mirror of
https://github.com/fastapi/full-stack-fastapi-template.git
synced 2026-09-21 13:28:57 +00:00
Compare commits
404
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8fa1a5100c | ||
|
|
cb740b656d | ||
|
|
041807b946 | ||
|
|
3000041090 | ||
|
|
ea37d2f5fb | ||
|
|
bf63770a9b | ||
|
|
3be4719849 | ||
|
|
2132b209eb | ||
|
|
bb92a02ca2 | ||
|
|
9d4ecbfc85 | ||
|
|
10dd26c613 | ||
|
|
5b632d4f88 | ||
|
|
bbe269d382 | ||
|
|
486f054cc8 | ||
|
|
f8dd304eeb | ||
|
|
2ccfa25845 | ||
|
|
f8ba0b81cd | ||
|
|
8063fe54f1 | ||
|
|
4d1a75de20 | ||
|
|
68adb40d37 | ||
|
|
7c11b644a3 | ||
|
|
6b5b886760 | ||
|
|
9a5c827ba6 | ||
|
|
b9cdd92dcc | ||
|
|
00a6aa978e | ||
|
|
2734dfd002 | ||
|
|
f369a27746 | ||
|
|
162344da11 | ||
|
|
981ae061b4 | ||
|
|
75b4026443 | ||
|
|
d95518294e | ||
|
|
c350936d28 | ||
|
|
42b4ca0586 | ||
|
|
84c5a9e11a | ||
|
|
98fb606b57 | ||
|
|
de2ed05b10 | ||
|
|
ec86250a21 | ||
|
|
7f11815e43 | ||
|
|
a2d2d18108 | ||
|
|
2d8fb3e4de | ||
|
|
ddb3c34f19 | ||
|
|
eae2d6701d | ||
|
|
6b9fa4113c | ||
|
|
b55b3122ab | ||
|
|
6dbb2e8256 | ||
|
|
6d75b2d132 | ||
|
|
32ab6dd022 | ||
|
|
cf1548a983 | ||
|
|
c8f9069168 | ||
|
|
512e496e1f | ||
|
|
fd0ca44d77 | ||
|
|
af791805ac | ||
|
|
9a218cd74a | ||
|
|
d85803bf64 | ||
|
|
781b283849 | ||
|
|
c291285975 | ||
|
|
b1abd91ba7 | ||
|
|
e95e501951 | ||
|
|
111c5fad66 | ||
|
|
9d541082a3 | ||
|
|
8893c6807a | ||
|
|
1c5dd70308 | ||
|
|
b5a664d510 | ||
|
|
23b0ba9bad | ||
|
|
74cf9ed832 | ||
|
|
4256e83fec | ||
|
|
85cd14d474 | ||
|
|
5069df32ea | ||
|
|
f2035ef732 | ||
|
|
b0ccf1e80e | ||
|
|
de53c8fd35 | ||
|
|
375af70ee2 | ||
|
|
6c2122e37d | ||
|
|
2c28c6f7dc | ||
|
|
a5aff58850 | ||
|
|
060795204b | ||
|
|
1a30f30e51 | ||
|
|
dd15054da0 | ||
|
|
bda0325818 | ||
|
|
2c7e51505e | ||
|
|
0625bcc8b0 | ||
|
|
4632845a39 | ||
|
|
029e929253 | ||
|
|
8a213ddae7 | ||
|
|
66f444a63a | ||
|
|
9c8983e2a5 | ||
|
|
2d04828d6a | ||
|
|
0137c3f2c3 | ||
|
|
75c388ba1c | ||
|
|
d5b20172e4 | ||
|
|
9097b329d6 | ||
|
|
6a1c084f6e | ||
|
|
220bcb74aa | ||
|
|
34378100a8 | ||
|
|
e5cdc73405 | ||
|
|
96c1147ee7 | ||
|
|
d506ea4883 | ||
|
|
a8f1ba0e70 | ||
|
|
f8b7926d1c | ||
|
|
de92a0d9fa | ||
|
|
750d3d0bc6 | ||
|
|
1b4d46c0b3 | ||
|
|
97f28a5905 | ||
|
|
752fc77bed | ||
|
|
24ff71fdac | ||
|
|
af27db9a1f | ||
|
|
24db0e9e18 | ||
|
|
84908a6fdd | ||
|
|
546f18469c | ||
|
|
daae6e1434 | ||
|
|
78c699079e | ||
|
|
e80d92452e | ||
|
|
588dfd46e5 | ||
|
|
eb9275a2f8 | ||
|
|
c9e70d65c7 | ||
|
|
7d0d2a890e | ||
|
|
5b358ea6f4 | ||
|
|
1c82b25096 | ||
|
|
4d3d5e92c1 | ||
|
|
402ca985bc | ||
|
|
7d80b8534e | ||
|
|
183bcf5189 | ||
|
|
4e5284b884 | ||
|
|
7feaeb309e | ||
|
|
95580c0191 | ||
|
|
886d05d597 | ||
|
|
536b73011f | ||
|
|
349a7537dc | ||
|
|
4cd0d9e51a | ||
|
|
0def368739 | ||
|
|
d85ceb5025 | ||
|
|
f900e07cc3 | ||
|
|
9e9b3a786b | ||
|
|
b5a2b458cc | ||
|
|
abecc7782e | ||
|
|
9eaf8185f3 | ||
|
|
34d14a4e76 | ||
|
|
95e83b1352 | ||
|
|
a75858514a | ||
|
|
4214d8b1a8 | ||
|
|
dbfd760dcc | ||
|
|
9a807a12c5 | ||
|
|
0bc5df81a9 | ||
|
|
7aecfb098b | ||
|
|
e4153f7cbf | ||
|
|
18a28cdb1e | ||
|
|
779323df09 | ||
|
|
7cfe46bfdf | ||
|
|
3685fb6625 | ||
|
|
119e31fba2 | ||
|
|
6bc7fa47e3 | ||
|
|
33c75e4cab | ||
|
|
6d63f81979 | ||
|
|
77be72439c | ||
|
|
a586c1c05c | ||
|
|
8c6e31a8f7 | ||
|
|
8e4fd7c722 | ||
|
|
54de75638b | ||
|
|
49a94eaab4 | ||
|
|
14728b636c | ||
|
|
a727535488 | ||
|
|
95a7a61c8b | ||
|
|
70461bb937 | ||
|
|
4179f15185 | ||
|
|
787e79a463 | ||
|
|
67250999a5 | ||
|
|
2a6eeda629 | ||
|
|
6bb47f9c9c | ||
|
|
248d7d11e7 | ||
|
|
98d93cfee8 | ||
|
|
2a56db28b2 | ||
|
|
13c4678515 | ||
|
|
cd83fc10ca | ||
|
|
3beccfe716 | ||
|
|
61da1d1f8d | ||
|
|
9ec63eae4a | ||
|
|
7975107f31 | ||
|
|
f459c20a17 | ||
|
|
ee684d67db | ||
|
|
53f0cf4488 | ||
|
|
a54720d4a1 | ||
|
|
20731272ca | ||
|
|
1c1175eb50 | ||
|
|
3814f249b2 | ||
|
|
31e9f272f4 | ||
|
|
e6d4aead1c | ||
|
|
9af21b878e | ||
|
|
49e9c5216f | ||
|
|
5027f2effb | ||
|
|
e39f0630e0 | ||
|
|
5ee2fe25b2 | ||
|
|
469273290f | ||
|
|
a6c8ec01e5 | ||
|
|
085686b31f | ||
|
|
2097350645 | ||
|
|
5fcaab8bab | ||
|
|
6a2b002a8e | ||
|
|
4f22958c3f | ||
|
|
800669075f | ||
|
|
495b8dbbd5 | ||
|
|
38302d7492 | ||
|
|
8fefa3f3f2 | ||
|
|
34c8f8b78e | ||
|
|
c1b7479e7a | ||
|
|
33fa827e7e | ||
|
|
b6b79b424d | ||
|
|
baa12f641c | ||
|
|
7776e56880 | ||
|
|
d92bb18923 | ||
|
|
c81925a009 | ||
|
|
a2de9241ed | ||
|
|
94597a5021 | ||
|
|
9b1819a478 | ||
|
|
69e384859e | ||
|
|
32ebacfb42 | ||
|
|
f8516cd73b | ||
|
|
a2d50e26dd | ||
|
|
41b6dcedae | ||
|
|
39ecf9a093 | ||
|
|
baa742be6b | ||
|
|
13652b51ea | ||
|
|
03e021f30a | ||
|
|
bba8d07c0c | ||
|
|
37287deafe | ||
|
|
041377eb6d | ||
|
|
2fdd62ce0c | ||
|
|
8bf0025039 | ||
|
|
d784c02d36 | ||
|
|
ae3f6e3038 | ||
|
|
15e055f471 | ||
|
|
b42b147e98 | ||
|
|
6335787dc8 | ||
|
|
b16f3b4156 | ||
|
|
2d7d4e7768 | ||
|
|
fbaf2dbe9d | ||
|
|
1b2d94a887 | ||
|
|
4c63a663ac | ||
|
|
7005892795 | ||
|
|
64455e5c7b | ||
|
|
2f5ceec867 | ||
|
|
16afa0d363 | ||
|
|
40384c9deb | ||
|
|
aafa8ebfc9 | ||
|
|
5e2e8a9e6a | ||
|
|
917c7c898c | ||
|
|
b9ee37b8b4 | ||
|
|
465a5672d3 | ||
|
|
cf956e2b0b | ||
|
|
706bd53aa3 | ||
|
|
960beee281 | ||
|
|
9059faa6b0 | ||
|
|
aec52069da | ||
|
|
4a14d47647 | ||
|
|
56684e7714 | ||
|
|
3f6cda7bf4 | ||
|
|
97b8debf74 | ||
|
|
366eb587c1 | ||
|
|
a6c5dbe89d | ||
|
|
4628375e8c | ||
|
|
012a7d02b9 | ||
|
|
04e1a55f68 | ||
|
|
752c40cf5a | ||
|
|
f6c2e534c3 | ||
|
|
51295d09b7 | ||
|
|
db4532678c | ||
|
|
b5ac33fe0b | ||
|
|
083d3e5c3d | ||
|
|
f21b241e25 | ||
|
|
70bf8ba988 | ||
|
|
f3abf45ccd | ||
|
|
12788c2707 | ||
|
|
6f32450121 | ||
|
|
7003bf07c4 | ||
|
|
03dea29b79 | ||
|
|
42bf7e7cfe | ||
|
|
fa39625d80 | ||
|
|
0f289cf840 | ||
|
|
8b35efe999 | ||
|
|
7af1d80593 | ||
|
|
1b523bbc0d | ||
|
|
b40b0e0806 | ||
|
|
dcd8f1e641 | ||
|
|
13b2dac791 | ||
|
|
0d3bc003f1 | ||
|
|
1c6d656482 | ||
|
|
a252d2e678 | ||
|
|
fa8795141f | ||
|
|
2fd5ba65da | ||
|
|
5e1fa15e65 | ||
|
|
0162c1db74 | ||
|
|
3e6449ce0d | ||
|
|
dedaa07be0 | ||
|
|
a00382f3ca | ||
|
|
7fa809754c | ||
|
|
cd3d744186 | ||
|
|
72967929eb | ||
|
|
a5ad271f7c | ||
|
|
71d0e20af8 | ||
|
|
4e58251f76 | ||
|
|
e127163403 | ||
|
|
d40de23896 | ||
|
|
46e9e1926e | ||
|
|
43fac49a14 | ||
|
|
64eac127f0 | ||
|
|
3d2fffd138 | ||
|
|
a8fa3455ab | ||
|
|
3c1f7c4cdb | ||
|
|
2720308701 | ||
|
|
6c3323547b | ||
|
|
7a542cade6 | ||
|
|
e6c973060a | ||
|
|
4c65c018ac | ||
|
|
0d2a360857 | ||
|
|
12b2a95a58 | ||
|
|
de9661fc4f | ||
|
|
0564d65041 | ||
|
|
da603ebaac | ||
|
|
61e161bfb9 | ||
|
|
c3577c0526 | ||
|
|
ca37099b01 | ||
|
|
d74c794054 | ||
|
|
cdc5fba430 | ||
|
|
9ba793038e | ||
|
|
540766b961 | ||
|
|
1f332b89b4 | ||
|
|
6ab7a40cdd | ||
|
|
03bca13d17 | ||
|
|
e8418cb027 | ||
|
|
8ab41e3b24 | ||
|
|
6a49131003 | ||
|
|
97a4346c98 | ||
|
|
689d7105e1 | ||
|
|
7107f7e83a | ||
|
|
730c6e9ebb | ||
|
|
a0fe8a236f | ||
|
|
ca9cecf6c1 | ||
|
|
d0d06d18d7 | ||
|
|
458fddd772 | ||
|
|
608bb80106 | ||
|
|
9fe3a4d221 | ||
|
|
a45258f520 | ||
|
|
e3ead78f84 | ||
|
|
d5ee4a7276 | ||
|
|
352cded1cf | ||
|
|
f8c4e68472 | ||
|
|
4cab9e972f | ||
|
|
fe3bafc6f6 | ||
|
|
22b884a69e | ||
|
|
bbfa6ec46c | ||
|
|
9ceac2cfaf | ||
|
|
1690b598aa | ||
|
|
dd11319612 | ||
|
|
e75db847d8 | ||
|
|
23435b1053 | ||
|
|
c68ca3b989 | ||
|
|
54cd72e08d | ||
|
|
8574ea4397 | ||
|
|
fb2a02345b | ||
|
|
ab7c28c038 | ||
|
|
e0c80050f1 | ||
|
|
00e55ccabb | ||
|
|
565ddb61f7 | ||
|
|
a42f89b892 | ||
|
|
7201b88628 | ||
|
|
92460ee1fe | ||
|
|
3a5611aa7f | ||
|
|
fcad8f8270 | ||
|
|
87747c30cb | ||
|
|
e5236814e0 | ||
|
|
4fcaa97ac6 | ||
|
|
be7ff79aa7 | ||
|
|
88eade2231 | ||
|
|
63f167d462 | ||
|
|
11f2fc90d1 | ||
|
|
2e0db3f9b4 | ||
|
|
2059d2e271 | ||
|
|
ac9319d841 | ||
|
|
f21b70bd8c | ||
|
|
9f94fda46d | ||
|
|
7b0c7e8a1a | ||
|
|
eadcf5c9d5 | ||
|
|
e36bcf0e87 | ||
|
|
bdf5e26363 | ||
|
|
bd6f0d4edd | ||
|
|
650a33d98b | ||
|
|
44b2e67ced | ||
|
|
3826039f51 | ||
|
|
7d2307bb9a | ||
|
|
7f4befa0a9 | ||
|
|
d512a6a5f8 | ||
|
|
6a91475bf6 | ||
|
|
9db30ed04c | ||
|
|
c5b3d05aa3 | ||
|
|
31892f31d5 | ||
|
|
a5d93de972 | ||
|
|
c9a09fca7d | ||
|
|
9581560edb | ||
|
|
68726e4191 | ||
|
|
0f3423a818 | ||
|
|
b376e16adb | ||
|
|
7ce4aa0904 | ||
|
|
6250e97f4e | ||
|
|
ee316abde0 | ||
|
|
27a81ea023 |
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.venv/lib/python3.14/site-packages/fastapi/.agents/skills/fastapi
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"kind": "tool-skill",
|
||||
"version": "0.0.19"
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
name: library-skills
|
||||
description: Use Library Skills to discover, install, refresh, repair, check, and manage agent skills from installed packages.
|
||||
---
|
||||
|
||||
# Library Skills
|
||||
|
||||
Use this skill when a project might benefit from agent skills bundled by its installed packages, or when existing Library Skills-managed symlinks are stale, broken, orphaned, or need to be checked.
|
||||
|
||||
Run commands from the project root.
|
||||
|
||||
Agents bundle their own skills by including an `.agents/skills` directory. More details in [Library Skills](https://library-skills.io).
|
||||
|
||||
## First-Time Setup
|
||||
|
||||
- Make sure project dependencies are installed first, for example with `uv sync` for Python projects or `npm install` / `bun install` for Node.js projects.
|
||||
- Run `uvx library-skills` or `npx library-skills` to discover skills bundled by the installed packages and install selected skills interactively.
|
||||
- Use `uvx library-skills --all` or `npx library-skills --all` only when all newly discovered skills should be installed without selecting individual skills.
|
||||
- Use `uvx library-skills --tool-skill` or `npx library-skills --tool-skill` to copy this Library Skills tool skill into the project so future agents know how to discover, install, update, repair, and check skills.
|
||||
|
||||
## Commands
|
||||
|
||||
- Run `uvx library-skills` or `npx library-skills` to discover package-provided skills, install selected new skills, and reconcile existing managed symlinks.
|
||||
- Run `uvx library-skills list` or `npx library-skills list` to inspect discovered and installed skills.
|
||||
- Run `uvx library-skills list --json` or `npx library-skills list --json` for machine-readable installed status.
|
||||
- Run `uvx library-skills scan --json` or `npx library-skills scan --json` for discovery-only automation.
|
||||
- Run `uvx library-skills --check` or `npx library-skills --check` to validate managed skill symlink state without changing files.
|
||||
- Run `uvx library-skills --yes` or `npx library-skills --yes` to repair stale managed symlinks and remove orphaned managed symlinks non-interactively.
|
||||
- Add `--claude` when `.claude/skills` should also be managed.
|
||||
- Add `--skill NAME` to install a specific discovered skill by name.
|
||||
|
||||
## Safety
|
||||
|
||||
- Prefer rerunning `library-skills` over editing managed symlinks manually.
|
||||
- If installed skill symlinks are broken, dependencies may not be installed yet. Try the project's normal install command first, such as `uv sync`, `npm install`, or `bun install`, then rerun `library-skills`.
|
||||
- Do not delete or overwrite hand-authored skill directories.
|
||||
- Library Skills only removes managed symlinks. It should not remove copied or hand-authored skill directories.
