header and return its service principal."""
settings = get_settings()
if not settings.api_key:
if not settings.api_key and not _has_enabled_keys(settings.api_keys):
raise HTTPException(
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
detail=SecurityErrorDetail.API_KEY_REQUIRED,
)
if not x_api_key or not compare_digest(x_api_key, settings.api_key):
principal = _match_service_key(
x_api_key,
settings.api_key,
settings.api_actor,
settings.api_keys,
)
if principal is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=SecurityErrorDetail.INVALID_API_KEY,
)
return ApiPrincipal(actor=settings.api_actor)
return principal
def require_approval_api_key(
@@ -42,20 +49,23 @@ def require_approval_api_key(
"""Validate the approval API key and return the approval principal."""
settings = get_settings()
if not settings.approval_api_key:
if not settings.approval_api_key and not _has_enabled_keys(settings.approval_api_keys):
raise HTTPException(
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
detail=SecurityErrorDetail.APPROVAL_API_KEY_REQUIRED,
)
if (
not x_approval_api_key
or not compare_digest(x_approval_api_key, settings.approval_api_key)
):
principal = _match_service_key(
x_approval_api_key,
settings.approval_api_key,
settings.approval_api_actor,
settings.approval_api_keys,
)
if principal is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=SecurityErrorDetail.INVALID_APPROVAL_API_KEY,
)
return ApiPrincipal(actor=settings.approval_api_actor)
return principal
def require_audit_api_key(
@@ -67,14 +77,50 @@ def require_audit_api_key(
"""Validate the audit API key and return the audit principal."""
settings = get_settings()
if not settings.audit_api_key:
if not settings.audit_api_key and not _has_enabled_keys(settings.audit_api_keys):
raise HTTPException(
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
detail=SecurityErrorDetail.AUDIT_API_KEY_REQUIRED,
)
if not x_audit_api_key or not compare_digest(x_audit_api_key, settings.audit_api_key):
principal = _match_service_key(
x_audit_api_key,
settings.audit_api_key,
settings.audit_api_actor,
settings.audit_api_keys,
)
if principal is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=SecurityErrorDetail.INVALID_AUDIT_API_KEY,
)
return ApiPrincipal(actor=settings.audit_api_actor)
return principal
def _has_enabled_keys(configured_keys: list[dict[str, Any]]) -> bool:
return any(_key_enabled(item) and item.get("key") for item in configured_keys)
def _match_service_key(
provided_key: str | None,
legacy_key: str | None,
legacy_actor: str,
configured_keys: list[dict[str, Any]],
) -> ApiPrincipal | None:
if not provided_key:
return None
if legacy_key and compare_digest(provided_key, legacy_key):
return ApiPrincipal(actor=legacy_actor)
for item in configured_keys:
key = item.get("key")
if not key or not _key_enabled(item):
continue
if compare_digest(provided_key, str(key)):
return ApiPrincipal(actor=str(item.get("actor") or legacy_actor))
return None
def _key_enabled(item: dict[str, Any]) -> bool:
value = item.get("enabled", True)
if isinstance(value, bool):
return value
return str(value).strip().lower() not in {"0", "false", "no", "off", "disabled"}

View File

@@ -7,6 +7,8 @@ from app.modules.feishu.constants import FeishuReceiveIdType
TASK_PUSH_DAILY_BRIEF = "reports.push_daily_brief"
TASK_PUSH_PROJECT_WEEKLY = "reports.push_project_weekly"
TASK_GENERATE_RISK_EVENTS = "risks.generate_events"
TASK_SYNC_LEGACY_PROJECTS = "legacy.sync_projects"
TASK_SYNC_LEGACY_TASKS = "legacy.sync_tasks"
def dispatch_task(
@@ -40,6 +42,47 @@ def enqueue_daily_brief_push(
receive_id_type: str = FeishuReceiveIdType.CHAT_ID,
actor: str = "scheduler",
) -> dict[str, Any]:
settings = get_settings()
if settings.task_queue_enabled:
from app.core.database import SessionLocal
from app.modules.reports.constants import ReportPushStatus, ReportTitle, ReportType
