feat: add apps/api (NestJS + Fastify) with authentication endpoints
- POST /auth/login, /auth/refresh, /auth/logout, /auth/select-tenant, /auth/change-password, GET /auth/tenants — wired to packages/auth - JwtAuthGuard + DomainExceptionFilter (401/403 without leaking internals) - LoginRateLimitGuard: Redis-backed 5/min per IP and per email (agente.md secao 149), safe across multiple API instances - helmet + restrictive cors (deny-by-default) + global rate limit - GET /health, /health/live, /health/ready checking Postgres and Redis - changePassword() added to packages/auth for the mustChangePassword flow - fixed REDIS_HOST/POSTGRES_HOST docker-compose-only hostnames not resolving from the host process; added REDIS_URL for host-side use - verified end-to-end with curl: login, wrong password / unknown email (same generic error), authenticated route, missing token, refresh rotation, logout revocation, and the 429 rate limit kicking in after 5 attempts
This commit is contained in:
5
TODO.md
5
TODO.md
@@ -37,8 +37,9 @@
|
||||
- [x] Seed: catálogo de permissions + roles de sistema + Platform Super Admin inicial
|
||||
(senha em `FIRST_LOGIN.txt`, fora do Git, `mustChangePassword=true`)
|
||||
- [x] Teste automatizado (`pnpm --filter @b2bcall/auth run test:auth`)
|
||||
- [ ] Camada HTTP (endpoints, rate limit por IP, guards) — depende de `apps/api` existir,
|
||||
ver docs/AUTHENTICATION.md → "O que falta"
|
||||
- [x] `apps/api` (NestJS + Fastify): endpoints de auth, JwtAuthGuard, DomainExceptionFilter,
|
||||
rate limit de login via Redis (5/min por IP e por e-mail), helmet/cors, health checks
|
||||
— testado ponta a ponta com curl (login, refresh rotation, logout, RBAC, 401/403/429)
|
||||
- [ ] Password reset por e-mail — depende de SMTP configurado
|
||||
|
||||
## PHASE 05+ — ver `agente.md` seções 15 em diante (FreeSWITCH, Telefonia, Call Center,
|
||||
|
||||
Reference in New Issue
Block a user