v0.1.27
Fix: Throughput API v1 available - Details posted to Irving. POWERBI_KEY was missing from the .ENV file, so was not live. Add: Editor now supports editing a mix's resolved formula directly, with % and kg dual entry on ingredient rows Fix: Mix Editor should bring through correct ingredients. New resolved formula (same logic we use in Mix Calculator). Fix: Security headers on all API responses (hardening) Add: New mix button available on the Mix Editor. Add: New ingredient button available on the Ingredient Editor
This commit is contained in:
@@ -13,6 +13,8 @@ from app.schemas.editor import (
|
||||
EditorIngredientRow,
|
||||
EditorIngredientUpdate,
|
||||
EditorMixFormulaRead,
|
||||
EditorMixCreate,
|
||||
EditorMixFormulaReplace,
|
||||
EditorMixIngredientCreate,
|
||||
EditorMixIngredientUpdate,
|
||||
EditorMixRow,
|
||||
@@ -22,9 +24,11 @@ from app.schemas.editor import (
|
||||
EditorProductIngredientUpdate,
|
||||
EditorProductRow,
|
||||
EditorProductUpdate,
|
||||
EditorResolvedMixFormula,
|
||||
)
|
||||
from app.services.client_access_service import has_access_level
|
||||
from app.services.costing_engine import calculate_raw_material_cost, get_active_price
|
||||
from app.services.mix_calculator_service import resolve_editor_mix_formula, resolve_representative_product
|
||||
|
||||
router = APIRouter(prefix="/api/editor", tags=["editor"])
|
||||
|
||||
@@ -250,6 +254,25 @@ def list_editor_mixes(
|
||||
]
|
||||
|
||||
|
||||
@router.post("/mixes", response_model=EditorMixRow, status_code=201)
|
||||
def create_editor_mix(
|
||||
payload: EditorMixCreate,
|
||||
session: AuthSession = Depends(_require_editor_session),
|
||||
db: Session = Depends(get_db),
|
||||
):
|
||||
mix = Mix(
|
||||
tenant_id=session.tenant_id or "",
|
||||
client_name=payload.client_name.strip(),
|
||||
name=payload.name.strip(),
|
||||
notes=payload.notes,
|
||||
)
|
||||
db.add(mix)
|
||||
db.commit()
|
||||
db.refresh(mix)
|
||||
# A brand-new mix has no products yet, so it reads as Inactive (no visible products).
|
||||
return _serialize_mix_row(mix, visible_count=0, product_count=0)
|
||||
|
||||
|
||||
@router.patch("/mixes/{mix_id}", response_model=EditorMixRow)
|
||||
def update_editor_mix(
|
||||
mix_id: int,
|
||||
@@ -377,6 +400,94 @@ def delete_editor_mix_ingredient(
|
||||
return _serialize_mix_formula(mix)
|
||||
|
||||
|
||||
@router.get("/mixes/{mix_id}/formula", response_model=EditorResolvedMixFormula)
|
||||
def get_editor_mix_resolved_formula(
|
||||
mix_id: int,
|
||||
session: AuthSession = Depends(_require_editor_session),
|
||||
db: Session = Depends(get_db),
|
||||
):
|
||||
"""The mix formula as the Mix Calculator reads it (product-first resolution).
|
||||
|
||||
This is what the Mix Editor displays, so the two surfaces show identical
|
||||
ingredients and quantities. See `resolve_editor_mix_formula`.
|
||||
"""
|
||||
tenant_id = session.tenant_id or ""
|
||||
mix = _load_editor_mix_formula(db, mix_id=mix_id, tenant_id=tenant_id)
|
||||
if mix is None:
|
||||
raise HTTPException(status_code=404, detail="Mix not found")
|
||||
return resolve_editor_mix_formula(db, tenant_id=tenant_id, mix=mix)
|
||||
|
||||
|
||||
@router.put("/mixes/{mix_id}/formula", response_model=EditorResolvedMixFormula)
|
||||
def replace_editor_mix_formula(
|
||||
mix_id: int,
|
||||
payload: EditorMixFormulaReplace,
|
||||
session: AuthSession = Depends(_require_editor_session),
|
||||
db: Session = Depends(get_db),
|
||||
):
|
||||
"""Replace a mix's whole formula in one save.
|
||||
|
||||
Writes back to the *same source* the Mix Calculator reads: the representative
|
||||
product's own formula (`ProductIngredient`) when it has one, otherwise the
|
||||
shared mix master (`MixIngredient`). Either way the calculator immediately
|
||||
reflects the edit.
|
||||
"""
|
||||
tenant_id = session.tenant_id or ""
|
||||
mix = _load_editor_mix_formula(db, mix_id=mix_id, tenant_id=tenant_id)
|
||||
if mix is None:
|
||||
raise HTTPException(status_code=404, detail="Mix not found")
|
||||
|
||||
raw_ids = [row.raw_material_id for row in payload.rows]
|
||||
if len(set(raw_ids)) != len(raw_ids):
|
||||
raise HTTPException(status_code=400, detail="Each raw material can only appear once in a mix")
|
||||
existing_ids = set(
|
||||
db.scalars(
|
||||
select(RawMaterial.id).where(RawMaterial.tenant_id == tenant_id, RawMaterial.id.in_(raw_ids))
|
||||
).all()
|
||||
)
|
||||
missing = [raw_id for raw_id in raw_ids if raw_id not in existing_ids]
|
||||
if missing:
|
||||
raise HTTPException(status_code=404, detail="Raw material not found")
|
||||
|
||||
product = resolve_representative_product(db, tenant_id=tenant_id, mix_id=mix_id)
|
||||
if product is not None and product.ingredients:
|
||||
# Replace the representative product's own formula.
|
||||
for ingredient in list(product.ingredients):
|
||||
db.delete(ingredient)
|
||||
db.flush()
|
||||
for sort_order, row in enumerate(payload.rows, start=1):
|
||||
db.add(
|
||||
ProductIngredient(
|
||||
tenant_id=tenant_id,
|
||||
product_id=product.id,
|
||||
raw_material_id=row.raw_material_id,
|
||||
quantity_kg=row.quantity_kg,
|
||||
sort_order=sort_order,
|
||||
notes=row.notes,
|
||||
)
|
||||
)
|
||||
else:
|
||||
# No product-specific formula in play: edit the shared mix master, which
|
||||
# is what the calculator falls back to for this mix.
|
||||
for ingredient in list(mix.ingredients):
|
||||
db.delete(ingredient)
|
||||
db.flush()
|
||||
for row in payload.rows:
|
||||
db.add(
|
||||
MixIngredient(
|
||||
tenant_id=tenant_id,
|
||||
mix_id=mix.id,
|
||||
raw_material_id=row.raw_material_id,
|
||||
quantity_kg=row.quantity_kg,
|
||||
notes=row.notes,
|
||||
)
|
||||
)
|
||||
|
||||
db.commit()
|
||||
mix = _load_editor_mix_formula(db, mix_id=mix_id, tenant_id=tenant_id)
|
||||
return resolve_editor_mix_formula(db, tenant_id=tenant_id, mix=mix)
|
||||
|
||||
|
||||
@router.get("/products/{product_id}/ingredients", response_model=EditorProductFormulaRead)
|
||||
def get_editor_product_ingredients(
|
||||
product_id: int,
|
||||
|
||||
@@ -0,0 +1,78 @@
|
||||
"""Read-only external data API (`/api/v1`).
|
||||
|
||||
A deliberately simple, API-key authenticated surface for Power BI (and any other
|
||||
external reporting tool). It is intentionally separate from the cookie/JWT
|
||||
session model used by the operator frontend: external tools cannot hold a
|
||||
browser session, so they present a single static key instead.
|
||||
|
||||
Authentication: send the key either as an ``X-API-Key`` request header or an
|
||||
``api_key`` query-string parameter (Power BI's Web connector supports both).
|
||||
The key is configured via the ``POWERBI_API_KEY`` environment variable; when it
|
||||
is blank the whole API is disabled and every request returns 503.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import secrets
|
||||
from datetime import date
|
||||
|
||||
from fastapi import APIRouter, Depends, HTTPException, Query, Request, status
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from app.core.config import settings
|
||||
from app.core.security_logging import log_security_event
|
||||
from app.db.session import get_db
|
||||
from app.models.throughput import ProductionThroughput
|
||||
from app.services.throughput_service import serialize_entry
|
||||
|
||||
router = APIRouter(prefix="/api/v1", tags=["public-v1"])
|
||||
|
||||
_API_KEY_HEADER = "X-API-Key"
|
||||
|
||||
|
||||
def require_powerbi_api_key(request: Request) -> str:
|
||||
"""Authorize an external request via the static Power BI API key.
|
||||
|
||||
Returns the tenant the caller may read. Raises 503 when the API is not
|
||||
configured, or 401 when the key is missing/incorrect.
|
||||
"""
|
||||
configured = settings.powerbi_api_key
|
||||
if not configured:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
|
||||
detail="The data API is not configured.",
|
||||
)
|
||||
|
||||
presented = request.headers.get(_API_KEY_HEADER) or request.query_params.get("api_key") or ""
|
||||
# Constant-time comparison so the endpoint does not leak key length/contents
|
||||
# through response timing.
|
||||
if not presented or not secrets.compare_digest(presented, configured):
|
||||
log_security_event("authz.denied", role="powerbi", reason="invalid_api_key")
|
||||
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail="Invalid or missing API key")
|
||||
|
||||
return settings.powerbi_tenant_id
|
||||
|
||||
|
||||
@router.get("/throughput")
|
||||
def list_throughput(
|
||||
date_from: date | None = Query(default=None, description="Only entries on/after this production date (YYYY-MM-DD)."),
|
||||
date_to: date | None = Query(default=None, description="Only entries on/before this production date (YYYY-MM-DD)."),
|
||||
limit: int = Query(default=5000, ge=1, le=50000),
|
||||
tenant_id: str = Depends(require_powerbi_api_key),
|
||||
db: Session = Depends(get_db),
|
||||
):
|
||||
"""Flat list of production throughput entries for Power BI.
|
||||
|
||||
One row per packing run, oldest first so incremental refreshes append
|
||||
naturally. Each row carries the same fields the operator UI shows
|
||||
(date, product, bag size, quantity, calculated kg, QA flags, staff, notes).
|
||||
"""
|
||||
stmt = select(ProductionThroughput).where(ProductionThroughput.tenant_id == tenant_id)
|
||||
if date_from is not None:
|
||||
stmt = stmt.where(ProductionThroughput.production_date >= date_from)
|
||||
if date_to is not None:
|
||||
stmt = stmt.where(ProductionThroughput.production_date <= date_to)
|
||||
stmt = stmt.order_by(ProductionThroughput.production_date.asc(), ProductionThroughput.id.asc()).limit(limit)
|
||||
|
||||
return [serialize_entry(entry) for entry in db.scalars(stmt).all()]
|
||||
Reference in New Issue
Block a user