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.venv/lib/python3.14/site-packages/sqlmodel/.agents/skills/sqlmodel
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.venv/lib/python3.14/site-packages/fastapi/.agents/skills/fastapi
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"kind": "tool-skill",
|
||||
"version": "0.0.19"
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
name: library-skills
|
||||
description: Use Library Skills to discover, install, refresh, repair, check, and manage agent skills from installed packages.
|
||||
---
|
||||
|
||||
# Library Skills
|
||||
|
||||
Use this skill when a project might benefit from agent skills bundled by its installed packages, or when existing Library Skills-managed symlinks are stale, broken, orphaned, or need to be checked.
|
||||
|
||||
Run commands from the project root.
|
||||
|
||||
Agents bundle their own skills by including an `.agents/skills` directory. More details in [Library Skills](https://library-skills.io).
|
||||
|
||||
## First-Time Setup
|
||||
|
||||
- Make sure project dependencies are installed first, for example with `uv sync` for Python projects or `npm install` / `bun install` for Node.js projects.
|
||||
- Run `uvx library-skills` or `npx library-skills` to discover skills bundled by the installed packages and install selected skills interactively.
|
||||
- Use `uvx library-skills --all` or `npx library-skills --all` only when all newly discovered skills should be installed without selecting individual skills.
|
||||
- Use `uvx library-skills --tool-skill` or `npx library-skills --tool-skill` to copy this Library Skills tool skill into the project so future agents know how to discover, install, update, repair, and check skills.
|
||||
|
||||
## Commands
|
||||
|
||||
- Run `uvx library-skills` or `npx library-skills` to discover package-provided skills, install selected new skills, and reconcile existing managed symlinks.
|
||||
- Run `uvx library-skills list` or `npx library-skills list` to inspect discovered and installed skills.
|
||||
- Run `uvx library-skills list --json` or `npx library-skills list --json` for machine-readable installed status.
|
||||
- Run `uvx library-skills scan --json` or `npx library-skills scan --json` for discovery-only automation.
|
||||
- Run `uvx library-skills --check` or `npx library-skills --check` to validate managed skill symlink state without changing files.
|
||||
- Run `uvx library-skills --yes` or `npx library-skills --yes` to repair stale managed symlinks and remove orphaned managed symlinks non-interactively.
|
||||
- Add `--claude` when `.claude/skills` should also be managed.
|
||||
- Add `--skill NAME` to install a specific discovered skill by name.
|
||||
|
||||
## Safety
|
||||
|
||||
- Prefer rerunning `library-skills` over editing managed symlinks manually.
|
||||
- If installed skill symlinks are broken, dependencies may not be installed yet. Try the project's normal install command first, such as `uv sync`, `npm install`, or `bun install`, then rerun `library-skills`.
|
||||
- Do not delete or overwrite hand-authored skill directories.
|
||||
- Library Skills only removes managed symlinks. It should not remove copied or hand-authored skill directories.
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../../.venv/lib/python3.14/site-packages/sqlmodel/.agents/skills/sqlmodel
|
||||
@@ -1 +0,0 @@
|
||||
{{ _copier_answers|to_json -}}
|
||||
@@ -1,26 +0,0 @@
|
||||
from pathlib import Path
|
||||
import json
|
||||
|
||||
# Update the .env file with the answers from the .copier-answers.yml file
|
||||
# without using Jinja2 templates in the .env file, this way the code works as is
|
||||
# without needing Copier, but if Copier is used, the .env file will be updated
|
||||
root_path = Path(__file__).parent.parent
|
||||
answers_path = Path(__file__).parent / ".copier-answers.yml"
|
||||
answers = json.loads(answers_path.read_text())
|
||||
env_path = root_path / ".env"
|
||||
env_content = env_path.read_text()
|
||||
lines = []
|
||||
for line in env_content.splitlines():
|
||||
for key, value in answers.items():
|
||||
upper_key = key.upper()
|
||||
if line.startswith(f"{upper_key}="):
|
||||
if " " in value:
|
||||
content = f"{upper_key}={value!r}"
|
||||
else:
|
||||
content = f"{upper_key}={value}"
|
||||
new_line = line.replace(line, content)
|
||||
lines.append(new_line)
|
||||
break
|
||||
else:
|
||||
lines.append(line)
|
||||
env_path.write_text("\n".join(lines))
|
||||
@@ -0,0 +1,10 @@
|
||||
.git
|
||||
**/__pycache__
|
||||
**/.venv
|
||||
backend/htmlcov
|
||||
frontend/blob-report
|
||||
frontend/dist
|
||||
frontend/node_modules
|
||||
frontend/playwright-report
|
||||
frontend/test-results
|
||||
node_modules
|
||||
@@ -1,45 +1,18 @@
|
||||
# Domain
|
||||
# This would be set to the production domain with an env var on deployment
|
||||
# used by Traefik to transmit traffic and aqcuire TLS certificates
|
||||
DOMAIN=localhost
|
||||
# To test the local Traefik config
|
||||
# DOMAIN=localhost.tiangolo.com
|
||||
|
||||
# Used by the backend to generate links in emails to the frontend
|
||||
FRONTEND_HOST=http://localhost:5173
|
||||
# In staging and production, set this env var to the frontend host, e.g.
|
||||
# FRONTEND_HOST=https://dashboard.example.com
|
||||
|
||||
# Environment: local, staging, production
|
||||
ENVIRONMENT=local
|
||||
# Enable development behavior for commands that import the app directly
|
||||
FASTAPI_ENV=development
|
||||
|
||||
PROJECT_NAME="Full Stack FastAPI Project"
|
||||
STACK_NAME=full-stack-fastapi-project
|
||||
|
||||
# Backend
|
||||
BACKEND_CORS_ORIGINS="http://localhost,http://localhost:5173,https://localhost,https://localhost:5173,http://localhost.tiangolo.com"
|
||||
SECRET_KEY=changethis
|
||||
FIRST_SUPERUSER=admin@example.com
|
||||
FIRST_SUPERUSER_PASSWORD=changethis
|
||||
|
||||
# Emails
|
||||
SMTP_HOST=
|
||||
SMTP_USER=
|
||||
SMTP_PASSWORD=
|
||||
SMTP_HOST=localhost
|
||||
EMAILS_FROM_EMAIL=info@example.com
|
||||
SMTP_TLS=True
|
||||
SMTP_SSL=False
|
||||
SMTP_PORT=587
|
||||
SMTP_TLS=False
|
||||
SMTP_PORT=1025
|
||||
|
||||
# Postgres
|
||||
POSTGRES_SERVER=localhost
|
||||
POSTGRES_PORT=5432
|
||||
POSTGRES_DB=app
|
||||
POSTGRES_USER=postgres
|
||||
POSTGRES_PASSWORD=changethis
|
||||
|
||||
SENTRY_DSN=
|
||||
|
||||
# Configure these with your own Docker registry images
|
||||
DOCKER_IMAGE_BACKEND=backend
|
||||
DOCKER_IMAGE_FRONTEND=frontend
|
||||
DATABASE_URL=postgresql://postgres:${POSTGRES_PASSWORD}@localhost:5432/app
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
.env
|
||||
!backend/app/frontend/
|
||||
@@ -1,118 +0,0 @@
|
||||
labels: [question]
|
||||
body:
|
||||
- type: markdown
|
||||
attributes:
|
||||
value: |
|
||||
Thanks for your interest in this project! 🚀
|
||||
|
||||
Please follow these instructions, fill every question, and do every step. 🙏
|
||||
|
||||
I'm asking this because answering questions and solving problems in GitHub is what consumes most of the time.
|
||||
|
||||
I end up not being able to add new features, fix bugs, review pull requests, etc. as fast as I wish because I have to spend too much time handling questions.
|
||||
|
||||
All that, on top of all the incredible help provided by a bunch of community members, that give a lot of their time to come here and help others.
|
||||
|
||||
That's a lot of work, but if more users came to help others like them just a little bit more, it would be much less effort for them (and you and me 😅).
|
||||
|
||||
By asking questions in a structured way (following this) it will be much easier to help you.
|
||||
|
||||
And there's a high chance that you will find the solution along the way and you won't even have to submit it and wait for an answer. 😎
|
||||
|
||||
As there are too many questions, I'll have to discard and close the incomplete ones. That will allow me (and others) to focus on helping people like you that follow the whole process and help us help you. 🤓
|
||||
- type: checkboxes
|
||||
id: checks
|
||||
attributes:
|
||||
label: First Check
|
||||
description: Please confirm and check all the following options.
|
||||
options:
|
||||
- label: I added a very descriptive title here.
|
||||
required: true
|
||||
- label: I used the GitHub search to find a similar question and didn't find it.
|
||||
required: true
|
||||
- label: I searched in the documentation/README.
|
||||
required: true
|
||||
- label: I already searched in Google "How to do X" and didn't find any information.
|
||||
required: true
|
||||
- label: I already read and followed all the tutorial in the docs/README and didn't find an answer.
|
||||
required: true
|
||||
- type: checkboxes
|
||||
id: help
|
||||
attributes:
|
||||
label: Commit to Help
|
||||
description: |
|
||||
After submitting this, I commit to one of:
|
||||
|
||||
* Read open questions until I find 2 where I can help someone and add a comment to help there.
|
||||
* I already hit the "watch" button in this repository to receive notifications and I commit to help at least 2 people that ask questions in the future.
|
||||
|
||||
options:
|
||||
- label: I commit to help with one of those options 👆
|
||||
required: true
|
||||
- type: textarea
|
||||
id: example
|
||||
attributes:
|
||||
label: Example Code
|
||||
description: |
|
||||
Please add a self-contained, [minimal, reproducible, example](https://stackoverflow.com/help/minimal-reproducible-example) with your use case.
|
||||
|
||||
If I (or someone) can copy it, run it, and see it right away, there's a much higher chance I (or someone) will be able to help you.
|
||||
|
||||
placeholder: |
|
||||
Write your example code here.
|
||||
render: Text
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
id: description
|
||||
attributes:
|
||||
label: Description
|
||||
description: |
|
||||
What is the problem, question, or error?
|
||||
|
||||
Write a short description telling me what you are doing, what you expect to happen, and what is currently happening.
|
||||
placeholder: |
|
||||
* Open the browser and call the endpoint `/`.
|
||||
* It returns a JSON with `{"message": "Hello World"}`.
|
||||
* But I expected it to return `{"message": "Hello Morty"}`.
|
||||
validations:
|
||||
required: true
|
||||
- type: dropdown
|
||||
id: os
|
||||
attributes:
|
||||
label: Operating System
|
||||
description: What operating system are you on?
|
||||
multiple: true
|
||||
options:
|
||||
- Linux
|
||||
- Windows
|
||||
- macOS
|
||||
- Other
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
id: os-details
|
||||
attributes:
|
||||
label: Operating System Details
|
||||
description: You can add more details about your operating system here, in particular if you chose "Other".
|
||||
validations:
|
||||
required: true
|
||||
- type: input
|
||||
id: python-version
|
||||
attributes:
|
||||
label: Python Version
|
||||
description: |
|
||||
What Python version are you using?
|
||||
|
||||
You can find the Python version with:
|
||||
|
||||
```bash
|
||||
python --version
|
||||
```
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
id: context
|
||||
attributes:
|
||||
label: Additional Context
|
||||
description: Add any additional context information or screenshots you think are useful.
|
||||
@@ -1 +0,0 @@
|
||||
github: [tiangolo]
|
||||
@@ -1,10 +0,0 @@
|
||||
blank_issues_enabled: false
|
||||
contact_links:
|
||||
- name: Security Contact
|
||||
about: Please report security vulnerabilities to security@tiangolo.com
|
||||
- name: Question or Problem
|
||||
about: Ask a question or ask about a problem in GitHub Discussions.
|
||||
url: https://github.com/fastapi/full-stack-fastapi-template/discussions/categories/questions
|
||||
- name: Feature Request
|
||||
about: To suggest an idea or ask about a feature, please start with a question saying what you would like to achieve. There might be a way to do it already.
|
||||
url: https://github.com/fastapi/full-stack-fastapi-template/discussions/categories/questions
|
||||
@@ -1,22 +0,0 @@
|
||||
name: Privileged
|
||||
description: You are @tiangolo or he asked you directly to create an issue here. If not, check the other options. 👇
|
||||
body:
|
||||
- type: markdown
|
||||
attributes:
|
||||
value: |
|
||||
Thanks for your interest in this project! 🚀
|
||||
|
||||
If you are not @tiangolo or he didn't ask you directly to create an issue here, please start the conversation in a [Question in GitHub Discussions](https://github.com/tiangolo/full-stack-fastapi-template/discussions/categories/questions) instead.
|
||||
- type: checkboxes
|
||||
id: privileged
|
||||
attributes:
|
||||
label: Privileged issue
|
||||
description: Confirm that you are allowed to create an issue here.
|
||||
options:
|
||||
- label: I'm @tiangolo or he asked me directly to create an issue here.
|
||||
required: true
|
||||
- type: textarea
|
||||
id: content
|
||||
attributes:
|
||||
label: Issue Content
|
||||
description: Add the content of the issue here.
|
||||
+43
-12
@@ -4,43 +4,74 @@ updates:
|
||||
- package-ecosystem: github-actions
|
||||
directory: /
|
||||
schedule:
|
||||
interval: daily
|
||||
interval: "monthly"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
commit-message:
|
||||
prefix: ⬆
|
||||
labels: [dependencies, internal]
|
||||
labels:
|
||||
- "internal"
|
||||
- "dependencies"
|
||||
- "github_actions"
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
# Python uv
|
||||
- package-ecosystem: uv
|
||||
directory: /backend
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: "monthly"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
commit-message:
|
||||
prefix: ⬆
|
||||
labels: [dependencies, internal]
|
||||
# npm
|
||||
- package-ecosystem: npm
|
||||
directory: /frontend
|
||||
groups:
|
||||
python-packages:
|
||||
patterns:
|
||||
- "*"
|
||||
# bun
|
||||
- package-ecosystem: bun
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: "monthly"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
commit-message:
|
||||
prefix: ⬆
|
||||
labels: [dependencies, internal]
|
||||
ignore:
|
||||
- dependency-name: "@hey-api/openapi-ts"
|
||||
groups:
|
||||
npm-packages:
|
||||
patterns:
|
||||
- "*"
|
||||
# Docker
|
||||
- package-ecosystem: docker
|
||||
directories:
|
||||
- /backend
|
||||
- /frontend
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: "monthly"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
commit-message:
|
||||
prefix: ⬆
|
||||
labels: [dependencies, internal]
|
||||
groups:
|
||||
docker:
|
||||
patterns:
|
||||
- "*"
|
||||
# Docker Compose
|
||||
- package-ecosystem: docker-compose
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: "monthly"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
commit-message:
|
||||
prefix: ⬆
|
||||
labels: [dependencies, internal]
|
||||
groups:
|
||||
docker-compose:
|
||||
patterns:
|
||||
- "*"
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
docs:
|
||||
- all:
|
||||
- changed-files:
|
||||
- any-glob-to-any-file:
|
||||
- '**/*.md'
|
||||
- all-globs-to-all-files:
|
||||
- '!frontend/**'
|
||||
- '!backend/**'
|
||||
- '!.github/**'
|
||||
- '!scripts/**'
|
||||
- '!.gitignore'
|
||||
- '!.pre-commit-config.yaml'
|
||||
|
||||
internal:
|
||||
- all:
|
||||
- changed-files:
|
||||
- any-glob-to-any-file:
|
||||
- .github/**
|
||||
- scripts/**
|
||||
- .gitignore
|
||||
- .pre-commit-config.yaml
|
||||
- all-globs-to-all-files:
|
||||
- '!./**/*.md'
|
||||
- '!frontend/**'
|
||||
- '!backend/**'
|
||||
@@ -0,0 +1,12 @@
|
||||
auto-labels:
|
||||
docs:
|
||||
- exclude: frontend/**
|
||||
- exclude: backend/**
|
||||
- exclude: .github/**
|
||||
- exclude: scripts/**
|
||||
- '**/*.md'
|
||||
internal:
|
||||
- .github/**
|
||||
- scripts/**
|
||||
- .gitignore
|
||||
- .pre-commit-config.yaml
|
||||
@@ -0,0 +1,2 @@
|
||||
workflows:
|
||||
- .github/workflows/pre-commit.yml
|
||||
@@ -0,0 +1,3 @@
|
||||
workflows:
|
||||
- .github/workflows/bump-pre-commit-hooks.yml
|
||||
- .github/workflows/prepare-release.yml
|
||||
@@ -1,18 +1,22 @@
|
||||
name: Add to Project
|
||||
|
||||
on:
|
||||
pull_request_target:
|
||||
pull_request_target: # zizmor: ignore[dangerous-triggers]
|
||||
issues:
|
||||
types:
|
||||
- opened
|
||||
- reopened
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
add-to-project:
|
||||
name: Add to project
|
||||
if: github.repository_owner == 'fastapi'
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- uses: actions/add-to-project@v1.0.2
|
||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
||||
with:
|
||||
project-url: https://github.com/orgs/fastapi/projects/2
|
||||
github-token: ${{ secrets.PROJECTS_TOKEN }}
|
||||
github-token: ${{ secrets.PROJECTS_TOKEN }} # zizmor: ignore[secrets-outside-env]
|
||||
|
||||
@@ -0,0 +1,71 @@
|
||||
name: Bump pre-commit hooks
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "0 12 1 * *"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
bump-pre-commit-hooks:
|
||||
if: github.repository_owner == 'fastapi'
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: ".python-version"
|
||||
- name: Setup uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
cache-dependency-glob: |
|
||||
pyproject.toml
|
||||
uv.lock
|
||||
- name: Bump pre-commit hooks
|
||||
run: uv run prek auto-update --freeze --cooldown-days 7
|
||||
- name: Get PR Submit token
|
||||
id: pr-submit
|
||||
uses: tiangolo/pr-submit@d802fdf59bde80bc3eb8bd3259f4cbeec63de4aa # 0.0.1
|
||||
- name: Create pull request
|
||||
env:
|
||||
GH_TOKEN: ${{ steps.pr-submit.outputs.token }}
|
||||
BASE_BRANCH: ${{ github.event.repository.default_branch }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
if git diff --quiet; then
|
||||
echo "No pre-commit hook updates available"
|
||||
exit 0
|
||||
fi
|
||||
git config user.name "pr-submit[bot]"
|
||||
git config user.email "pr-submit[bot]@users.noreply.github.com"
|
||||
branch="bump-pre-commit-hooks"
|
||||
git switch -C "$branch"
|
||||
git add .pre-commit-config.yaml
|
||||
git commit -m "⬆ Bump pre-commit hooks"
|
||||
gh auth setup-git
|
||||
git push --force origin "$branch"
|
||||
if [ -z "$(gh pr list --head "$branch" --state open --json number --jq '.[].number')" ]; then
|
||||
gh pr create \
|
||||
--base "$BASE_BRANCH" \
|
||||
--head "$branch" \
|
||||
--title "⬆ Bump pre-commit hooks" \
|
||||
--body "Bump pre-commit hook versions via \`prek auto-update --freeze --cooldown-days 7\`." \
|
||||
--label internal \
|
||||
--label dependencies \
|
||||
--label pre-commit
|
||||
else
|
||||
echo "PR for \"$branch\" already open; branch updated in place."