from app.modules.reports.service import ReportService
from app.tasks import celery_app
db = SessionLocal()
try:
push_run = ReportService(db).create_push_run(
report_type=ReportType.DAILY,
title=ReportTitle.DAILY_BRIEF,
receive_id=receive_id,
receive_id_type=receive_id_type,
actor=actor,
status=ReportPushStatus.QUEUED,
)
async_result = celery_app.signature(
TASK_PUSH_DAILY_BRIEF,
kwargs={
"receive_id": receive_id,
"receive_id_type": receive_id_type,
"actor": actor,
"push_run_code": push_run.code,
},
).apply_async()
ReportService(db).update_push_run(
push_run.code,
ReportPushStatus.QUEUED,
task_id=async_result.id,
)
finally:
db.close()
return {
"queued": True,
"mode": "celery",
"task_name": TASK_PUSH_DAILY_BRIEF,
"task_id": async_result.id,
"push_run_code": push_run.code,
}
def inline() -> Any:
from app.core.database import SessionLocal
from app.modules.reports.service import ReportService
@@ -67,6 +110,47 @@ def enqueue_project_weekly_push(
receive_id_type: str = FeishuReceiveIdType.CHAT_ID,
actor: str = "scheduler",
) -> dict[str, Any]:
settings = get_settings()
if settings.task_queue_enabled:
from app.core.database import SessionLocal
from app.modules.reports.constants import ReportPushStatus, ReportTitle, ReportType
from app.modules.reports.service import ReportService
from app.tasks import celery_app
db = SessionLocal()
try:
push_run = ReportService(db).create_push_run(
report_type=ReportType.WEEKLY,
title=ReportTitle.PROJECT_WEEKLY,
receive_id=receive_id,
receive_id_type=receive_id_type,
actor=actor,
status=ReportPushStatus.QUEUED,
)
async_result = celery_app.signature(
TASK_PUSH_PROJECT_WEEKLY,
kwargs={
"receive_id": receive_id,
"receive_id_type": receive_id_type,
"actor": actor,
"push_run_code": push_run.code,
},
).apply_async()
ReportService(db).update_push_run(
push_run.code,
ReportPushStatus.QUEUED,
task_id=async_result.id,
)
finally:
db.close()
return {
"queued": True,
"mode": "celery",
"task_name": TASK_PUSH_PROJECT_WEEKLY,
"task_id": async_result.id,
"push_run_code": push_run.code,
}
def inline() -> Any:
from app.core.database import SessionLocal
from app.modules.reports.service import ReportService
@@ -105,3 +189,81 @@ def enqueue_risk_event_generation(actor: str = "scheduler") -> dict[str, Any]:
{"actor": actor},
inline,
)
def enqueue_legacy_project_sync(
source_query: str | None = None,
source_query_name: str | None = None,
field_map: dict[str, str] | None = None,
limit: int = 100,
dry_run: bool = False,
actor: str = "scheduler",
) -> dict[str, Any]:
def inline() -> Any:
from app.core.database import SessionLocal
from app.modules.legacy_mysql.service import LegacyMySQLService
db = SessionLocal()
try:
return LegacyMySQLService(db).sync_projects(
source_query=source_query,
source_query_name=source_query_name,
field_map=field_map or {},
limit=limit,
dry_run=dry_run,
actor=actor,
)
finally:
db.close()
return dispatch_task(
TASK_SYNC_LEGACY_PROJECTS,
{
"source_query": source_query,
"source_query_name": source_query_name,
"field_map": field_map or {},
"limit": limit,
"dry_run": dry_run,
"actor": actor,
},
inline,
)
def enqueue_legacy_task_sync(
source_query: str | None = None,
source_query_name: str | None = None,
field_map: dict[str, str] | None = None,
limit: int = 100,
dry_run: bool = False,
actor: str = "scheduler",
) -> dict[str, Any]:
def inline() -> Any:
from app.core.database import SessionLocal
from app.modules.legacy_mysql.service import LegacyMySQLService
db = SessionLocal()
try:
return LegacyMySQLService(db).sync_tasks(
source_query=source_query,
source_query_name=source_query_name,
field_map=field_map or {},
limit=limit,
dry_run=dry_run,
actor=actor,
)
finally:
db.close()
return dispatch_task(
TASK_SYNC_LEGACY_TASKS,
{
"source_query": source_query,
"source_query_name": source_query_name,
"field_map": field_map or {},
"limit": limit,
"dry_run": dry_run,
"actor": actor,
},
inline,
)