feat: implement Extensions with real FreeSWITCH directory integration
- extensions table (tenant-scoped, RLS): number, sip_password_enc
(AES-256-GCM via packages/shared/src/crypto.ts), caller_id, context,
sofia_profile, codecs, max_registrations
- apps/api/src/extensions: CRUD (POST/GET/GET:id/DELETE), protected by a
new generic PermissionGuard (@RequirePermission decorator), tenant
resolved only from the JWT (never trusted from the client)
- SIP password is returned in plaintext only once, in the create response;
toPublicExtension() explicitly destructures the encrypted field out
(not a spread) so it can't leak by accident
- b2bcall-fs-config now resolves real directory data: Tenant.telephonyDomain
-> Extension.number, decrypts the password, builds proper directory XML
including a dial-string param (missing it caused originate to fail with
MANDATORY_IE_MISSING instead of the expected USER_NOT_REGISTERED)
- pinned FreeSWITCH's 357737{domain} to a stable value (b2bcall.local) via a
vars.xml patch in the Dockerfile -- it previously used the container's
dynamic IP, which could never match a stored telephony_domain
- added HTTP Basic auth between FreeSWITCH and fs-config
(gateway-credentials, timingSafeEqual comparison) now that the service
returns real secret data, closing the gap flagged as pending in the XML
Curl phase instead of leaving it open
- found and fixed: PermissionGuard's constructor-injected Reflector came
back undefined at runtime under tsx/esbuild (unreliable cross-file
decorator metadata emission) -- fixed with an explicit @Inject(Reflector);
worth watching for in future guards/services run via tsx
- verified end-to-end: create extension -> originate user/<ext> reports
USER_NOT_REGISTERED (found, not registered) -> delete -> back to
SUBSCRIBER_ABSENT (not found); password never reappears in any GET;
unauthenticated fs-config requests get 401
- docs/EXTENSIONS.md
This commit is contained in:
@@ -38,6 +38,15 @@ services:
|
||||
dockerfile: apps/freeswitch-config/Dockerfile
|
||||
container_name: b2bcall-fs-config
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
- postgres
|
||||
environment:
|
||||
# Hostname interno do compose (postgres), nao localhost — ver
|
||||
# docs/NETWORK_ARCHITECTURE.md.
|
||||
APP_DATABASE_URL: postgresql://${POSTGRES_APP_USER}:${POSTGRES_APP_PASSWORD}@postgres:5432/${POSTGRES_DB}?schema=public
|
||||
ENCRYPTION_KEY: ${ENCRYPTION_KEY}
|
||||
FS_CONFIG_USER: ${FS_CONFIG_USER}
|
||||
FS_CONFIG_PASSWORD: ${FS_CONFIG_PASSWORD}
|
||||
# Sem porta publicada: so o FreeSWITCH (mesma rede do compose) chama isto.
|
||||
healthcheck:
|
||||
test: ["CMD", "node", "-e", "fetch('http://localhost:8080/health').then(r => process.exit(r.ok ? 0 : 1)).catch(() => process.exit(1))"]
|
||||
@@ -57,6 +66,8 @@ services:
|
||||
- fs-config
|
||||
environment:
|
||||
ESL_PASSWORD: ${ESL_PASSWORD}
|
||||
FS_CONFIG_USER: ${FS_CONFIG_USER}
|
||||
FS_CONFIG_PASSWORD: ${FS_CONFIG_PASSWORD}
|
||||
# Nenhuma porta publicada no host: SIP/RTP ainda não têm troncos reais
|
||||
# configurados, e o Event Socket (8021) só deve ser alcançável por outros
|
||||
# containers na rede interna do compose (agente.md secao 22).
|
||||
|
||||
Reference in New Issue
Block a user