|
||||
fi
|
||||
@@ -0,0 +1,52 @@
|
||||
name: Create Draft Release
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types:
|
||||
- closed
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
create-draft-release:
|
||||
if: github.event.pull_request.merged == true && contains(github.event.pull_request.labels.*.name, 'release')
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: read
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
ref: ${{ github.event.repository.default_branch }}
|
||||
persist-credentials: false
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: ".python-version"
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
- name: Extract release details
|
||||
id: release-details
|
||||
run: |
|
||||
set -euo pipefail
|
||||
version="$(uv run python scripts/prepare_release.py current-version)"
|
||||
uv run python scripts/prepare_release.py release-notes > draft-release-notes.md
|
||||
echo "version=$version" >> "$GITHUB_OUTPUT"
|
||||
- name: Create draft release
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
VERSION: ${{ steps.release-details.outputs.version }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
gh release create "$VERSION" \
|
||||
--draft \
|
||||
--title "$VERSION" \
|
||||
--notes-file draft-release-notes.md \
|
||||
--target "$(git rev-parse HEAD)"
|
||||
@@ -0,0 +1,41 @@
|
||||
name: Deploy with Docker Compose
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: deploy-docker-compose
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
# Do not deploy the template repository, only projects created from it
|
||||
if: github.repository != 'fastapi/full-stack-fastapi-template'
|
||||
runs-on: self-hosted
|
||||
timeout-minutes: 30
|
||||
env:
|
||||
DOMAIN: ${{ vars.DOMAIN }}
|
||||
PROJECT_NAME: ${{ vars.PROJECT_NAME }}
|
||||
SECRET_KEY: ${{ secrets.SECRET_KEY }}
|
||||
FIRST_SUPERUSER: ${{ vars.FIRST_SUPERUSER }}
|
||||
FIRST_SUPERUSER_PASSWORD: ${{ secrets.FIRST_SUPERUSER_PASSWORD }}
|
||||
SMTP_HOST: ${{ vars.SMTP_HOST }}
|
||||
SMTP_USER: ${{ vars.SMTP_USER }}
|
||||
SMTP_PASSWORD: ${{ secrets.SMTP_PASSWORD }}
|
||||
EMAILS_FROM_EMAIL: ${{ vars.EMAILS_FROM_EMAIL }}
|
||||
POSTGRES_PASSWORD: ${{ secrets.POSTGRES_PASSWORD }}
|
||||
SENTRY_DSN: ${{ vars.SENTRY_DSN }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Build
|
||||
run: docker compose -f compose.yml -f compose.deploy.yml build
|
||||
- name: Prepare database
|
||||
run: docker compose -f compose.yml -f compose.deploy.yml run --rm backend bash scripts/prestart.sh
|
||||
- name: Start application
|
||||
run: docker compose -f compose.yml -f compose.deploy.yml up -d
|
||||
@@ -1,32 +0,0 @@
|
||||
name: Deploy to Production
|
||||
|
||||
on:
|
||||
release:
|
||||
types:
|
||||
- published
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
# Do not deploy in the main repository, only in user projects
|
||||
if: github.repository_owner != 'fastapi'
|
||||
runs-on:
|
||||
- self-hosted
|
||||
- production
|
||||
env:
|
||||
ENVIRONMENT: production
|
||||
DOMAIN: ${{ secrets.DOMAIN_PRODUCTION }}
|
||||
STACK_NAME: ${{ secrets.STACK_NAME_PRODUCTION }}
|
||||
SECRET_KEY: ${{ secrets.SECRET_KEY }}
|
||||
FIRST_SUPERUSER: ${{ secrets.FIRST_SUPERUSER }}
|
||||
FIRST_SUPERUSER_PASSWORD: ${{ secrets.FIRST_SUPERUSER_PASSWORD }}
|
||||
SMTP_HOST: ${{ secrets.SMTP_HOST }}
|
||||
SMTP_USER: ${{ secrets.SMTP_USER }}
|
||||
SMTP_PASSWORD: ${{ secrets.SMTP_PASSWORD }}
|
||||
EMAILS_FROM_EMAIL: ${{ secrets.EMAILS_FROM_EMAIL }}
|
||||
POSTGRES_PASSWORD: ${{ secrets.POSTGRES_PASSWORD }}
|
||||
SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
- run: docker compose -f docker-compose.yml --project-name ${{ secrets.STACK_NAME_PRODUCTION }} build
|
||||
- run: docker compose -f docker-compose.yml --project-name ${{ secrets.STACK_NAME_PRODUCTION }} up -d
|
||||
@@ -1,32 +0,0 @@
|
||||
name: Deploy to Staging
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
# Do not deploy in the main repository, only in user projects
|
||||
if: github.repository_owner != 'fastapi'
|
||||
runs-on:
|
||||
- self-hosted
|
||||
- staging
|
||||
env:
|
||||
ENVIRONMENT: staging
|
||||
DOMAIN: ${{ secrets.DOMAIN_STAGING }}
|
||||
STACK_NAME: ${{ secrets.STACK_NAME_STAGING }}
|
||||
SECRET_KEY: ${{ secrets.SECRET_KEY }}
|
||||
FIRST_SUPERUSER: ${{ secrets.FIRST_SUPERUSER }}
|
||||
FIRST_SUPERUSER_PASSWORD: ${{ secrets.FIRST_SUPERUSER_PASSWORD }}
|
||||
SMTP_HOST: ${{ secrets.SMTP_HOST }}
|
||||
SMTP_USER: ${{ secrets.SMTP_USER }}
|
||||
SMTP_PASSWORD: ${{ secrets.SMTP_PASSWORD }}
|
||||
EMAILS_FROM_EMAIL: ${{ secrets.EMAILS_FROM_EMAIL }}
|
||||
POSTGRES_PASSWORD: ${{ secrets.POSTGRES_PASSWORD }}
|
||||
SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
- run: docker compose -f docker-compose.yml --project-name ${{ secrets.STACK_NAME_STAGING }} build
|
||||
- run: docker compose -f docker-compose.yml --project-name ${{ secrets.STACK_NAME_STAGING }} up -d
|
||||
@@ -0,0 +1,54 @@
|
||||
name: Deploy
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
paths-ignore:
|
||||
- release-notes.md
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
# Do not deploy the template repository, only projects created from it
|
||||
if: github.repository != 'fastapi/full-stack-fastapi-template'
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Set up Bun
|
||||
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
|
||||
with:
|
||||
bun-version: 1.3.12
|
||||
- name: Install frontend dependencies
|
||||
run: bun ci
|
||||
- name: Build frontend
|
||||
run: bun run --filter frontend build
|
||||
env:
|
||||
# Override frontend/.env so the deployed frontend uses the same origin as the API
|
||||
VITE_API_URL: ""
|
||||
- name: Set up uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
- name: Prepare database
|
||||
run: uv run bash scripts/prestart.sh
|
||||
working-directory: backend
|
||||
env:
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL }}
|
||||
PROJECT_NAME: ${{ vars.PROJECT_NAME }}
|
||||
SECRET_KEY: ${{ secrets.SECRET_KEY }}
|
||||
FIRST_SUPERUSER: ${{ vars.FIRST_SUPERUSER }}
|
||||
FIRST_SUPERUSER_PASSWORD: ${{ secrets.FIRST_SUPERUSER_PASSWORD }}
|
||||
- name: Deploy to FastAPI Cloud
|
||||
run: uv run fastapi deploy
|
||||
env:
|
||||
FASTAPI_CLOUD_TOKEN: ${{ secrets.FASTAPI_CLOUD_TOKEN }}
|
||||
FASTAPI_CLOUD_APP_ID: ${{ secrets.FASTAPI_CLOUD_APP_ID }}
|
||||
@@ -1,18 +1,21 @@
|
||||
name: "Conflict detector"
|
||||
on:
|
||||
push:
|
||||
pull_request_target:
|
||||
pull_request_target: # zizmor: ignore[dangerous-triggers]
|
||||
types: [synchronize]
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
main:
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Check if PRs have merge conflicts
|
||||
uses: eps1lon/actions-label-merge-conflict@v3
|
||||
uses: eps1lon/actions-label-merge-conflict@0273be72a0bbd58fcd71d0d6c02c209b50d1e5e1 # v3.1.0
|
||||
with:
|
||||
dirtyLabel: "conflicts"
|
||||
repoToken: "${{ secrets.GITHUB_TOKEN }}"
|
||||
|
||||
@@ -1,60 +0,0 @@
|
||||
name: Generate Client
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
|
||||
jobs:
|
||||
generate-client:
|
||||
permissions:
|
||||
contents: write
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# For PRs from forks
|
||||
- uses: actions/checkout@v6
|
||||
# For PRs from the same repo
|
||||
- uses: actions/checkout@v6
|
||||
if: ( github.event_name != 'pull_request' || github.secret_source == 'Actions' )
|
||||
with:
|
||||
ref: ${{ github.head_ref }}
|
||||
token: ${{ secrets.FULL_STACK_FASTAPI_TEMPLATE_REPO_TOKEN }}
|
||||
- uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version: lts/*
|
||||
- uses: actions/setup-python@v6
|
||||
with:
|
||||
python-version: "3.10"
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@v7
|
||||
with:
|
||||
version: "0.4.15"
|
||||
enable-cache: true
|
||||
- name: Install dependencies
|
||||
run: npm ci
|
||||
working-directory: frontend
|
||||
- run: uv sync
|
||||
working-directory: backend
|
||||
- run: uv run bash scripts/generate-client.sh
|
||||
env:
|
||||
VIRTUAL_ENV: backend/.venv
|
||||
SECRET_KEY: just-for-generating-client
|
||||
POSTGRES_PASSWORD: just-for-generating-client
|
||||
FIRST_SUPERUSER_PASSWORD: just-for-generating-client
|
||||
- name: Add changes to git
|
||||
run: |
|
||||
git config --local user.email "github-actions@github.com"
|
||||
git config --local user.name "github-actions"
|
||||
git add frontend/src/client
|
||||
# Same repo PRs
|
||||
- name: Push changes
|
||||
if: ( github.event_name != 'pull_request' || github.secret_source == 'Actions' )
|
||||
run: |
|
||||
git diff --staged --quiet || git commit -m "✨ Autogenerate frontend client"
|
||||
git push
|
||||
# Fork PRs
|
||||
- name: Check changes
|
||||
if: ( github.event_name == 'pull_request' && github.secret_source != 'Actions' )
|
||||
run: |
|
||||
git diff --staged --quiet || (echo "Changes detected in generated client, run scripts/generate-client.sh and commit the changes" && exit 1)
|
||||
@@ -0,0 +1,52 @@
|
||||
name: Guard Dependencies
|
||||
|
||||
on:
|
||||
pull_request_target: # zizmor: ignore[dangerous-triggers] -- This workflow only reads context.payload metadata, never checks out PR code
|
||||
branches: [master]
|
||||
paths:
|
||||
- pyproject.toml
|
||||
- uv.lock
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
issues: write
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
check-author:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check if author is org member or allowed bot
|
||||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||||
with:
|
||||
script: |
|
||||
const pr = context.payload.pull_request;
|
||||
const author = pr.user.login;
|
||||
const assoc = pr.author_association;
|
||||
|
||||
const botAllowlist = new Set(['dependabot[bot]']);
|
||||
const orgAuthorAssociations = new Set(['MEMBER', 'OWNER']);
|
||||
|
||||
const allowed =
|
||||
botAllowlist.has(author) ||
|
||||
(assoc != null && orgAuthorAssociations.has(assoc));
|
||||
|
||||
if (!allowed) {
|
||||
await github.rest.issues.createComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
issue_number: context.payload.pull_request.number,
|
||||
body: `This PR modifies dependency files (\`pyproject.toml\` or \`uv.lock\`), which is restricted to members of the **${context.repo.owner}** organization on GitHub.\n\nIf you need a dependency change, please [open a discussion](https://github.com/${context.repo.owner}/${context.repo.repo}/discussions/new) describing what you need and why.\n\nClosing this PR automatically.`
|
||||
});
|
||||
|
||||
await github.rest.pulls.update({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
pull_number: context.payload.pull_request.number,
|
||||
state: 'closed'
|
||||
});
|
||||
|
||||
core.setFailed('Dependency changes are restricted to organization members.');
|
||||
} else {
|
||||
console.log(`Author ${author} (author_association=${assoc}) is allowed to make dependency changes.`);
|
||||
}
|
||||
@@ -9,43 +9,26 @@ on:
|
||||
issues:
|
||||
types:
|
||||
- labeled
|
||||
pull_request_target:
|
||||
pull_request_target: # zizmor: ignore[dangerous-triggers]
|
||||
types:
|
||||
- labeled
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
issue-manager:
|
||||
if: github.repository_owner == 'fastapi'
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: tiangolo/issue-manager@0.6.0
|
||||
- uses: tiangolo/issue-manager@dc846170c36eb62fb434b3d943b36399fe240fb5 # 0.8.1
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
config: >
|
||||
{
|
||||
"answered": {
|
||||
"delay": 864000,
|
||||
"message": "Assuming the original need was handled, this will be automatically closed now. But feel free to add more comments or create new issues or PRs."
|
||||
},
|
||||
"waiting": {
|
||||
"delay": 2628000,
|
||||
"message": "As this PR has been waiting for the original user for a while but seems to be inactive, it's now going to be closed. But if there's anyone interested, feel free to create a new PR.",
|
||||
"reminder": {
|
||||
"before": "P3D",
|
||||
"message": "Heads-up: this will be closed in 3 days unless there's new activity."
|
||||
}
|
||||
},
|
||||
"invalid": {
|
||||
"delay": 0,
|
||||
"message": "This was marked as invalid and will be closed now. If this is an error, please provide additional details."
