Inlocuieste crearea conturilor prin INSERT SQL manual cu un tool admin dedicat, simetric cu tools/apikey.py. Fundatia Etapei 3 (3.2/3.3). - app/accounts.py: create_account/set_active/list_accounts (helper pur, partajat CLI + viitor flux web 3.3). Normalizeaza CUI (trim+upper), prinde IntegrityError -> ValueError cu cauza+fix. - accounts.active (lifecycle cont) + index unic partial ux_accounts_cui (unicitate la nivel de index, fara fereastra de coliziune). Migrare idempotenta in _migrate. - tools/account.py: create (--name/--cui/--inactive/--with-key atomic), list [--pending], activate/deactivate --account N. Erori -> exit 2. - 20 teste noi (12 helper + 8 CLI); suita 299 passed. active e inert pana la gate-ul worker din 3.3 (documentat). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
143 lines
7.1 KiB
SQL
143 lines
7.1 KiB
SQL
-- Schema SQLite (WAL) pentru gateway RAR AUTOPASS.
|
|
-- Vezi plan.md sect. 5 + plan-treapta2.md sect. 4.
|
|
-- Treapta 2: adauga conturi cu creds RAR durabile, tabele import, atestari.
|
|
|
|
PRAGMA journal_mode = WAL;
|
|
PRAGMA foreign_keys = ON;
|
|
|
|
-- Conturi ROAAUTO (clientii care folosesc gateway-ul).
|
|
CREATE TABLE IF NOT EXISTS accounts (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
name TEXT NOT NULL,
|
|
cui TEXT,
|
|
active INTEGER NOT NULL DEFAULT 1, -- lifecycle cont (3.1); gate „in asteptare" consumat de 3.3
|
|
rar_creds_enc TEXT, -- creds RAR criptate (Fernet) durabile per-cont (D4/Eng#1)
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
|
);
|
|
-- Un CUI = un cont (cand e prezent). NULL ramane distinct nativ in SQLite -> conturi
|
|
-- fara CUI (ex. default) se pot crea multiplu. Unicitate la nivel de index (nu check
|
|
-- in helper) ca sa nu existe fereastra de coliziune intre doi create_account concurenti.
|
|
CREATE UNIQUE INDEX IF NOT EXISTS ux_accounts_cui ON accounts(cui) WHERE cui IS NOT NULL;
|
|
-- Cont implicit (id=1): auth API-key (CORE) inca neimplementat, deci ingestiile vin
|
|
-- cu account_id NULL. Le atribuim contului default ca FK + UNIQUE(account_id,...) din
|
|
-- operations_mapping sa fie valide; cand auth livreaza, account_id real va curge natural.
|
|
INSERT OR IGNORE INTO accounts (id, name) VALUES (1, 'default');
|
|
|
|
-- Chei API per cont (separate de creds RAR). Stocam doar hash-ul.
|
|
CREATE TABLE IF NOT EXISTS api_keys (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
account_id INTEGER NOT NULL REFERENCES accounts(id) ON DELETE CASCADE,
|
|
key_hash TEXT NOT NULL UNIQUE,
|
|
active INTEGER NOT NULL DEFAULT 1,
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
|
revoked_at TEXT
|
|
);
|
|
|
|
-- Mapare operatie service -> codPrestatie RAR (← mapare_prestatii.DBF, T5).
|
|
CREATE TABLE IF NOT EXISTS operations_mapping (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
account_id INTEGER NOT NULL REFERENCES accounts(id) ON DELETE CASCADE,
|
|
cod_op_service TEXT NOT NULL,
|
|
cod_prestatie TEXT NOT NULL,
|
|
auto_send INTEGER NOT NULL DEFAULT 1,
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
|
UNIQUE (account_id, cod_op_service)
|
|
);
|
|
|
|
-- Cache nomenclator RAR {codPrestatie, numePrestatie} (← prestatii_rar.DBF / live).
|
|
CREATE TABLE IF NOT EXISTS nomenclator_rar (
|
|
cod_prestatie TEXT PRIMARY KEY,
|
|
nume_prestatie TEXT NOT NULL,
|
|
updated_at TEXT NOT NULL DEFAULT (datetime('now'))
|
|
);
|
|
|
|
-- Coada de prezentari catre RAR. Masina de stari: plan.md sect. 3.
