feat(P01): SLICE-06 P1 integration — wire lifespan + auth + verification swap

- TASK-06-01 __main__.py: SessionMiddleware (signed cookies, D-056) added
  AFTER CORS so it is outermost. slowapi limiter state + 429 exception
  handler registered. The lifespan (TASK-01-03) now also runs the VC key
  migration on first boot.
- TASK-06-02 __main__.py: auth_router mounted (POST /api/operator/login,
  POST /api/operator/logout, GET /api/operator/me) BEFORE the StaticFiles
  mount (routes-before-static constraint). Auth routes use app.state.pg_store
  (503 if no Postgres).
- TASK-06-03 __main__.py: /vc/verify swapped to the two-store path (G-011):
  pg_store for key lookup (active + superseded), SQLite fallback for v0.3
  credentials, SQLite-only if no Postgres. _maybe_migrate_issuer_keys()
  runs once in the lifespan (idempotent, G-027 first-boot, non-fatal on
  failure — v0.3 path intact).
- TASK-06-04 tests/test_p1_auth_integration.py: 4 e2e tests (skip if no
  Postgres) — full auth flow, /me without cookie 401, wrong password 401,
  learner voice loop unaffected (REQ-NFR-MT-01).
- TASK-06-05 tests/test_p1_vc_migration_e2e.py: 5 e2e tests (skip if no
  Postgres) — R-VC-MIG-01 critical (v0.3 VC verifies against archived
  superseded key in Postgres), idempotent migration, G-027 first-boot,
  v0.04 VC verifies, tamper detection.

Graceful degradation verified: server starts without Postgres (pg_pool/
pg_store are None; voice loop works; auth routes return 503).

---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: backend-engineer
task: 06-01,06-02,06-03,06-04,06-05
requirements:
  covered: [REQ-MT-01, REQ-AUTH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01]
  grill:
    - G-011 (two-store fallback wired in /vc/verify)
  risks:
    - R-VC-MIG-01 (e2e test: v0.3 VC verifies against archived superseded key in Postgres)
---/ci---
This commit is contained in:
Praxis CI
2026-08-04 01:00:11 +00:00
parent e8a05adcd1
commit 46b46479ca
3 changed files with 390 additions and 7 deletions
+66 -7
View File
@@ -28,16 +28,25 @@ try:
except ImportError: # pragma: no cover
pass
from fastapi import FastAPI, HTTPException
from fastapi import FastAPI, HTTPException, Request
from fastapi.middleware.cors import CORSMiddleware
from fastapi.responses import JSONResponse
from fastapi.staticfiles import StaticFiles
from pipecat.transports.smallwebrtc.connection import SmallWebRTCConnection
from slowapi.errors import RateLimitExceeded
from slowapi import _rate_limit_exceeded_handler
from db.pg_migrate import apply_pg_migrations
from db.pg_store import PgStore
from db.store import PraxisStore
from server.auth.cookies import get_session_middleware_kwargs
from server.auth.rate_limit import limiter
from server.auth.routes import router as auth_router
from server.pipeline import build_pipeline
from server.vc.issuer_keys import _load_root_key
from server.vc.migrate_keys import migrate_issuer_keys
from server.vc.verification import verify_credential
from starlette.middleware.sessions import SessionMiddleware
_store = PraxisStore()
@@ -89,6 +98,10 @@ async def lifespan(app: FastAPI):
logger.info(f"Postgres migrations applied: {applied}")
else:
logger.info("Postgres migrations up to date")
# VC key migration (TASK-06-03, R-VC-MIG-01, G-027) — runs once on
# first boot, idempotent. Non-fatal on failure (v0.3 SQLite path
# remains intact for verification).
await _maybe_migrate_issuer_keys()
try:
yield
finally:
@@ -106,12 +119,18 @@ class WebRTCOffer(BaseModel):
app = FastAPI(title="Praxis v0.1 voice server", version="0.1.0", lifespan=lifespan)
# slowapi rate-limit state + 429 handler (D-041, TASK-03-03).
app.state.limiter = limiter
app.add_exception_handler(RateLimitExceeded, _rate_limit_exceeded_handler)
app.add_middleware(
CORSMiddleware,
allow_origins=["*"], # dev — the client is a separate Vite origin
allow_methods=["*"],
allow_headers=["*"],
)
# SessionMiddleware (signed cookies, D-056) — added AFTER CORS so it is
# the outermost middleware (signs cookies before CORS headers are added).
app.add_middleware(SessionMiddleware, **get_session_middleware_kwargs())
@app.get("/health")
@@ -174,20 +193,60 @@ async def webrtc_offer(offer: WebRTCOffer) -> dict[str, str]:
@app.get("/vc/verify/{credential_id}")
async def vc_verify(credential_id: str) -> dict[str, Any]:
"""Public, unauthenticated VC verification endpoint (D-043).
"""Public, unauthenticated VC verification endpoint (D-043, G-011).
Returns {valid, status, issuer, credential, mastery, credentialTier,
verifiedAt}. 404 if the credential id is not found. No PII beyond what
the credential asserts.
Two-store fallback (G-011, binding contract):
(a) If Postgres is available (app.state.pg_store), use it for issuer
key lookup (active + superseded keys).
(b) If the credential is not in Postgres issued_credentials, fall back
to SQLite (v0.3 credentials remain in SQLite — D-051).
(c) If Postgres is NOT available, use the v0.3 SQLite path for both.
The VC key migration (TASK-04-03) runs once on first boot (idempotent)
inside the lifespan — see _maybe_migrate_issuer_keys.
"""
await _store.init()
result = await verify_credential(_store, credential_id)
pg_store = getattr(app.state, "pg_store", None)
result = await verify_credential(
_store, credential_id,
pg_store=pg_store, sqlite_store=_store,
)
if result is None:
raise HTTPException(status_code=404, detail="credential not found")
return result
# ── Static client serving (D-023, REQ-DEPLOY-13) ────────────────────
async def _maybe_migrate_issuer_keys() -> None:
"""Run the VC key migration on first boot (TASK-06-03, R-VC-MIG-01).
Idempotent — no-op if Postgres already has an active issuer key. G-027:
if SQLite has no v0.3 active key (fresh deploy), skips archive and only
generates a fresh v0.4 keypair.
"""
pg_store = getattr(app.state, "pg_store", None)
if pg_store is None:
return
try:
await _store.init()
root_key = _load_root_key()
result = await migrate_issuer_keys(_store, pg_store, root_key)
if result["new_key_id"] is not None:
logger.info(
f"VC key migration: archived v0.3 key={result['archived_key_id']}, "
f"generated fresh v0.4 key={result['new_key_id']}"
)
else:
logger.info("VC key migration: active key already present (no-op)")
except Exception as exc:
logger.error(f"VC key migration failed (non-fatal — v0.3 path intact): {exc}")
# ── Operator auth routes (TASK-06-02, D-057) ───────────────────────────
# Mounted BEFORE the StaticFiles mount so /api/operator/* is matched by
# the router (routes-before-static-mount constraint, carry-forward v0.2).
app.include_router(auth_router)
# ── Static client serving (D-023, REQ-DEPLOY-13) ──────────────────────
# Mount client/dist as StaticFiles at "/" AFTER all API routes so they
# take precedence. html=True serves index.html for "/" (SPA root).
# The client has no React Router (single-view state machine: start→live