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,33 +0,0 @@
|
||||
name: Labels
|
||||
on:
|
||||
pull_request_target:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
# For label-checker
|
||||
- labeled
|
||||
- unlabeled
|
||||
|
||||
jobs:
|
||||
labeler:
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/labeler@v6
|
||||
if: ${{ github.event.action != 'labeled' && github.event.action != 'unlabeled' }}
|
||||
- run: echo "Done adding labels"
|
||||
# Run this after labeler applied labels
|
||||
check-labels:
|
||||
needs:
|
||||
- labeler
|
||||
permissions:
|
||||
pull-requests: read
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: docker://agilepathway/pull-request-label-checker:latest
|
||||
with:
|
||||
one_of: breaking,security,feature,bug,refactor,upgrade,docs,lang-all,internal
|
||||
repo_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
@@ -1,40 +0,0 @@
|
||||
name: Latest Changes
|
||||
|
||||
on:
|
||||
pull_request_target:
|
||||
branches:
|
||||
- master
|
||||
types:
|
||||
- closed
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
number:
|
||||
description: PR number
|
||||
required: true
|
||||
debug_enabled:
|
||||
description: "Run the build with tmate debugging enabled (https://github.com/marketplace/actions/debugging-with-tmate)"
|
||||
required: false
|
||||
default: "false"
|
||||
|
||||
jobs:
|
||||
latest-changes:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
pull-requests: read
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
# To allow latest-changes to commit to the main branch
|
||||
token: ${{ secrets.LATEST_CHANGES }}
|
||||
- uses: tiangolo/latest-changes@0.4.1
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
latest_changes_file: ./release-notes.md
|
||||
latest_changes_header: "## Latest Changes"
|
||||
end_regex: "^## "
|
||||
debug_logs: true
|
||||
label_header_prefix: "### "
|
||||
@@ -1,28 +0,0 @@
|
||||
name: Lint Backend
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
|
||||
jobs:
|
||||
lint-backend:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v6
|
||||
with:
|
||||
python-version: "3.10"
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@v7
|
||||
with:
|
||||
version: "0.4.15"
|
||||
enable-cache: true
|
||||
- run: uv run bash scripts/lint.sh
|
||||
working-directory: backend
|
||||
@@ -5,9 +5,6 @@ on:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
debug_enabled:
|
||||
@@ -15,16 +12,23 @@ on:
|
||||
required: false
|
||||
default: 'false'
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
changes:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
# Set job outputs to values from filter step
|
||||
outputs:
|
||||
changed: ${{ steps.filter.outputs.changed }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 2
|
||||
persist-credentials: false
|
||||
# For pull requests it's not necessary to checkout the code but for the main branch it is
|
||||
- uses: dorny/paths-filter@v3
|
||||
- uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
|
||||
id: filter
|
||||
with:
|
||||
filters: |
|
||||
@@ -32,14 +36,14 @@ jobs:
|
||||
- backend/**
|
||||
- frontend/**
|
||||
- .env
|
||||
- docker-compose*.yml
|
||||
- compose*.yml
|
||||
- .github/workflows/playwright.yml
|
||||
|
||||
test-playwright:
|
||||
needs:
|
||||
- changes
|
||||
if: ${{ needs.changes.outputs.changed == 'true' }}
|
||||
timeout-minutes: 60
|
||||
timeout-minutes: 15
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
@@ -47,38 +51,38 @@ jobs:
|
||||
shardTotal: [4]
|
||||
fail-fast: false
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/setup-node@v6
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
node-version: lts/*
|
||||
- uses: actions/setup-python@v6
|
||||
persist-credentials: false
|
||||
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
|
||||
with:
|
||||
python-version: '3.10'
|
||||
bun-version: 1.3.12
|
||||
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: .python-version
|
||||
- name: Setup tmate session
|
||||
uses: mxschmitt/action-tmate@v3
|
||||
uses: mxschmitt/action-tmate@35b54afac29c97fb54faba5b513f8fbd1882f113 # v3.24
|
||||
if: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.debug_enabled == 'true' }}
|
||||
with:
|
||||
limit-access-to-actor: true
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@v7
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "0.4.15"
|
||||
enable-cache: true
|
||||
version: "latest-known"
|
||||
- run: uv sync
|
||||
working-directory: backend
|
||||
- run: npm ci
|
||||
- run: bun ci
|
||||
working-directory: frontend
|
||||
- run: uv run bash scripts/generate-client.sh
|
||||
env:
|
||||
VIRTUAL_ENV: backend/.venv
|
||||
- run: bash scripts/generate-client.sh
|
||||
- run: docker compose build
|
||||
- run: docker compose down -v --remove-orphans
|
||||
- run: docker compose run --rm backend bash scripts/prestart.sh
|
||||
- name: Run Playwright tests
|
||||
run: docker compose run --rm playwright npx playwright test --fail-on-flaky-tests --trace=retain-on-failure --shard=${{ matrix.shardIndex }}/${{ matrix.shardTotal }}
|
||||
run: docker compose run --rm playwright bunx playwright test --fail-on-flaky-tests --trace=retain-on-failure --shard=${{ matrix.shardIndex }}/${{ matrix.shardTotal }}
|
||||
- run: docker compose down -v --remove-orphans
|
||||
- name: Upload blob report to GitHub Actions Artifacts
|
||||
if: ${{ !cancelled() }}
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: blob-report-${{ matrix.shardIndex }}
|
||||
path: frontend/blob-report
|
||||
@@ -92,25 +96,27 @@ jobs:
|
||||
# Merge reports after playwright-tests, even if some shards have failed
|
||||
if: ${{ !cancelled() && needs.changes.outputs.changed == 'true' }}
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/setup-node@v6
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
node-version: 20
|
||||
persist-credentials: false
|
||||
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
|
||||
with:
|
||||
bun-version: 1.3.12
|
||||
- name: Install dependencies
|
||||
run: npm ci
|
||||
working-directory: frontend
|
||||
run: bun ci
|
||||
- name: Download blob reports from GitHub Actions Artifacts
|
||||
uses: actions/download-artifact@v6
|
||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
path: frontend/all-blob-reports
|
||||
pattern: blob-report-*
|
||||
merge-multiple: true
|
||||
- name: Merge into HTML Report
|
||||
run: npx playwright merge-reports --reporter html ./all-blob-reports
|
||||
run: bunx playwright merge-reports --reporter html ./all-blob-reports
|
||||
working-directory: frontend
|
||||
- name: Upload HTML report
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: html-report--attempt-${{ github.run_attempt }}
|
||||
path: frontend/playwright-report
|
||||
@@ -123,9 +129,10 @@ jobs:
|
||||
needs:
|
||||
- test-playwright
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Decide whether the needed jobs succeeded or failed
|
||||
uses: re-actors/alls-green@release/v1
|
||||
uses: re-actors/alls-green@b5b5b37504aa4183270bd3d855c52a67f212be35 # v1.3.0
|
||||
with:
|
||||
jobs: ${{ toJSON(needs) }}
|
||||
allowed-skips: test-playwright
|
||||
|
||||
@@ -0,0 +1,114 @@
|
||||
name: pre-commit
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
permissions: {}
|
||||
|
||||
env:
|
||||
CAN_PUSH: ${{ github.event.pull_request.head.repo.full_name == github.repository && github.actor != 'dependabot[bot]' }}
|
||||
|
||||
jobs:
|
||||
pre-commit:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
name: Checkout PR for own repo
|
||||
if: env.CAN_PUSH == 'true'
|
||||
with:
|
||||
# To be able to commit it needs to fetch the head of the branch, not the
|
||||
# merge commit
|
||||
ref: ${{ github.head_ref }}
|
||||
# And it needs the full history to be able to compute diffs
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
# pre-commit lite ci needs the default checkout configs to work
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
name: Checkout PR for fork
|
||||
if: env.CAN_PUSH == 'false'
|
||||
with:
|
||||
# To be able to commit it needs the head branch of the PR, the remote one
|
||||
ref: ${{ github.event.pull_request.head.sha }}
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
|
||||
with:
|
||||
bun-version: 1.3.12
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: .python-version
|
||||
- name: Setup uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
cache-dependency-glob: |
|
||||
requirements**.txt
|
||||
pyproject.toml
|
||||
uv.lock
|
||||
- name: Install backend dependencies
|
||||
run: uv sync --all-packages
|
||||
- name: Install frontend dependencies
|
||||
run: bun ci
|
||||
- name: Run prek - pre-commit
|
||||
id: precommit
|
||||
run: uv run prek run --from-ref origin/${GITHUB_BASE_REF} --to-ref HEAD --show-diff-on-failure
|
||||
continue-on-error: true
|
||||
- name: Check for changes
|
||||
id: changes
|
||||
run: |
|
||||
if [[ -n "$(git status --porcelain)" ]]; then
|
||||
echo "changed=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "changed=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
- name: Get PR Push token
|
||||
id: pr-push
|
||||
if: env.CAN_PUSH == 'true' && steps.changes.outputs.changed == 'true'
|
||||
uses: tiangolo/pr-push@f336b3817f32ea9b8273a8c15f8ecb739ac38167 # 0.0.4
|
||||
- name: Commit and push changes
|
||||
if: env.CAN_PUSH == 'true' && steps.changes.outputs.changed == 'true'
|
||||
env:
|
||||
GH_TOKEN: ${{ steps.pr-push.outputs.token }}
|
||||
run: |
|
||||
git config user.name "pr-push[bot]"
|
||||
git config user.email "pr-push[bot]@users.noreply.github.com"
|
||||
gh auth setup-git
|
||||
git add -A
|
||||
if git diff --staged --quiet; then
|
||||
echo "No changes to commit"
|
||||
else
|
||||
git commit -m "🎨 Auto format and update with pre-commit"
|
||||
git push
|
||||
fi
|
||||
- uses: pre-commit-ci/lite-action@5d6cc0eb514c891a40562a58a8e71576c5c7fb43 # v1.1.0
|
||||
if: env.CAN_PUSH == 'false'
|
||||
with:
|
||||
msg: 🎨 Auto format and update with pre-commit
|
||||
- name: Error out on pre-commit errors
|
||||
if: steps.precommit.outcome == 'failure'
|
||||
run: exit 1
|
||||
|
||||
# https://github.com/marketplace/actions/alls-green#why
|
||||
pre-commit-alls-green: # This job does nothing and is only used for the branch protection
|
||||
if: always()
|
||||
needs:
|
||||
- pre-commit
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- name: Decide whether the needed jobs succeeded or failed
|
||||
uses: re-actors/alls-green@b5b5b37504aa4183270bd3d855c52a67f212be35 # v1.3.0
|
||||
with:
|
||||
jobs: ${{ toJSON(needs) }}
|
||||
@@ -0,0 +1,82 @@
|
||||
name: Prepare Release
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
bump:
|
||||
description: Release bump
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- patch
|
||||
- minor
|
||||
- major
|
||||
date:
|
||||
description: Release date in YYYY-MM-DD format. Defaults to today.
|
||||
required: false
|
||||
type: string
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
prepare-release:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
steps:
|
||||
- name: Dump GitHub context
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: ".python-version"
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
- name: Prepare release
|
||||
env:
|
||||
BUMP: ${{ inputs.bump }}
|
||||
RELEASE_DATE: ${{ inputs.date }}
|
||||
run: uv run python scripts/prepare_release.py prepare "$BUMP" --date "$RELEASE_DATE"
|
||||
- name: Get release version
|
||||
id: release-version
|
||||
run: |
|
||||
version="$(uv run python scripts/prepare_release.py current-version)"
|
||||
echo "$version"
|
||||
echo "version=$version" >> "$GITHUB_OUTPUT"
|
||||
- name: Get PR Submit token
|
||||
id: pr-submit
|
||||
uses: tiangolo/pr-submit@d802fdf59bde80bc3eb8bd3259f4cbeec63de4aa # 0.0.1
|
||||
- name: Create release pull request
|
||||
env:
|
||||
BASE_BRANCH: ${{ github.event.repository.default_branch }}
|
||||
GH_TOKEN: ${{ steps.pr-submit.outputs.token }}
|
||||
VERSION: ${{ steps.release-version.outputs.version }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
branch="release-${VERSION}-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
|
||||
git config user.name "pr-submit[bot]"
|
||||
git config user.email "pr-submit[bot]@users.noreply.github.com"
|
||||
git switch -c "$branch"
|
||||
git add release-notes.md
|
||||
git commit -m "🔖 Release version ${VERSION}"
|
||||
gh auth setup-git
|
||||
git push --set-upstream origin "$branch"
|
||||
gh label create release \
|
||||
--description "Release preparation" \
|
||||
--color ededed \
|
||||
--force
|
||||
gh pr create \
|
||||
--base "$BASE_BRANCH" \
|
||||
--head "$branch" \
|
||||
--title "🔖 Release version ${VERSION}" \
|
||||
--body "Prepare release ${VERSION}." \
|
||||
--label release
|
||||
@@ -1,35 +1,47 @@
|
||||
name: Smokeshow
|
||||
|
||||
on:
|
||||
workflow_run:
|
||||
workflow_run: # zizmor: ignore[dangerous-triggers]
|
||||
workflows: [Test Backend]
|
||||
types: [completed]
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
smokeshow:
|
||||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
statuses: write
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/setup-python@v6
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
python-version: "3.10"
|
||||
- run: pip install smokeshow
|
||||
- uses: actions/download-artifact@v6
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version-file: .python-version
|
||||
- name: Setup uv
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "latest-known"
|
||||
cache-dependency-glob: |
|
||||
pyproject.toml
|
||||
uv.lock
|
||||
- run: uv sync --all-packages --no-dev --group github-actions
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
name: coverage-html
|
||||
path: backend/htmlcov
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
run-id: ${{ github.event.workflow_run.id }}
|
||||
- run: smokeshow upload backend/htmlcov
|
||||
- run: uv run smokeshow upload backend/htmlcov
|
||||
env:
|
||||
SMOKESHOW_GITHUB_STATUS_DESCRIPTION: Coverage {coverage-percentage}
|
||||
SMOKESHOW_GITHUB_COVERAGE_THRESHOLD: 90
|
||||
SMOKESHOW_GITHUB_CONTEXT: coverage
|
||||
SMOKESHOW_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
SMOKESHOW_GITHUB_PR_HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
|
||||
SMOKESHOW_AUTH_KEY: ${{ secrets.SMOKESHOW_AUTH_KEY }}
|
||||
SMOKESHOW_AUTH_KEY: ${{ secrets.SMOKESHOW_AUTH_KEY }} # zizmor: ignore[secrets-outside-env]
|
||||
|
||||
@@ -5,27 +5,28 @@ on:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
test-backend:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v6
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version: "3.10"
|
||||
python-version-file: .python-version
|
||||
- name: Install uv
|
||||
uses: astral-sh/setup-uv@v7
|
||||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||||
with:
|
||||
version: "0.4.15"
|
||||
enable-cache: true
|
||||
version: "latest-known"
|
||||
- run: docker compose down -v --remove-orphans
|
||||
- run: docker compose up -d db mailcatcher
|
||||
- run: docker compose up -d --wait db mailpit
|
||||
- name: Migrate DB
|
||||
run: uv run bash scripts/prestart.sh
|
||||
working-directory: backend
|
||||
@@ -34,8 +35,11 @@ jobs:
|
||||
working-directory: backend
|
||||
- run: docker compose down -v --remove-orphans
|
||||
- name: Store coverage files
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: coverage-html
|
||||
path: backend/htmlcov
|
||||
include-hidden-files: true
|
||||
- name: Coverage report
|
||||
run: uv run coverage report --fail-under=90
|
||||
working-directory: backend
|
||||
|
||||
@@ -5,22 +5,25 @@ on:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
|
||||
test-docker-compose:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- run: docker compose build
|
||||
- run: docker compose down -v --remove-orphans
|
||||
- run: docker compose up -d --wait backend frontend adminer
|
||||
- run: docker compose run --rm backend bash scripts/prestart.sh
|
||||
- run: docker compose up -d --wait backend adminer
|
||||
- name: Test backend is up
|
||||
run: curl http://localhost:8000/api/v1/utils/health-check
|
||||
- name: Test frontend is up
|
||||
run: curl http://localhost:5173
|
||||
run: curl http://localhost:8000
|
||||
- run: docker compose down -v --remove-orphans
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
name: Zizmor
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
zizmor:
|
||||
name: Run zizmor
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
security-events: write # Required for upload-sarif (used by zizmor-action) to upload SARIF files.
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Run zizmor
|
||||
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
|
||||
with:
|
||||
advanced-security: ${{ github.repository_owner == 'fastapi' }}
|
||||
annotations: ${{ github.repository_owner != 'fastapi' }}
|
||||
+3
-1
@@ -1,5 +1,7 @@
|
||||
.vscode
|
||||
.vscode/*
|
||||
!.vscode/extensions.json
|
||||
node_modules/
|
||||
backend/app/frontend/
|
||||
/test-results/
|
||||
/playwright-report/
|
||||
/blob-report/
|
||||
|
||||
+56
-12
@@ -2,7 +2,7 @@
|
||||
# See https://pre-commit.com/hooks.html for more hooks
|
||||
repos:
|
||||
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||
rev: v4.4.0
|
||||
rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # v6.0.0
|
||||
hooks:
|
||||
- id: check-added-large-files
|
||||
- id: check-toml
|
||||
@@ -13,26 +13,70 @@ repos:
|
||||
exclude: |
|
||||
(?x)^(
|
||||
frontend/src/client/.*|
|
||||
backend/app/email-templates/build/.*
|
||||
backend/app/email-templates/.*
|
||||
)$
|
||||
- id: trailing-whitespace
|
||||
exclude: ^frontend/src/client/.*
|
||||
- repo: https://github.com/charliermarsh/ruff-pre-commit
|
||||
rev: v0.2.2
|
||||
- repo: https://github.com/crate-ci/typos
|
||||
rev: 8a48f81b6c64dcfea44b3633223084c4be58ac5f # frozen: v1.49.0
|
||||
hooks:
|
||||
- id: ruff
|
||||
args:
|
||||
- --fix
|
||||
- id: ruff-format
|
||||
- id: typos
|
||||
args: [--force-exclude]
|
||||
- repo: local
|
||||
hooks:
|
||||
- id: local-biome-check
|
||||
name: biome check
|
||||
entry: bash -c 'cd frontend && npm run lint'
|
||||
entry: npm run lint
|
||||
language: system
|
||||
types: [text]
|
||||
files: ^frontend/
|
||||
|
||||
ci:
|
||||
autofix_commit_msg: 🎨 [pre-commit.ci] Auto format from pre-commit.com hooks
|
||||
autoupdate_commit_msg: ⬆ [pre-commit.ci] pre-commit autoupdate
|
||||
- id: local-ruff-check
|
||||
name: ruff check
|
||||
entry: uv run ruff check --force-exclude --fix --exit-non-zero-on-fix
|
||||
require_serial: true
|
||||
language: unsupported
|
||||
types: [python]
|
||||
|
||||
- id: local-ruff-format
|
||||
name: ruff format
|
||||
entry: uv run ruff format --force-exclude --exit-non-zero-on-format
|
||||
require_serial: true
|
||||
language: unsupported
|
||||
types: [python]
|
||||
|
||||
- id: local-mypy
|
||||
name: mypy check
|
||||
entry: uv run mypy backend/app
|
||||
require_serial: true
|
||||
language: unsupported
|
||||
pass_filenames: false
|
||||
|
||||
- id: local-ty
|
||||
name: ty check
|
||||
entry: uv run ty check backend/app
|
||||
require_serial: true
|
||||
language: unsupported
|
||||
pass_filenames: false
|
||||
|
||||
- id: generate-frontend-sdk
|
||||
name: Generate Frontend SDK
|
||||
entry: bash ./scripts/generate-client.sh
|
||||
pass_filenames: false
|
||||
language: unsupported
|
||||
files: ^backend/app/.*\.py$|^backend/pyproject\.toml$|^uv\.lock$|^frontend/openapi-ts\.config\.ts$|^scripts/generate-client\.sh$
|
||||
|
||||
- id: add-release-date
|
||||
language: unsupported
|
||||
name: add date to latest release header
|
||||
entry: uv run python scripts/add_latest_release_date.py
|
||||
files: ^release-notes\.md$
|
||||
pass_filenames: false
|
||||
|
||||
- id: zizmor
|
||||
name: zizmor
|
||||
language: python
|
||||
entry: uv run zizmor .
|
||||
files: ^\.github\/workflows\/
|
||||
require_serial: true
|
||||
pass_filenames: false
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
3.14
|
||||
Vendored
+14
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"recommendations": [
|
||||
"FastAPILabs.fastapi-vscode",
|
||||
"astral-sh.ty",
|
||||
"biomejs.biome",
|
||||
"bradlc.vscode-tailwindcss",
|
||||
"charliermarsh.ruff",
|
||||
"docker.docker",
|
||||
"github.vscode-github-actions",
|
||||
"ms-playwright.playwright",
|
||||
"ms-python.python",
|
||||
"tombi-toml.tombi"
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
# Contributing
|
||||
|
||||
Thank you for your interest in contributing to the Full Stack FastAPI Template! 🙇
|
||||
|
||||
## Discussions First
|
||||
|
||||
For **big changes** (new features, architectural changes, significant refactoring), please start by opening a [GitHub Discussion](https://github.com/fastapi/full-stack-fastapi-template/discussions) first. This allows the community and maintainers to provide feedback on the approach before you invest significant time in implementation.
|
||||
|
||||
For small, straightforward changes, you can go directly to a Pull Request without starting a discussion first. This includes:
|
||||
|
||||
- Typos and grammatical fixes
|
||||
- Small reproducible bug fixes
|
||||
- Fixing lint warnings or type errors
|
||||
- Minor code improvements (e.g., removing unused code)
|
||||
|
||||
Note that PRs from non-team members are not allowed to modify `pyproject.toml` or `uv.lock`, to prevent supply chain risk.