|
|
CREATE TABLE IF NOT EXISTS submissions (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
idempotency_key TEXT NOT NULL UNIQUE,
|
|
account_id INTEGER REFERENCES accounts(id) ON DELETE SET NULL,
|
|
status TEXT NOT NULL DEFAULT 'queued'
|
|
CHECK (status IN ('queued','sending','sent','needs_mapping','needs_data','error')),
|
|
payload_json TEXT NOT NULL,
|
|
rar_creds_enc TEXT, -- creds RAR criptate (Fernet), sterse dupa primul login reusit
|
|
rar_status_code INTEGER,
|
|
rar_error TEXT,
|
|
id_prezentare INTEGER, -- data.id intors de RAR la succes
|
|
retry_count INTEGER NOT NULL DEFAULT 0,
|
|
next_attempt_at TEXT, -- backoff: randul nu se ia inainte de acest moment (T2)
|
|
sending_since TEXT, -- pentru lease/timeout pe randuri 'sending' orfane (T2)
|
|
purge_after TEXT, -- sent + 90z (T16)
|
|
batch_id INTEGER, -- import batch (T7; NULL = canal API)
|
|
row_index INTEGER, -- rand in batch (T7; NULL = canal API)
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
|
updated_at TEXT NOT NULL DEFAULT (datetime('now'))
|
|
);
|
|
|
|
CREATE INDEX IF NOT EXISTS idx_submissions_status ON submissions(status);
|
|
-- Nota: idx_submissions_batch se creeaza in _migrate (dupa ALTER care adauga batch_id pe DB veche).
|
|
|
|
-- Mapare coloane fisier -> campuri canonice (retinuta per cont, semnatura coloane).
|
|
CREATE TABLE IF NOT EXISTS column_mappings (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
account_id INTEGER NOT NULL REFERENCES accounts(id) ON DELETE CASCADE,
|
|
signature_coloane TEXT NOT NULL, -- hash/lista sortata a coloanelor fisierului
|
|
json_mapare TEXT NOT NULL, -- {col_fisier: camp_canonic, ...} JSON
|
|
format_data TEXT, -- ex. "DD.MM.YYYY"
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
|
UNIQUE (account_id, signature_coloane)
|
|
);
|
|
|
|
-- Loturi de import (fisiere incarcate).
|
|
CREATE TABLE IF NOT EXISTS import_batches (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
account_id INTEGER NOT NULL REFERENCES accounts(id) ON DELETE CASCADE,
|
|
filename TEXT NOT NULL,
|
|
status TEXT NOT NULL DEFAULT 'staging'
|
|
CHECK (status IN ('staging','committed','error')),
|
|
total INTEGER NOT NULL DEFAULT 0,
|
|
ok INTEGER NOT NULL DEFAULT 0,
|
|
needs_mapping INTEGER NOT NULL DEFAULT 0,
|
|
needs_data INTEGER NOT NULL DEFAULT 0,
|
|
needs_review INTEGER NOT NULL DEFAULT 0,
|
|
already_sent INTEGER NOT NULL DEFAULT 0,
|
|
duplicate_in_file INTEGER NOT NULL DEFAULT 0,
|
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
|
purge_after TEXT -- created_at + 90z (T16)
|
|
);
|
|
|
|
-- Randuri din lot de import (PII criptat cu Fernet).
|
|
CREATE TABLE IF NOT EXISTS import_rows (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
batch_id INTEGER NOT NULL REFERENCES import_batches(id) ON DELETE CASCADE,
|
|
row_index INTEGER NOT NULL,
|
|
raw_json TEXT NOT NULL, -- PII criptat (Fernet, ca submissions)
|
|
resolved_status TEXT NOT NULL DEFAULT 'pending'
|
|
CHECK (resolved_status IN (
|
|
'pending','ok','needs_mapping','needs_data',
|
|
'needs_review','already_sent','duplicate_in_file'
|
|
)),
|
|
error TEXT
|
|
);
|
|
|
|
CREATE INDEX IF NOT EXISTS idx_import_rows_batch ON import_rows(batch_id);
|
|
|
|
-- Log atestare legala (confirmare import batch, L.142/2023).
|
|
CREATE TABLE IF NOT EXISTS import_attestations (
|
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
|
batch_id INTEGER NOT NULL REFERENCES import_batches(id) ON DELETE CASCADE,
|
|
account_id INTEGER NOT NULL,
|
|
confirmed_by TEXT, -- email/identifier utilizator
|
|
ts TEXT NOT NULL DEFAULT (datetime('now')),
|
|
rows_hash TEXT NOT NULL, -- sha256 peste valorile rezolvate confirmate
|
|
n_confirmed INTEGER NOT NULL
|
|
);
|
|
|
|
-- Heartbeat worker (un singur rand, id=1). /healthz citeste de aici.
|
|
CREATE TABLE IF NOT EXISTS worker_heartbeat (
|
|
id INTEGER PRIMARY KEY CHECK (id = 1),
|
|
last_beat TEXT,
|
|
last_rar_login_ok TEXT,
|
|
detail TEXT
|
|
);
|
|
INSERT OR IGNORE INTO worker_heartbeat (id, last_beat, detail) VALUES (1, NULL, 'never started');
|