|
||||
If you would like to add a new dependency, create a new [Discussion](https://github.com/fastapi/full-stack-fastapi-template/discussions) to explain why.
|
||||
|
||||
## Developing
|
||||
|
||||
For detailed instructions on setting up your development environment, running the stack, linting, pre-commit hooks, and more, see the [Development Guide](development.md).
|
||||
|
||||
## Pull Requests
|
||||
|
||||
When submitting a pull request:
|
||||
|
||||
1. Make sure all tests pass before submitting.
|
||||
2. Keep PRs focused on a single change.
|
||||
3. Update tests if you're changing functionality.
|
||||
4. Reference any related issues in your PR description.
|
||||
|
||||
## Automated Code and AI
|
||||
|
||||
You are encouraged to use all the tools you want to do your work and contribute as efficiently as possible, this includes AI (LLM) tools, etc. Nevertheless, contributions should have meaningful human intervention, judgement, context, etc.
|
||||
|
||||
If the **human effort** put in a PR, e.g. writing LLM prompts, is **less** than the **effort we would need to put** to **review it**, please **don't** submit the PR.
|
||||
|
||||
Think of it this way: we can already write LLM prompts or run automated tools ourselves, and that would be faster than reviewing external PRs.
|
||||
|
||||
### Closing Automated and AI PRs
|
||||
|
||||
If we see PRs that seem AI generated or automated in similar ways, we'll flag them and close them.
|
||||
|
||||
The same applies to comments and descriptions, please don't copy paste the content generated by an LLM.
|
||||
|
||||
### Human Effort Denial of Service
|
||||
|
||||
Using automated tools and AI to submit PRs or comments that we have to carefully review and handle would be the equivalent of a [Denial-of-service attack](https://en.wikipedia.org/wiki/Denial-of-service_attack) on our human effort.
|
||||
|
||||
It would be very little effort from the person submitting the PR (an LLM prompt) that generates a large amount of effort on our side (carefully reviewing code).
|
||||
|
||||
Please don't do that.
|
||||
|
||||
We'll need to block accounts that spam us with repeated automated PRs or comments.
|
||||
|
||||
### Use Tools Wisely
|
||||
|
||||
As Uncle Ben said:
|
||||
|
||||
> With great ~~power~~ **tools** comes great responsibility.
|
||||
|
||||
Avoid inadvertently doing harm.
|
||||
|
||||
You have amazing tools at hand, use them wisely to help effectively.
|
||||
|
||||
## Questions?
|
||||
|
||||
If you have questions about contributing, feel free to open a [GitHub Discussion](https://github.com/fastapi/full-stack-fastapi-template/discussions).
|
||||
@@ -1,8 +1,7 @@
|
||||
# Full Stack FastAPI Template
|
||||
|
||||
<a href="https://github.com/fastapi/full-stack-fastapi-template/actions?query=workflow%3A%22Test+Docker+Compose%22" target="_blank"><img src="https://github.com/fastapi/full-stack-fastapi-template/workflows/Test%20Docker%20Compose/badge.svg" alt="Test Docker Compose"></a>
|
||||
<a href="https://github.com/fastapi/full-stack-fastapi-template/actions?query=workflow%3A%22Test+Backend%22" target="_blank"><img src="https://github.com/fastapi/full-stack-fastapi-template/workflows/Test%20Backend/badge.svg" alt="Test Backend"></a>
|
||||
<a href="https://coverage-badge.samuelcolvin.workers.dev/redirect/fastapi/full-stack-fastapi-template" target="_blank"><img src="https://coverage-badge.samuelcolvin.workers.dev/fastapi/full-stack-fastapi-template.svg" alt="Coverage"></a>
|
||||
[](../../actions/workflows/test-docker-compose.yml)
|
||||
[](../../actions/workflows/test-backend.yml)
|
||||
|
||||
## Technology Stack and Features
|
||||
|
||||
@@ -11,200 +10,54 @@
|
||||
- 🔍 [Pydantic](https://docs.pydantic.dev), used by FastAPI, for the data validation and settings management.
|
||||
- 💾 [PostgreSQL](https://www.postgresql.org) as the SQL database.
|
||||
- 🚀 [React](https://react.dev) for the frontend.
|
||||
- 🧩 Built into the backend application and served by FastAPI on the same domain as the API.
|
||||
- 💃 Using TypeScript, hooks, [Vite](https://vitejs.dev), and other parts of a modern frontend stack.
|
||||
- 🎨 [Tailwind CSS](https://tailwindcss.com) and [shadcn/ui](https://ui.shadcn.com) for the frontend components.
|
||||
- 🤖 An automatically generated frontend client.
|
||||
- 🧪 [Playwright](https://playwright.dev) for End-to-End testing.
|
||||
- 🧪 [Playwright](https://playwright.dev) for end-to-end testing.
|
||||
- 🦇 Dark mode support.
|
||||
- 🐋 [Docker Compose](https://www.docker.com) for development and production.
|
||||
- ☁️ [FastAPI Cloud](https://fastapicloud.com) for deployment.
|
||||
- 🐋 [Docker Compose](https://www.docker.com) for local services and self-hosted deployment.
|
||||
- 📞 [Traefik](https://traefik.io) as a reverse proxy with automatic HTTPS.
|
||||
- 🔒 Secure password hashing by default.
|
||||
- 🔑 JWT (JSON Web Token) authentication.
|
||||
- 📫 Email based password recovery.
|
||||
- 📬 [Mailcatcher](https://mailcatcher.me) for local email testing during development.
|
||||
- 📫 Email-based password recovery.
|
||||
- ✉️ [React Email](https://react.email) for email templates.
|
||||
- 📬 [Mailpit](https://mailpit.axllent.org) for local email testing during development.
|
||||
- ✅ Tests with [Pytest](https://pytest.org).
|
||||
- 📞 [Traefik](https://traefik.io) as a reverse proxy / load balancer.
|
||||
- 🚢 Deployment instructions using Docker Compose, including how to set up a frontend Traefik proxy to handle automatic HTTPS certificates.
|
||||
- 🏭 CI (continuous integration) and CD (continuous deployment) based on GitHub Actions.
|
||||
|
||||
### Dashboard Login
|
||||
|
||||
[](https://github.com/fastapi/full-stack-fastapi-template)
|
||||

|
||||
|
||||
### Dashboard - Admin
|
||||
|
||||
[](https://github.com/fastapi/full-stack-fastapi-template)
|
||||

|
||||
|
||||
### Dashboard - Items
|
||||
|
||||
[](https://github.com/fastapi/full-stack-fastapi-template)
|
||||

|
||||
|
||||
### Dashboard - Dark Mode
|
||||
|
||||
[](https://github.com/fastapi/full-stack-fastapi-template)
|
||||

|
||||
|
||||
### React Email Templates
|
||||
|
||||

|
||||
|
||||
### Mailpit - Local Email Testing
|
||||
|
||||

|
||||
|
||||
### Interactive API Documentation
|
||||
|
||||
[](https://github.com/fastapi/full-stack-fastapi-template)
|
||||

|
||||
|
||||
## How To Use It
|
||||
## How to Use It
|
||||
|
||||
You can **just fork or clone** this repository and use it as is.
|
||||
|
||||
✨ It just works. ✨
|
||||
|
||||
### How to Use a Private Repository
|
||||
|
||||
If you want to have a private repository, GitHub won't allow you to simply fork it as it doesn't allow changing the visibility of forks.
|
||||
|
||||
But you can do the following:
|
||||
|
||||
- Create a new GitHub repo, for example `my-full-stack`.
|
||||
- Clone this repository manually, set the name with the name of the project you want to use, for example `my-full-stack`:
|
||||
|
||||
```bash
|
||||
git clone git@github.com:fastapi/full-stack-fastapi-template.git my-full-stack
|
||||
```
|
||||
|
||||
- Enter into the new directory:
|
||||
|
||||
```bash
|
||||
cd my-full-stack
|
||||
```
|
||||
|
||||
- Set the new origin to your new repository, copy it from the GitHub interface, for example:
|
||||
|
||||
```bash
|
||||
git remote set-url origin git@github.com:octocat/my-full-stack.git
|
||||
```
|
||||
|
||||
- Add this repo as another "remote" to allow you to get updates later:
|
||||
|
||||
```bash
|
||||
git remote add upstream git@github.com:fastapi/full-stack-fastapi-template.git
|
||||
```
|
||||
|
||||
- Push the code to your new repository:
|
||||
|
||||
```bash
|
||||
git push -u origin master
|
||||
```
|
||||
|
||||
### Update From the Original Template
|
||||
|
||||
After cloning the repository, and after doing changes, you might want to get the latest changes from this original template.
|
||||
|
||||
- Make sure you added the original repository as a remote, you can check it with:
|
||||
|
||||
```bash
|
||||
git remote -v
|
||||
|
||||
origin git@github.com:octocat/my-full-stack.git (fetch)
|
||||
origin git@github.com:octocat/my-full-stack.git (push)
|
||||
upstream git@github.com:fastapi/full-stack-fastapi-template.git (fetch)
|
||||
upstream git@github.com:fastapi/full-stack-fastapi-template.git (push)
|
||||
```
|
||||
|
||||
- Pull the latest changes without merging:
|
||||
|
||||
```bash
|
||||
git pull --no-commit upstream master
|
||||
```
|
||||
|
||||
This will download the latest changes from this template without committing them, that way you can check everything is right before committing.
|
||||
|
||||
- If there are conflicts, solve them in your editor.
|
||||
|
||||
- Once you are done, commit the changes:
|
||||
|
||||
```bash
|
||||
git merge --continue
|
||||
```
|
||||
|
||||
### Configure
|
||||
|
||||
You can then update configs in the `.env` files to customize your configurations.
|
||||
|
||||
Before deploying it, make sure you change at least the values for:
|
||||
|
||||
- `SECRET_KEY`
|
||||
- `FIRST_SUPERUSER_PASSWORD`
|
||||
- `POSTGRES_PASSWORD`
|
||||
|
||||
You can (and should) pass these as environment variables from secrets.
|
||||
|
||||
Read the [deployment.md](./deployment.md) docs for more details.
|
||||
|
||||
### Generate Secret Keys
|
||||
|
||||
Some environment variables in the `.env` file have a default value of `changethis`.
|
||||
|
||||
You have to change them with a secret key, to generate secret keys you can run the following command:
|
||||
|
||||
```bash
|
||||
python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||
```
|
||||
|
||||
Copy the content and use that as password / secret key. And run that again to generate another secure key.
|
||||
|
||||
## How To Use It - Alternative With Copier
|
||||
|
||||
This repository also supports generating a new project using [Copier](https://copier.readthedocs.io).
|
||||
|
||||
It will copy all the files, ask you configuration questions, and update the `.env` files with your answers.
|
||||
|
||||
### Install Copier
|
||||
|
||||
You can install Copier with:
|
||||
|
||||
```bash
|
||||
pip install copier
|
||||
```
|
||||
|
||||
Or better, if you have [`pipx`](https://pipx.pypa.io/), you can run it with:
|
||||
|
||||
```bash
|
||||
pipx install copier
|
||||
```
|
||||
|
||||
**Note**: If you have `pipx`, installing copier is optional, you could run it directly.
|
||||
|
||||
### Generate a Project With Copier
|
||||
|
||||
Decide a name for your new project's directory, you will use it below. For example, `my-awesome-project`.
|
||||
|
||||
Go to the directory that will be the parent of your project, and run the command with your project's name:
|
||||
|
||||
```bash
|
||||
copier copy https://github.com/fastapi/full-stack-fastapi-template my-awesome-project --trust
|
||||
```
|
||||
|
||||
If you have `pipx` and you didn't install `copier`, you can run it directly:
|
||||
|
||||
```bash
|
||||
pipx run copier copy https://github.com/fastapi/full-stack-fastapi-template my-awesome-project --trust
|
||||
```
|
||||
|
||||
**Note** the `--trust` option is necessary to be able to execute a [post-creation script](https://github.com/fastapi/full-stack-fastapi-template/blob/master/.copier/update_dotenv.py) that updates your `.env` files.
|
||||
|
||||
### Input Variables
|
||||
|
||||
Copier will ask you for some data, you might want to have at hand before generating the project.
|
||||
|
||||
But don't worry, you can just update any of that in the `.env` files afterwards.
|
||||
|
||||
The input variables, with their default values (some auto generated) are:
|
||||
|
||||
- `project_name`: (default: `"FastAPI Project"`) The name of the project, shown to API users (in .env).
|
||||
- `stack_name`: (default: `"fastapi-project"`) The name of the stack used for Docker Compose labels and project name (no spaces, no periods) (in .env).
|
||||
- `secret_key`: (default: `"changethis"`) The secret key for the project, used for security, stored in .env, you can generate one with the method above.
|
||||
- `first_superuser`: (default: `"admin@example.com"`) The email of the first superuser (in .env).
|
||||
- `first_superuser_password`: (default: `"changethis"`) The password of the first superuser (in .env).
|
||||
- `smtp_host`: (default: "") The SMTP server host to send emails, you can set it later in .env.
|
||||
- `smtp_user`: (default: "") The SMTP server user to send emails, you can set it later in .env.
|
||||
- `smtp_password`: (default: "") The SMTP server password to send emails, you can set it later in .env.
|
||||
- `emails_from_email`: (default: `"info@example.com"`) The email account to send emails from, you can set it later in .env.
|
||||
- `postgres_password`: (default: `"changethis"`) The password for the PostgreSQL database, stored in .env, you can generate one with the method above.
|
||||
- `sentry_dsn`: (default: "") The DSN for Sentry, if you are using it, you can set it later in .env.
|
||||
Click the **Use this template** button at the top of this page to create a new repository.
|
||||
|
||||
## Backend Development
|
||||
|
||||
@@ -216,13 +69,15 @@ Frontend docs: [frontend/README.md](./frontend/README.md).
|
||||
|
||||
## Deployment
|
||||
|
||||
Deployment docs: [deployment.md](./deployment.md).
|
||||
FastAPI Cloud deployment: [deployment.md](./deployment.md).
|
||||
|
||||
Self-hosted deployment with Docker Compose: [deployment-docker-compose.md](./deployment-docker-compose.md).
|
||||
|
||||
## Development
|
||||
|
||||
General development docs: [development.md](./development.md).
|
||||
|
||||
This includes using Docker Compose, custom local domains, `.env` configurations, etc.
|
||||
This includes the local FastAPI and Vite workflow, Docker Compose services, `.env` configuration, and more.
|
||||
|
||||
## Release Notes
|
||||
|
||||
|
||||
-29
@@ -1,29 +0,0 @@
|
||||
# Security Policy
|
||||
|
||||
Security is very important for this project and its community. 🔒
|
||||
|
||||
Learn more about it below. 👇
|
||||
|
||||
## Versions
|
||||
|
||||
The latest version or release is supported.
|
||||
|
||||
You are encouraged to write tests for your application and update your versions frequently after ensuring that your tests are passing. This way you will benefit from the latest features, bug fixes, and **security fixes**.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you think you found a vulnerability, and even if you are not sure about it, please report it right away by sending an email to: security@tiangolo.com. Please try to be as explicit as possible, describing all the steps and example code to reproduce the security issue.
|
||||
|
||||
I (the author, [@tiangolo](https://twitter.com/tiangolo)) will review it thoroughly and get back to you.
|
||||
|
||||
## Public Discussions
|
||||
|
||||
Please restrain from publicly discussing a potential security vulnerability. 🙊
|
||||
|
||||
It's better to discuss privately and try to find a solution first, to limit the potential impact as much as possible.
|
||||
|
||||
---
|
||||
|
||||
Thanks for your help!
|
||||
|
||||
The community and I thank you for that. 🙇
|
||||
+37
-16
@@ -1,16 +1,28 @@
|
||||
FROM python:3.10
|
||||
FROM oven/bun:1 AS frontend-build
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY package.json bun.lock /app/
|
||||
COPY frontend/package.json /app/frontend/
|
||||
|
||||
WORKDIR /app/frontend
|
||||
|
||||
RUN bun install
|
||||
|
||||
COPY ./frontend /app/frontend
|
||||
|
||||
ARG VITE_API_URL=
|
||||
|
||||
RUN bun run build
|
||||
|
||||
|
||||
FROM python:3.14
|
||||
|
||||
ENV PYTHONUNBUFFERED=1
|
||||
|
||||
WORKDIR /app/
|
||||
|
||||
# Install uv
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#installing-uv
|
||||
COPY --from=ghcr.io/astral-sh/uv:0.5.11 /uv /uvx /bin/
|
||||
|
||||
# Place executables in the environment at the front of the path
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#using-the-environment
|
||||
ENV PATH="/app/.venv/bin:$PATH"
|
||||
COPY --from=ghcr.io/astral-sh/uv:0.9.26 /uv /uvx /bin/
|
||||
|
||||
# Compile bytecode
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#compiling-bytecode
|
||||
@@ -20,25 +32,34 @@ ENV UV_COMPILE_BYTECODE=1
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#caching
|
||||
ENV UV_LINK_MODE=copy
|
||||
|
||||
WORKDIR /app/
|
||||
|
||||
# Place executables in the environment at the front of the path
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#using-the-environment
|
||||
ENV PATH="/app/.venv/bin:$PATH"
|
||||
|
||||
# Install dependencies
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#intermediate-layers
|
||||
RUN --mount=type=cache,target=/root/.cache/uv \
|
||||
--mount=type=bind,source=uv.lock,target=uv.lock \
|
||||
--mount=type=bind,source=pyproject.toml,target=pyproject.toml \
|
||||
uv sync --frozen --no-install-project
|
||||
uv sync --frozen --no-install-workspace --package app
|
||||
|
||||
ENV PYTHONPATH=/app
|
||||
COPY ./backend/scripts /app/backend/scripts
|
||||
|
||||
COPY ./scripts /app/scripts
|
||||
COPY ./backend/pyproject.toml ./backend/alembic.ini /app/backend/
|
||||
|
||||
COPY ./pyproject.toml ./uv.lock ./alembic.ini /app/
|
||||
COPY ./backend/app /app/backend/app
|
||||
|
||||
COPY ./app /app/app
|
||||
COPY ./tests /app/tests
|
||||
COPY --from=frontend-build /app/backend/app/frontend /app/backend/app/frontend
|
||||
|
||||
# Sync the project
|
||||
# Ref: https://docs.astral.sh/uv/guides/integration/docker/#intermediate-layers
|
||||
RUN --mount=type=cache,target=/root/.cache/uv \
|
||||
uv sync
|
||||
--mount=type=bind,source=uv.lock,target=uv.lock \
|
||||
--mount=type=bind,source=pyproject.toml,target=pyproject.toml \
|
||||
uv sync --frozen --package app
|
||||
|
||||
CMD ["fastapi", "run", "--workers", "4", "app/main.py"]
|
||||
WORKDIR /app/backend/
|
||||
|
||||
CMD ["fastapi", "run", "--workers", "4"]
|
||||
|
||||
+47
-74
@@ -5,27 +5,29 @@
|
||||
* [Docker](https://www.docker.com/).
|
||||
* [uv](https://docs.astral.sh/uv/) for Python package and environment management.
|
||||
|
||||
## Docker Compose
|
||||
## Local Development
|
||||
|
||||
Start the local development environment with Docker Compose following the guide in [../development.md](../development.md).
|
||||
Run the backend locally and connect it to PostgreSQL in Docker Compose.
|
||||
|
||||
## General Workflow
|
||||
From the project root, start PostgreSQL and Mailpit:
|
||||
|
||||
By default, the dependencies are managed with [uv](https://docs.astral.sh/uv/), go there and install it.
|
||||
```console
|
||||
$ docker compose up -d db mailpit
|
||||
```
|
||||
|
||||
From `./backend/` you can install all the dependencies with:
|
||||
Then, from `./backend/`, install the dependencies, prepare the database, and start the development server:
|
||||
|
||||
```console
|
||||
$ uv sync
|
||||
$ uv run bash scripts/prestart.sh
|
||||
$ uv run fastapi dev
|
||||
```
|
||||
|
||||
Then you can activate the virtual environment with:
|
||||
The API is available at `http://localhost:8000`, with automatic interactive docs at `http://localhost:8000/docs`.
|
||||
|
||||
```console
|
||||
$ source .venv/bin/activate
|
||||
```
|
||||
## General Workflow
|
||||
|
||||
Make sure your editor is using the correct Python virtual environment, with the interpreter at `backend/.venv/bin/python`.
|
||||
Run backend commands from `./backend/` with `uv run`. Make sure your editor uses the Python interpreter at `.venv/bin/python` in the project root.
|
||||
|
||||
Modify or add SQLModel models for data and SQL tables in `./backend/app/models.py`, API endpoints in `./backend/app/api/`, CRUD (Create, Read, Update, Delete) utils in `./backend/app/crud.py`.
|
||||
|
||||
@@ -35,73 +37,40 @@ There are already configurations in place to run the backend through the VS Code
|
||||
|
||||
The setup is also already configured so you can run the tests through the VS Code Python tests tab.
|
||||
|
||||
## Docker Compose Override
|
||||
## Full Stack with Docker Compose
|
||||
|
||||
During development, you can change Docker Compose settings that will only affect the local development environment in the file `docker-compose.override.yml`.
|
||||
|
||||
The changes to that file only affect the local development environment, not the production environment. So, you can add "temporary" changes that help the development workflow.
|
||||
|
||||
For example, the directory with the backend code is synchronized in the Docker container, copying the code you change live to the directory inside the container. That allows you to test your changes right away, without having to build the Docker image again. It should only be done during development, for production, you should build the Docker image with a recent version of the backend code. But during development, it allows you to iterate very fast.
|
||||
|
||||
There is also a command override that runs `fastapi run --reload` instead of the default `fastapi run`. It starts a single server process (instead of multiple, as would be for production) and reloads the process whenever the code changes. Have in mind that if you have a syntax error and save the Python file, it will break and exit, and the container will stop. After that, you can restart the container by fixing the error and running again:
|
||||
To run the backend and built frontend in Docker Compose:
|
||||
|
||||
```console
|
||||
$ docker compose run --rm backend bash scripts/prestart.sh
|
||||
$ docker compose watch
|
||||
```
|
||||
|
||||
There is also a commented out `command` override, you can uncomment it and comment the default one. It makes the backend container run a process that does "nothing", but keeps the container alive. That allows you to get inside your running container and execute commands inside, for example a Python interpreter to test installed dependencies, or start the development server that reloads when it detects changes.
|
||||
The application is available at `http://localhost:8000`.
|
||||
|
||||
To get inside the container with a `bash` session you can start the stack with:
|
||||
### Docker Compose Override
|
||||
|
||||
```console
|
||||
$ docker compose watch
|
||||
```
|
||||
The `compose.override.yml` file contains local settings for published ports, source synchronization, automatic image rebuilds, and backend reloads. Docker Compose applies it automatically when you run `docker compose` without an explicit file list.
|
||||
|
||||
and then in another terminal, `exec` inside the running container:
|
||||
To open a shell in the backend container:
|
||||
|
||||
```console
|
||||
$ docker compose exec backend bash
|
||||
```
|
||||
|
||||
You should see an output like:
|
||||
## Backend Tests
|
||||
|
||||
To test the backend from the `backend` directory, run:
|
||||
|
||||
```console
|
||||
root@7f2607af31c3:/app#
|
||||
$ uv run bash scripts/test.sh
|
||||
```
|
||||
|
||||
that means that you are in a `bash` session inside your container, as a `root` user, under the `/app` directory, this directory has another directory called "app" inside, that's where your code lives inside the container: `/app/app`.
|
||||
The tests run with Pytest. Modify existing tests or add new ones in `./backend/tests/`.
|
||||
|
||||
There you can use the `fastapi run --reload` command to run the debug live reloading server.
|
||||
If you use GitHub Actions, the tests will run automatically.
|
||||
|
||||
```console
|
||||
$ fastapi run --reload app/main.py
|
||||
```
|
||||
|
||||
...it will look like:
|
||||
|
||||
```console
|
||||
root@7f2607af31c3:/app# fastapi run --reload app/main.py
|
||||
```
|
||||
|
||||
and then hit enter. That runs the live reloading server that auto reloads when it detects code changes.
|
||||
|
||||
Nevertheless, if it doesn't detect a change but a syntax error, it will just stop with an error. But as the container is still alive and you are in a Bash session, you can quickly restart it after fixing the error, running the same command ("up arrow" and "Enter").
|
||||
|
||||
...this previous detail is what makes it useful to have the container alive doing nothing and then, in a Bash session, make it run the live reload server.
|
||||
|
||||
## Backend tests
|
||||
|
||||
To test the backend run:
|
||||
|
||||
```console
|
||||
$ bash ./scripts/test.sh
|
||||
```
|
||||
|
||||
The tests run with Pytest, modify and add tests to `./backend/tests/`.
|
||||
|
||||
If you use GitHub Actions the tests will run automatically.
|
||||
|
||||
### Test running stack
|
||||
### Test a Running Stack
|
||||
|
||||
If your stack is already up and you just want to run the tests, you can use:
|
||||
|
||||
@@ -109,7 +78,7 @@ If your stack is already up and you just want to run the tests, you can use:
|
||||
docker compose exec backend bash scripts/tests-start.sh
|
||||
```
|
||||
|
||||
That `/app/scripts/tests-start.sh` script just calls `pytest` after making sure that the rest of the stack is running. If you need to pass extra arguments to `pytest`, you can pass them to that command and they will be forwarded.
|
||||
The `/app/backend/scripts/tests-start.sh` script calls `pytest`. If you need to pass extra arguments to `pytest`, you can pass them to that command and they will be forwarded.
|
||||
|
||||
For example, to stop on first error:
|
||||
|
||||
@@ -119,26 +88,18 @@ docker compose exec backend bash scripts/tests-start.sh -x
|
||||
|
||||
### Test Coverage
|
||||
|
||||
When the tests are run, a file `htmlcov/index.html` is generated, you can open it in your browser to see the coverage of the tests.
|
||||
When the tests run, they generate `htmlcov/index.html`. Open it in your browser to inspect the test coverage.
|
||||
|
||||
## Migrations
|
||||
|
||||
As during local development your app directory is mounted as a volume inside the container, you can also run the migrations with `alembic` commands inside the container and the migration code will be in your app directory (instead of being only inside the container). So you can add it to your git repository.
|
||||
|
||||
Make sure you create a "revision" of your models and that you "upgrade" your database with that revision every time you change them. As this is what will update the tables in your database. Otherwise, your application will have errors.
|
||||
|
||||
* Start an interactive session in the backend container:
|
||||
|
||||
```console
|
||||
$ docker compose exec backend bash
|
||||
```
|
||||
Make sure you create a revision of your models and upgrade the database with that revision every time you change them. From the `backend` directory, use `uv` to run Alembic against the PostgreSQL container:
|
||||
|
||||
* Alembic is already configured to import your SQLModel models from `./backend/app/models.py`.
|
||||
|
||||
* After changing a model (for example, adding a column), inside the container, create a revision, e.g.:
|
||||
* After changing a model (for example, adding a column), create a revision:
|
||||
|
||||
```console
|
||||
$ alembic revision --autogenerate -m "Add column last_name to User model"
|
||||
$ uv run alembic revision --autogenerate -m "Add column last_name to User model"
|
||||
```
|
||||
|
||||
* Commit to the git repository the files generated in the alembic directory.
|
||||
@@ -146,7 +107,7 @@ $ alembic revision --autogenerate -m "Add column last_name to User model"
|
||||
* After creating the revision, run the migration in the database (this is what will actually change the database):
|
||||
|
||||
```console
|
||||
$ alembic upgrade head
|
||||
$ uv run alembic upgrade head
|
||||
```
|
||||
|
||||
If you don't want to use migrations at all, uncomment the lines in the file at `./backend/app/core/db.py` that end in:
|
||||
@@ -165,8 +126,20 @@ If you don't want to start with the default models and want to remove them / mod
|
||||
|
||||
## Email Templates
|
||||
|
||||
The email templates are in `./backend/app/email-templates/`. Here, there are two directories: `build` and `src`. The `src` directory contains the source files that are used to build the final email templates. The `build` directory contains the final email templates that are used by the application.
|
||||
The email templates are written with [React Email](https://react.email) in `./packages/react-email/`. The `emails` directory holds one component per email and the `ui` directory holds the shared components (layout, heading, button, link, callout).
|
||||
|
||||
Before continuing, ensure you have the [MJML extension](https://marketplace.visualstudio.com/items?itemName=attilabuti.vscode-mjml) installed in your VS Code.
|
||||
The rendered HTML in `./backend/app/email-templates/` is generated from those components. It is what the application sends and should not be edited by hand.
|
||||
|
||||
Once you have the MJML extension installed, you can create a new email template in the `src` directory. After creating the new email template and with the `.mjml` file open in your editor, open the command palette with `Ctrl+Shift+P` and search for `MJML: Export to HTML`. This will convert the `.mjml` file to a `.html` file and now you can save it in the build directory.
|
||||
To preview the emails while editing them, start the dev server from the root of the project:
|
||||
|
||||
```console
|
||||
$ bun run email:dev
|
||||
```
|
||||
|
||||
Values coming from the backend are declared as Jinja placeholders in the component props, for example `username = "{{ username }}"`. The context for each email is built in `generate_*_email()` in `./backend/app/utils.py`, so a new placeholder needs to be added there too.
|
||||
|
||||
Once you are done, regenerate the templates used by the application:
|
||||
|
||||
```console
|
||||
$ bun run email:export
|
||||
```
|
||||
|
||||
@@ -10,6 +10,7 @@ config = context.config
|
||||
|
||||
# Interpret the config file for Python logging.
|
||||
# This line sets up loggers basically.
|
||||
assert config.config_file_name is not None
|
||||
fileConfig(config.config_file_name)
|
||||
|
||||
# add your model's MetaData object here
|
||||
@@ -30,7 +31,7 @@ target_metadata = SQLModel.metadata
|
||||
|
||||
|
||||
def get_url():
|
||||
return str(settings.SQLALCHEMY_DATABASE_URI)
|
||||
return str(settings.DATABASE_URL)
|
||||
|
||||
|
||||
def run_migrations_offline():
|
||||
@@ -62,6 +63,7 @@ def run_migrations_online():
|
||||
|
||||
"""
|
||||
configuration = config.get_section(config.config_ini_section)
|
||||
assert configuration is not None
|
||||
configuration["sqlalchemy.url"] = get_url()
|
||||
connectable = engine_from_config(
|
||||
configuration,
|
||||
|
||||
@@ -29,7 +29,7 @@ def upgrade():
|
||||
|
||||
def downgrade():
|
||||
# ### commands auto generated by Alembic - please adjust! ###
|
||||
op.drop_constraint(None, 'item', type_='foreignkey')
|
||||
op.drop_constraint('item_owner_id_fkey', 'item', type_='foreignkey')
|
||||
op.create_foreign_key('item_owner_id_fkey', 'item', 'user', ['owner_id'], ['id'])
|
||||
op.alter_column('item', 'owner_id',
|
||||
existing_type=sa.UUID(),
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
"""Add created_at to User and Item
|
||||
|
||||
Revision ID: fe56fa70289e
|
||||
Revises: 1a31ce608336
|
||||
Create Date: 2026-01-23 15:50:37.171462
|
||||
|
||||
"""
|
||||
from alembic import op
|
||||
import sqlalchemy as sa
|
||||
import sqlmodel.sql.sqltypes
|
||||
|
||||
|
||||
# revision identifiers, used by Alembic.
|
||||
revision = 'fe56fa70289e'
|
||||
down_revision = '1a31ce608336'
|
||||
branch_labels = None
|
||||
depends_on = None
|
||||
|
||||
|
||||
def upgrade():
|
||||
# ### commands auto generated by Alembic - please adjust! ###
|
||||
op.add_column('item', sa.Column('created_at', sa.DateTime(timezone=True), nullable=True))
|
||||
op.add_column('user', sa.Column('created_at', sa.DateTime(timezone=True), nullable=True))
|
||||
# ### end Alembic commands ###
|
||||
|
||||
|
||||
def downgrade():
|
||||
# ### commands auto generated by Alembic - please adjust! ###
|
||||
op.drop_column('user', 'created_at')
|
||||
op.drop_column('item', 'created_at')
|
||||
# ### end Alembic commands ###
|
||||
@@ -18,7 +18,7 @@ reusable_oauth2 = OAuth2PasswordBearer(
|
||||
)
|
||||
|
||||
|
||||
def get_db() -> Generator[Session, None, None]:
|
||||
def get_db() -> Generator[Session]:
|
||||
with Session(engine) as session:
|
||||
yield session
|
||||
|
||||
@@ -33,7 +33,7 @@ def get_current_user(session: SessionDep, token: TokenDep) -> User:
|
||||
token, settings.SECRET_KEY, algorithms=[security.ALGORITHM]
|
||||
)
|
||||
token_data = TokenPayload(**payload)
|
||||
except (InvalidTokenError, ValidationError):
|
||||
except InvalidTokenError, ValidationError:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_403_FORBIDDEN,
|
||||
detail="Could not validate credentials",
|
||||
|
||||
@@ -10,5 +10,5 @@ api_router.include_router(utils.router)
|
||||
api_router.include_router(items.router)
|
||||
|
||||
|
||||
if settings.ENVIRONMENT == "local":
|
||||
if settings.FASTAPI_ENV == "development":
|
||||
api_router.include_router(private.router)
|
||||
|
||||
@@ -2,7 +2,7 @@ import uuid
|
||||
from typing import Any
|
||||
|
||||
from fastapi import APIRouter, HTTPException
|
||||
from sqlmodel import func, select
|
||||
from sqlmodel import col, func, select
|
||||
|
||||
from app.api.deps import CurrentUser, SessionDep
|
||||
from app.models import Item, ItemCreate, ItemPublic, ItemsPublic, ItemUpdate, Message
|
||||
@@ -21,7 +21,9 @@ def read_items(
|
||||
if current_user.is_superuser:
|
||||
count_statement = select(func.count()).select_from(Item)
|
||||
count = session.exec(count_statement).one()
|
||||
statement = select(Item).offset(skip).limit(limit)
|
||||
statement = (
|
||||
select(Item).order_by(col(Item.created_at).desc()).offset(skip).limit(limit)
|
||||
)
|
||||
items = session.exec(statement).all()
|
||||
else:
|
||||
count_statement = (
|
||||
@@ -33,12 +35,14 @@ def read_items(
|
||||
statement = (
|
||||
select(Item)
|
||||
.where(Item.owner_id == current_user.id)
|
||||
.order_by(col(Item.created_at).desc())
|
||||
.offset(skip)
|
||||
.limit(limit)
|
||||
)
|
||||
items = session.exec(statement).all()
|
||||
|
||||
return ItemsPublic(data=items, count=count)
|
||||
items_public = [ItemPublic.model_validate(item) for item in items]
|
||||
return ItemsPublic(data=items_public, count=count)
|
||||
|
||||
|
||||
@router.get("/{id}", response_model=ItemPublic)
|
||||
@@ -50,7 +54,7 @@ def read_item(session: SessionDep, current_user: CurrentUser, id: uuid.UUID) ->
|
||||
if not item:
|
||||
raise HTTPException(status_code=404, detail="Item not found")
|
||||
if not current_user.is_superuser and (item.owner_id != current_user.id):
|
||||
raise HTTPException(status_code=400, detail="Not enough permissions")
|
||||
raise HTTPException(status_code=403, detail="Not enough permissions")
|
||||
return item
|
||||
|
||||
|
||||
@@ -83,7 +87,7 @@ def update_item(
|
||||
if not item:
|
||||
raise HTTPException(status_code=404, detail="Item not found")
|
||||
if not current_user.is_superuser and (item.owner_id != current_user.id):
|
||||
raise HTTPException(status_code=400, detail="Not enough permissions")
|
||||
raise HTTPException(status_code=403, detail="Not enough permissions")
|
||||
update_dict = item_in.model_dump(exclude_unset=True)
|
||||
item.sqlmodel_update(update_dict)
|
||||
session.add(item)
|
||||
@@ -103,7 +107,7 @@ def delete_item(
|
||||
if not item:
|
||||
raise HTTPException(status_code=404, detail="Item not found")
|
||||
if not current_user.is_superuser and (item.owner_id != current_user.id):
|
||||
raise HTTPException(status_code=400, detail="Not enough permissions")
|
||||
raise HTTPException(status_code=403, detail="Not enough permissions")
|
||||
session.delete(item)
|
||||
session.commit()
|
||||
return Message(message="Item deleted successfully")
|
||||
|
||||
@@ -9,8 +9,7 @@ from app import crud
|
||||
from app.api.deps import CurrentUser, SessionDep, get_current_active_superuser
|
||||
from app.core import security
|
||||
from app.core.config import settings
|
||||
from app.core.security import get_password_hash
|
||||
from app.models import Message, NewPassword, Token, UserPublic
|
||||
from app.models import Message, NewPassword, Token, UserPublic, UserUpdate
|
||||
from app.utils import (
|
||||
generate_password_reset_token,
|
||||
generate_reset_password_email,
|
||||
@@ -58,21 +57,21 @@ def recover_password(email: str, session: SessionDep) -> Message:
|
||||
"""
|
||||
user = crud.get_user_by_email(session=session, email=email)
|
||||
|
||||
if not user:
|
||||
raise HTTPException(
|
||||
status_code=404,
|
||||
detail="The user with this email does not exist in the system.",
|
||||
# Always return the same response to prevent email enumeration attacks
|
||||
# Only send email if user actually exists
|
||||
if user:
|
||||
password_reset_token = generate_password_reset_token(email=email)
|
||||
email_data = generate_reset_password_email(
|
||||
email_to=user.email, email=email, token=password_reset_token
|
||||
)
|
||||
password_reset_token = generate_password_reset_token(email=email)
|
||||
email_data = generate_reset_password_email(
|
||||
email_to=user.email, email=email, token=password_reset_token
|
||||
send_email(
|
||||
email_to=user.email,
|
||||
subject=email_data.subject,
|
||||
html_content=email_data.html_content,
|
||||
)
|
||||
return Message(
|
||||
message="If that email is registered, we sent a password recovery link"
|
||||
)
|
||||
send_email(
|
||||
email_to=user.email,
|
||||
subject=email_data.subject,
|
||||
html_content=email_data.html_content,
|
||||
)
|
||||
return Message(message="Password recovery email sent")
|
||||
|
||||
|
||||
@router.post("/reset-password/")
|
||||
@@ -85,16 +84,16 @@ def reset_password(session: SessionDep, body: NewPassword) -> Message:
|
||||
raise HTTPException(status_code=400, detail="Invalid token")
|
||||
user = crud.get_user_by_email(session=session, email=email)
|
||||
if not user:
|
||||
raise HTTPException(
|
||||
status_code=404,
|
||||
detail="The user with this email does not exist in the system.",
|
||||
)
|
||||
# Don't reveal that the user doesn't exist - use same error as invalid token
|
||||
raise HTTPException(status_code=400, detail="Invalid token")
|
||||
elif not user.is_active:
|
||||
raise HTTPException(status_code=400, detail="Inactive user")
|
||||
hashed_password = get_password_hash(password=body.new_password)
|
||||
user.hashed_password = hashed_password
|
||||
session.add(user)
|
||||
session.commit()
|
||||
user_in_update = UserUpdate(password=body.new_password)
|
||||
crud.update_user(
|
||||
session=session,
|
||||
db_user=user,
|
||||
user_in=user_in_update,
|
||||
)
|
||||
return Message(message="Password updated successfully")
|
||||
|
||||
|
||||
|
||||
@@ -42,10 +42,13 @@ def read_users(session: SessionDep, skip: int = 0, limit: int = 100) -> Any:
|
||||
count_statement = select(func.count()).select_from(User)
|
||||
count = session.exec(count_statement).one()
|
||||
|
||||
statement = select(User).offset(skip).limit(limit)
|
||||
statement = (
|
||||
select(User).order_by(col(User.created_at).desc()).offset(skip).limit(limit)
|
||||
)
|
||||
users = session.exec(statement).all()
|
||||
|
||||
return UsersPublic(data=users, count=count)
|
||||
users_public = [UserPublic.model_validate(user) for user in users]
|
||||
return UsersPublic(data=users_public, count=count)
|
||||
|
||||
|
||||
@router.post(
|
||||
@@ -104,7 +107,8 @@ def update_password_me(
|
||||
"""
|
||||
Update own password.
|
||||
"""
|
||||
if not verify_password(body.current_password, current_user.hashed_password):
|
||||
verified, _ = verify_password(body.current_password, current_user.hashed_password)
|
||||
if not verified:
|
||||
raise HTTPException(status_code=400, detail="Incorrect password")
|
||||
if body.current_password == body.new_password:
|
||||
raise HTTPException(
|
||||
@@ -170,6 +174,8 @@ def read_user_by_id(
|
||||
status_code=403,
|
||||
detail="The user doesn't have enough privileges",
|
||||
)
|
||||
if user is None:
|
||||
raise HTTPException(status_code=404, detail="User not found")
|
||||
return user
|
||||
|
||||
|
||||
@@ -220,7 +226,7 @@ def delete_user(
|
||||
status_code=403, detail="Super users are not allowed to delete themselves"
|
||||
)
|
||||
statement = delete(Item).where(col(Item.owner_id) == user_id)
|
||||
session.exec(statement) # type: ignore
|
||||
session.exec(statement)
|
||||
session.delete(user)
|
||||
session.commit()
|
||||
return Message(message="User deleted successfully")
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
import logging
|
||||
|
||||
from sqlalchemy import Engine
|
||||
from sqlmodel import Session, select
|
||||
from tenacity import after_log, before_log, retry, stop_after_attempt, wait_fixed
|
||||
|
||||
from app.core.db import engine
|
||||
|
||||
logging.basicConfig(level=logging.INFO)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
max_tries = 60 * 5 # 5 minutes
|
||||
wait_seconds = 1
|
||||
|
||||
|
||||
@retry(
|
||||
stop=stop_after_attempt(max_tries),
|
||||
wait=wait_fixed(wait_seconds),
|
||||
before=before_log(logger, logging.INFO),
|
||||
after=after_log(logger, logging.WARN),
|
||||
)
|
||||
def init(db_engine: Engine) -> None:
|
||||
try:
|
||||
with Session(db_engine) as session:
|
||||
# Try to create session to check if DB is awake
|
||||
session.exec(select(1))
|
||||
except Exception as e:
|
||||
logger.error(e)
|
||||
raise e
|
||||
|
||||
|
||||
def main() -> None:
|
||||
logger.info("Initializing service")
|
||||
init(engine)
|
||||
logger.info("Service finished initializing")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
+17
-45
@@ -1,26 +1,15 @@
|
||||
import secrets
|
||||
import warnings
|
||||
from typing import Annotated, Any, Literal
|
||||
from typing import Literal, Self
|
||||
|
||||
from pydantic import (
|
||||
AnyUrl,
|
||||
BeforeValidator,
|
||||
EmailStr,
|
||||
HttpUrl,
|
||||
PostgresDsn,
|
||||
computed_field,
|
||||
field_validator,
|
||||
model_validator,
|
||||
)
|
||||
from pydantic_settings import BaseSettings, SettingsConfigDict
|
||||
from typing_extensions import Self
|
||||
|
||||
|
||||
def parse_cors(v: Any) -> list[str] | str:
|
||||
if isinstance(v, str) and not v.startswith("["):
|
||||
return [i.strip() for i in v.split(",") if i.strip()]
|
||||
elif isinstance(v, list | str):
|
||||
return v
|
||||
raise ValueError(v)
|
||||
|
||||
|
||||
class Settings(BaseSettings):
|
||||
@@ -31,42 +20,24 @@ class Settings(BaseSettings):
|
||||
extra="ignore",
|
||||
)
|
||||
API_V1_STR: str = "/api/v1"
|
||||
SECRET_KEY: str = secrets.token_urlsafe(32)
|
||||
SECRET_KEY: str
|
||||
# 60 minutes * 24 hours * 8 days = 8 days
|
||||
ACCESS_TOKEN_EXPIRE_MINUTES: int = 60 * 24 * 8
|
||||
FRONTEND_HOST: str = "http://localhost:5173"
|
||||
ENVIRONMENT: Literal["local", "staging", "production"] = "local"
|
||||
|
||||
BACKEND_CORS_ORIGINS: Annotated[
|
||||
list[AnyUrl] | str, BeforeValidator(parse_cors)
|
||||
] = []
|
||||
|
||||
@computed_field # type: ignore[prop-decorator]
|
||||
@property
|
||||
def all_cors_origins(self) -> list[str]:
|
||||
return [str(origin).rstrip("/") for origin in self.BACKEND_CORS_ORIGINS] + [
|
||||
self.FRONTEND_HOST
|
||||
]
|
||||
FASTAPI_ENV: Literal["development"] | None = None
|
||||
|
||||
PROJECT_NAME: str
|
||||
SENTRY_DSN: HttpUrl | None = None
|
||||
POSTGRES_SERVER: str
|
||||
POSTGRES_PORT: int = 5432
|
||||
POSTGRES_USER: str
|
||||
POSTGRES_PASSWORD: str = ""
|
||||
POSTGRES_DB: str = ""
|
||||
DATABASE_URL: PostgresDsn
|
||||
|
||||
@computed_field # type: ignore[prop-decorator]
|
||||
@property
|
||||
def SQLALCHEMY_DATABASE_URI(self) -> PostgresDsn:
|
||||
return PostgresDsn.build(
|
||||
scheme="postgresql+psycopg",
|
||||
username=self.POSTGRES_USER,
|
||||
password=self.POSTGRES_PASSWORD,
|
||||
host=self.POSTGRES_SERVER,
|
||||
port=self.POSTGRES_PORT,
|
||||
path=self.POSTGRES_DB,
|
||||
)
|
||||
@field_validator("DATABASE_URL", mode="before")
|
||||
@classmethod
|
||||
def _use_psycopg_driver(cls, value: str | PostgresDsn) -> str:
|
||||
database_url = str(value)
|
||||
for scheme in ("postgres://", "postgresql://"):
|
||||
if database_url.startswith(scheme):
|
||||
return database_url.replace(scheme, "postgresql+psycopg://", 1)
|
||||
return database_url
|
||||
|
||||
SMTP_TLS: bool = True
|
||||
SMTP_SSL: bool = False
|
||||
@@ -100,7 +71,7 @@ class Settings(BaseSettings):
|
||||
f'The value of {var_name} is "changethis", '
|
||||
"for security, please change it, at least for deployments."
|
||||
)
|
||||
if self.ENVIRONMENT == "local":
|
||||
if self.FASTAPI_ENV == "development":
|
||||
warnings.warn(message, stacklevel=1)
|
||||
else:
|
||||
raise ValueError(message)
|
||||
@@ -108,7 +79,8 @@ class Settings(BaseSettings):
|
||||
@model_validator(mode="after")
|
||||
def _enforce_non_default_secrets(self) -> Self:
|
||||
self._check_default_secret("SECRET_KEY", self.SECRET_KEY)
|
||||
self._check_default_secret("POSTGRES_PASSWORD", self.POSTGRES_PASSWORD)
|
||||
for host in self.DATABASE_URL.hosts():
|
||||
self._check_default_secret("DATABASE_URL password", host["password"])
|
||||
self._check_default_secret(
|
||||
"FIRST_SUPERUSER_PASSWORD", self.FIRST_SUPERUSER_PASSWORD
|
||||
)
|
||||
@@ -116,4 +88,4 @@ class Settings(BaseSettings):
|
||||
return self
|
||||
|
||||
|
||||
settings = Settings() # type: ignore
|
||||
settings = Settings() # type: ignore # ty: ignore[unused-ignore-comment]
|
||||
|
||||
@@ -4,7 +4,7 @@ from app import crud
|
||||
from app.core.config import settings
|
||||
from app.models import User, UserCreate
|
||||
|
||||
engine = create_engine(str(settings.SQLALCHEMY_DATABASE_URI))
|
||||
engine = create_engine(str(settings.DATABASE_URL), pool_pre_ping=True)
|
||||
|
||||
|
||||
# make sure all SQLModel models are imported (app.models) before initializing DB
|
||||
|
||||
@@ -1,27 +1,36 @@
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from datetime import UTC, datetime, timedelta
|
||||
from typing import Any
|
||||
|
||||
import jwt
|
||||
from passlib.context import CryptContext
|
||||
from pwdlib import PasswordHash
|
||||
from pwdlib.hashers.argon2 import Argon2Hasher
|
||||
from pwdlib.hashers.bcrypt import BcryptHasher
|
||||
|
||||
from app.core.config import settings
|
||||
|
||||
pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
|
||||
password_hash = PasswordHash(
|
||||
(
|
||||
Argon2Hasher(),
|
||||
BcryptHasher(),
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
ALGORITHM = "HS256"
|
||||
|
||||
|
||||
def create_access_token(subject: str | Any, expires_delta: timedelta) -> str:
|
||||
expire = datetime.now(timezone.utc) + expires_delta
|
||||
expire = datetime.now(UTC) + expires_delta
|
||||
to_encode = {"exp": expire, "sub": str(subject)}
|
||||
encoded_jwt = jwt.encode(to_encode, settings.SECRET_KEY, algorithm=ALGORITHM)
|
||||
return encoded_jwt
|
||||
|
||||
|
||||
def verify_password(plain_password: str, hashed_password: str) -> bool:
|
||||
return pwd_context.verify(plain_password, hashed_password)
|
||||
def verify_password(
|
||||
plain_password: str, hashed_password: str
|
||||
) -> tuple[bool, str | None]:
|
||||
return password_hash.verify_and_update(plain_password, hashed_password)
|
||||
|
||||
|
||||
def get_password_hash(password: str) -> str:
|
||||
return pwd_context.hash(password)
|
||||
return password_hash.hash(password)
|
||||
|
||||
+15
-1
@@ -37,12 +37,26 @@ def get_user_by_email(*, session: Session, email: str) -> User | None:
|
||||
return session_user
|
||||
|
||||
|
||||
# Dummy hash to use for timing attack prevention when user is not found
|
||||
# This is an Argon2 hash of a random password, used to ensure constant-time comparison
|
||||
DUMMY_HASH = "$argon2id$v=19$m=65536,t=3,p=4$MjQyZWE1MzBjYjJlZTI0Yw$YTU4NGM5ZTZmYjE2NzZlZjY0ZWY3ZGRkY2U2OWFjNjk"
|
||||
|
||||
|
||||
def authenticate(*, session: Session, email: str, password: str) -> User | None:
|
||||
db_user = get_user_by_email(session=session, email=email)
|
||||
if not db_user:
|
||||
# Prevent timing attacks by running password verification even when user doesn't exist
|
||||
# This ensures the response time is similar whether or not the email exists
|
||||
verify_password(password, DUMMY_HASH)
|
||||
return None
|
||||
if not verify_password(password, db_user.hashed_password):
|
||||
verified, updated_password_hash = verify_password(password, db_user.hashed_password)
|
||||
if not verified:
|
||||
return None
|
||||
if updated_password_hash:
|
||||
db_user.hashed_password = updated_password_hash
|
||||
session.add(db_user)
|
||||
session.commit()
|
||||
session.refresh(db_user)
|
||||
return db_user
|
||||
|
||||
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
<!doctype html><html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office"><head><title></title><!--[if !mso]><!-- --><meta http-equiv="X-UA-Compatible" content="IE=edge"><!--<![endif]--><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width,initial-scale=1"><style type="text/css">#outlook a { padding:0; }
|
||||
.ReadMsgBody { width:100%; }
|
||||
.ExternalClass { width:100%; }
|
||||
.ExternalClass * { line-height:100%; }
|
||||
body { margin:0;padding:0;-webkit-text-size-adjust:100%;-ms-text-size-adjust:100%; }
|
||||
table, td { border-collapse:collapse;mso-table-lspace:0pt;mso-table-rspace:0pt; }
|
||||
img { border:0;height:auto;line-height:100%; outline:none;text-decoration:none;-ms-interpolation-mode:bicubic; }
|
||||
p { display:block;margin:13px 0; }</style><!--[if !mso]><!--><style type="text/css">@media only screen and (max-width:480px) {
|
||||
@-ms-viewport { width:320px; }
|
||||
@viewport { width:320px; }
|
||||
}</style><!--<![endif]--><!--[if mso]>
|
||||
<xml>
|
||||
<o:OfficeDocumentSettings>
|
||||
<o:AllowPNG/>
|
||||
<o:PixelsPerInch>96</o:PixelsPerInch>
|
||||
</o:OfficeDocumentSettings>
|
||||
</xml>
|
||||
<![endif]--><!--[if lte mso 11]>
|
||||
<style type="text/css">
|
||||
.outlook-group-fix { width:100% !important; }
|
||||
</style>
|
||||
<![endif]--><!--[if !mso]><!--><link href="https://fonts.googleapis.com/css?family=Ubuntu:300,400,500,700" rel="stylesheet" type="text/css"><style type="text/css">@import url(https://fonts.googleapis.com/css?family=Ubuntu:300,400,500,700);</style><!--<![endif]--><style type="text/css">@media only screen and (min-width:480px) {
|
||||
.mj-column-per-100 { width:100% !important; max-width: 100%; }
|
||||
}</style><style type="text/css"></style></head><body style="background-color:#fafbfc;"><div style="background-color:#fafbfc;"><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" class="" style="width:600px;" width="600" ><tr><td style="line-height:0px;font-size:0px;mso-line-height-rule:exactly;"><![endif]--><div style="background:#ffffff;background-color:#ffffff;Margin:0px auto;max-width:600px;"><table align="center" border="0" cellpadding="0" cellspacing="0" role="presentation" style="background:#ffffff;background-color:#ffffff;width:100%;"><tbody><tr><td style="direction:ltr;font-size:0px;padding:40px 20px;text-align:center;vertical-align:top;"><!--[if mso | IE]><table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td class="" style="vertical-align:middle;width:560px;" ><![endif]--><div class="mj-column-per-100 outlook-group-fix" style="font-size:13px;text-align:left;direction:ltr;display:inline-block;vertical-align:middle;width:100%;"><table border="0" cellpadding="0" cellspacing="0" role="presentation" style="vertical-align:middle;" width="100%"><tr><td align="center" style="font-size:0px;padding:35px;word-break:break-word;"><div style="font-family:Ubuntu, Helvetica, Arial, sans-serif;font-size:20px;line-height:1;text-align:center;color:#333333;">{{ project_name }} - New Account</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;"><span>Welcome to your new account!</span></div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">Here are your account details:</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">Username: {{ username }}</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">Password: {{ password }}</div></td></tr><tr><td align="center" vertical-align="middle" style="font-size:0px;padding:15px 30px;word-break:break-word;"><table border="0" cellpadding="0" cellspacing="0" role="presentation" style="border-collapse:separate;line-height:100%;"><tr><td align="center" bgcolor="#009688" role="presentation" style="border:none;border-radius:8px;cursor:auto;padding:10px 25px;background:#009688;" valign="middle"><a href="{{ link }}" style="background:#009688;color:#ffffff;font-family:Ubuntu, Helvetica, Arial, sans-serif;font-size:18px;font-weight:normal;line-height:120%;Margin:0;text-decoration:none;text-transform:none;" target="_blank">Go to Dashboard</a></td></tr></table></td></tr><tr><td style="font-size:0px;padding:10px 25px;word-break:break-word;"><p style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:100%;"></p><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:510px;" role="presentation" width="510px" ><tr><td style="height:0;line-height:0;">
|
||||
</td></tr></table><![endif]--></td></tr></table></div><!--[if mso | IE]></td></tr></table><![endif]--></td></tr></tbody></table></div><!--[if mso | IE]></td></tr></table><![endif]--></div></body></html>
|
||||
@@ -1,25 +0,0 @@
|
||||
<!doctype html><html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office"><head><title></title><!--[if !mso]><!-- --><meta http-equiv="X-UA-Compatible" content="IE=edge"><!--<![endif]--><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width,initial-scale=1"><style type="text/css">#outlook a { padding:0; }
|
||||
.ReadMsgBody { width:100%; }
|
||||
.ExternalClass { width:100%; }
|
||||
.ExternalClass * { line-height:100%; }
|
||||
body { margin:0;padding:0;-webkit-text-size-adjust:100%;-ms-text-size-adjust:100%; }
|
||||
table, td { border-collapse:collapse;mso-table-lspace:0pt;mso-table-rspace:0pt; }
|
||||
img { border:0;height:auto;line-height:100%; outline:none;text-decoration:none;-ms-interpolation-mode:bicubic; }
|
||||
p { display:block;margin:13px 0; }</style><!--[if !mso]><!--><style type="text/css">@media only screen and (max-width:480px) {
|
||||
@-ms-viewport { width:320px; }
|
||||
@viewport { width:320px; }
|
||||
}</style><!--<![endif]--><!--[if mso]>
|
||||
<xml>
|
||||
<o:OfficeDocumentSettings>
|
||||
<o:AllowPNG/>
|
||||
<o:PixelsPerInch>96</o:PixelsPerInch>
|
||||
</o:OfficeDocumentSettings>
|
||||
</xml>
|
||||
<![endif]--><!--[if lte mso 11]>
|
||||
<style type="text/css">
|
||||
.outlook-group-fix { width:100% !important; }
|
||||
</style>
|
||||
<![endif]--><!--[if !mso]><!--><link href="https://fonts.googleapis.com/css?family=Ubuntu:300,400,500,700" rel="stylesheet" type="text/css"><style type="text/css">@import url(https://fonts.googleapis.com/css?family=Ubuntu:300,400,500,700);</style><!--<![endif]--><style type="text/css">@media only screen and (min-width:480px) {
|
||||
.mj-column-per-100 { width:100% !important; max-width: 100%; }
|
||||
}</style><style type="text/css"></style></head><body style="background-color:#fafbfc;"><div style="background-color:#fafbfc;"><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" class="" style="width:600px;" width="600" ><tr><td style="line-height:0px;font-size:0px;mso-line-height-rule:exactly;"><![endif]--><div style="background:#ffffff;background-color:#ffffff;Margin:0px auto;max-width:600px;"><table align="center" border="0" cellpadding="0" cellspacing="0" role="presentation" style="background:#ffffff;background-color:#ffffff;width:100%;"><tbody><tr><td style="direction:ltr;font-size:0px;padding:40px 20px;text-align:center;vertical-align:top;"><!--[if mso | IE]><table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td class="" style="vertical-align:middle;width:560px;" ><![endif]--><div class="mj-column-per-100 outlook-group-fix" style="font-size:13px;text-align:left;direction:ltr;display:inline-block;vertical-align:middle;width:100%;"><table border="0" cellpadding="0" cellspacing="0" role="presentation" style="vertical-align:middle;" width="100%"><tr><td align="center" style="font-size:0px;padding:35px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:20px;line-height:1;text-align:center;color:#333333;">{{ project_name }} - Password Recovery</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;"><span>Hello {{ username }}</span></div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">We've received a request to reset your password. You can do it by clicking the button below:</div></td></tr><tr><td align="center" vertical-align="middle" style="font-size:0px;padding:15px 30px;word-break:break-word;"><table border="0" cellpadding="0" cellspacing="0" role="presentation" style="border-collapse:separate;line-height:100%;"><tr><td align="center" bgcolor="#009688" role="presentation" style="border:none;border-radius:8px;cursor:auto;padding:10px 25px;background:#009688;" valign="middle"><a href="{{ link }}" style="background:#009688;color:#ffffff;font-family:Ubuntu, Helvetica, Arial, sans-serif;font-size:18px;font-weight:normal;line-height:120%;Margin:0;text-decoration:none;text-transform:none;" target="_blank">Reset password</a></td></tr></table></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">Or copy and paste the following link into your browser:</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;"><a href="{{ link }}">{{ link }}</a></div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;">This password will expire in {{ valid_hours }} hours.</div></td></tr><tr><td style="font-size:0px;padding:10px 25px;word-break:break-word;"><p style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:100%;"></p><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:510px;" role="presentation" width="510px" ><tr><td style="height:0;line-height:0;">
|
||||
</td></tr></table><![endif]--></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:14px;line-height:1;text-align:center;color:#555555;">If you didn't request a password recovery you can disregard this email.</div></td></tr></table></div><!--[if mso | IE]></td></tr></table><![endif]--></td></tr></tbody></table></div><!--[if mso | IE]></td></tr></table><![endif]--></div></body></html>
|
||||
@@ -1,25 +0,0 @@
|
||||
<!doctype html><html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office"><head><title></title><!--[if !mso]><!-- --><meta http-equiv="X-UA-Compatible" content="IE=edge"><!--<![endif]--><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width,initial-scale=1"><style type="text/css">#outlook a { padding:0; }
|
||||
.ReadMsgBody { width:100%; }
|
||||
.ExternalClass { width:100%; }
|
||||
.ExternalClass * { line-height:100%; }
|
||||
body { margin:0;padding:0;-webkit-text-size-adjust:100%;-ms-text-size-adjust:100%; }
|
||||
table, td { border-collapse:collapse;mso-table-lspace:0pt;mso-table-rspace:0pt; }
|
||||
img { border:0;height:auto;line-height:100%; outline:none;text-decoration:none;-ms-interpolation-mode:bicubic; }
|
||||
p { display:block;margin:13px 0; }</style><!--[if !mso]><!--><style type="text/css">@media only screen and (max-width:480px) {
|
||||
@-ms-viewport { width:320px; }
|
||||
@viewport { width:320px; }
|
||||
}</style><!--<![endif]--><!--[if mso]>
|
||||
<xml>
|
||||
<o:OfficeDocumentSettings>
|
||||
<o:AllowPNG/>
|
||||
<o:PixelsPerInch>96</o:PixelsPerInch>
|
||||
</o:OfficeDocumentSettings>
|
||||
</xml>
|
||||
<![endif]--><!--[if lte mso 11]>
|
||||
<style type="text/css">
|
||||
.outlook-group-fix { width:100% !important; }
|
||||
</style>
|
||||
<![endif]--><style type="text/css">@media only screen and (min-width:480px) {
|
||||
.mj-column-per-100 { width:100% !important; max-width: 100%; }
|
||||
}</style><style type="text/css"></style></head><body style="background-color:#fafbfc;"><div style="background-color:#fafbfc;"><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" class="" style="width:600px;" width="600" ><tr><td style="line-height:0px;font-size:0px;mso-line-height-rule:exactly;"><![endif]--><div style="background:#ffffff;background-color:#ffffff;Margin:0px auto;max-width:600px;"><table align="center" border="0" cellpadding="0" cellspacing="0" role="presentation" style="background:#ffffff;background-color:#ffffff;width:100%;"><tbody><tr><td style="direction:ltr;font-size:0px;padding:40px 20px;text-align:center;vertical-align:top;"><!--[if mso | IE]><table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td class="" style="vertical-align:middle;width:560px;" ><![endif]--><div class="mj-column-per-100 outlook-group-fix" style="font-size:13px;text-align:left;direction:ltr;display:inline-block;vertical-align:middle;width:100%;"><table border="0" cellpadding="0" cellspacing="0" role="presentation" style="vertical-align:middle;" width="100%"><tr><td align="center" style="font-size:0px;padding:35px;word-break:break-word;"><div style="font-family:Arial, Helvetica, sans-serif;font-size:20px;line-height:1;text-align:center;color:#333333;">{{ project_name }}</div></td></tr><tr><td align="center" style="font-size:0px;padding:10px 25px;padding-right:25px;padding-left:25px;word-break:break-word;"><div style="font-family:, sans-serif;font-size:16px;line-height:1;text-align:center;color:#555555;"><span>Test email for: {{ email }}</span></div></td></tr><tr><td style="font-size:0px;padding:10px 25px;word-break:break-word;"><p style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:100%;"></p><!--[if mso | IE]><table align="center" border="0" cellpadding="0" cellspacing="0" style="border-top:solid 2px #cccccc;font-size:1;margin:0px auto;width:510px;" role="presentation" width="510px" ><tr><td style="height:0;line-height:0;">
|
||||
</td></tr></table><![endif]--></td></tr></table></div><!--[if mso | IE]></td></tr></table><![endif]--></td></tr></tbody></table></div><!--[if mso | IE]></td></tr></table><![endif]--></div></body></html>
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -1,15 +0,0 @@
|
||||
<mjml>
|
||||
<mj-body background-color="#fafbfc">
|
||||
<mj-section background-color="#fff" padding="40px 20px">
|
||||
<mj-column vertical-align="middle" width="100%">
|
||||
<mj-text align="center" padding="35px" font-size="20px" color="#333">{{ project_name }} - New Account</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555"><span>Welcome to your new account!</span></mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">Here are your account details:</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">Username: {{ username }}</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">Password: {{ password }}</mj-text>
|
||||
<mj-button align="center" font-size="18px" background-color="#009688" border-radius="8px" color="#fff" href="{{ link }}" padding="15px 30px">Go to Dashboard</mj-button>
|
||||
<mj-divider border-color="#ccc" border-width="2px"></mj-divider>
|
||||
</mj-column>
|
||||
</mj-section>
|
||||
</mj-body>
|
||||
</mjml>
|
||||
@@ -1,17 +0,0 @@
|
||||
<mjml>
|
||||
<mj-body background-color="#fafbfc">
|
||||
<mj-section background-color="#fff" padding="40px 20px">
|
||||
<mj-column vertical-align="middle" width="100%">
|
||||
<mj-text align="center" padding="35px" font-size="20px" font-family="Arial, Helvetica, sans-serif" color="#333">{{ project_name }} - Password Recovery</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555"><span>Hello {{ username }}</span></mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">We've received a request to reset your password. You can do it by clicking the button below:</mj-text>
|
||||
<mj-button align="center" font-size="18px" background-color="#009688" border-radius="8px" color="#fff" href="{{ link }}" padding="15px 30px">Reset password</mj-button>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">Or copy and paste the following link into your browser:</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555"><a href="{{ link }}">{{ link }}</a></mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">This password will expire in {{ valid_hours }} hours.</mj-text>
|
||||
<mj-divider border-color="#ccc" border-width="2px"></mj-divider>
|
||||
<mj-text align="center" font-size="14px" padding-left="25px" padding-right="25px" font-family="Arial, Helvetica, sans-serif" color="#555">If you didn't request a password recovery you can disregard this email.</mj-text>
|
||||
</mj-column>
|
||||
</mj-section>
|
||||
</mj-body>
|
||||
</mjml>
|
||||
@@ -1,11 +0,0 @@
|
||||
<mjml>
|
||||
<mj-body background-color="#fafbfc">
|
||||
<mj-section background-color="#fff" padding="40px 20px">
|
||||
<mj-column vertical-align="middle" width="100%">
|
||||
<mj-text align="center" padding="35px" font-size="20px" font-family="Arial, Helvetica, sans-serif" color="#333">{{ project_name }}</mj-text>
|
||||
<mj-text align="center" font-size="16px" padding-left="25px" padding-right="25px" font-family=", sans-serif" color="#555"><span>Test email for: {{ email }}</span></mj-text>
|
||||
<mj-divider border-color="#ccc" border-width="2px"></mj-divider>
|
||||
</mj-column>
|
||||
</mj-section>
|
||||
</mj-body>
|
||||
</mjml>
|
||||
File diff suppressed because one or more lines are too long
+13
-10
@@ -1,3 +1,5 @@
|
||||
from pathlib import Path
|
||||
|
||||
import sentry_sdk
|
||||
from fastapi import FastAPI
|
||||
from fastapi.routing import APIRoute
|
||||
@@ -6,12 +8,14 @@ from starlette.middleware.cors import CORSMiddleware
|
||||
from app.api.main import api_router
|
||||
from app.core.config import settings
|
||||
|
||||
FRONTEND_DIR = Path(__file__).parent / "frontend"
|
||||
|
||||
|
||||
def custom_generate_unique_id(route: APIRoute) -> str:
|
||||
return f"{route.tags[0]}-{route.name}"
|
||||
|
||||
|
||||
if settings.SENTRY_DSN and settings.ENVIRONMENT != "local":
|
||||
if settings.SENTRY_DSN and settings.FASTAPI_ENV != "development":
|
||||
sentry_sdk.init(dsn=str(settings.SENTRY_DSN), enable_tracing=True)
|
||||
|
||||
app = FastAPI(
|
||||
@@ -20,14 +24,13 @@ app = FastAPI(
|
||||
generate_unique_id_function=custom_generate_unique_id,
|
||||
)
|
||||
|
||||
# Set all CORS enabled origins
|
||||
if settings.all_cors_origins:
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=settings.all_cors_origins,
|
||||
allow_credentials=True,
|
||||
allow_methods=["*"],
|
||||
allow_headers=["*"],
|
||||
)
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=[settings.FRONTEND_HOST],
|
||||
allow_credentials=True,
|
||||
allow_methods=["*"],
|
||||
allow_headers=["*"],
|
||||
)
|
||||
|
||||
app.include_router(api_router, prefix=settings.API_V1_STR)
|
||||
app.frontend("/", directory=FRONTEND_DIR)
|
||||
|
||||
+25
-5
@@ -1,9 +1,15 @@
|
||||
import uuid
|
||||
from datetime import UTC, datetime
|
||||
|
||||
from pydantic import EmailStr
|
||||
from sqlalchemy import DateTime
|
||||
from sqlmodel import Field, Relationship, SQLModel
|
||||
|
||||
|
||||
def get_datetime_utc() -> datetime:
|
||||
return datetime.now(UTC)
|
||||
|
||||
|
||||
# Shared properties
|
||||
class UserBase(SQLModel):
|
||||
email: EmailStr = Field(unique=True, index=True, max_length=255)
|
||||
@@ -24,8 +30,11 @@ class UserRegister(SQLModel):
|
||||
|
||||
|
||||
# Properties to receive via API on update, all are optional
|
||||
class UserUpdate(UserBase):
|
||||
email: EmailStr | None = Field(default=None, max_length=255) # type: ignore
|
||||
class UserUpdate(SQLModel):
|
||||
email: EmailStr | None = Field(default=None, max_length=255)
|
||||
is_active: bool | None = None
|
||||
is_superuser: bool | None = None
|
||||
full_name: str | None = Field(default=None, max_length=255)
|
||||
password: str | None = Field(default=None, min_length=8, max_length=128)
|
||||
|
||||
|
||||
@@ -43,12 +52,17 @@ class UpdatePassword(SQLModel):
|
||||
class User(UserBase, table=True):
|
||||
id: uuid.UUID = Field(default_factory=uuid.uuid4, primary_key=True)
|
||||
hashed_password: str
|
||||
items: list["Item"] = Relationship(back_populates="owner", cascade_delete=True)
|
||||
created_at: datetime | None = Field(
|
||||
default_factory=get_datetime_utc,
|
||||
sa_type=DateTime(timezone=True), # type: ignore
|
||||
)
|
||||
items: list[Item] = Relationship(back_populates="owner", cascade_delete=True)
|
||||
|
||||
|
||||
# Properties to return via API, id is always required
|
||||
class UserPublic(UserBase):
|
||||
id: uuid.UUID
|
||||
created_at: datetime | None = None
|
||||
|
||||
|
||||
class UsersPublic(SQLModel):
|
||||
@@ -68,13 +82,18 @@ class ItemCreate(ItemBase):
|
||||
|
||||
|
||||
# Properties to receive on item update
|
||||
class ItemUpdate(ItemBase):
|
||||
title: str | None = Field(default=None, min_length=1, max_length=255) # type: ignore
|
||||
class ItemUpdate(SQLModel):
|
||||
title: str | None = Field(default=None, min_length=1, max_length=255)
|
||||
description: str | None = Field(default=None, max_length=255)
|
||||
|
||||
|
||||
# Database model, database table inferred from class name
|
||||
class Item(ItemBase, table=True):
|
||||
id: uuid.UUID = Field(default_factory=uuid.uuid4, primary_key=True)
|
||||
created_at: datetime | None = Field(
|
||||
default_factory=get_datetime_utc,
|
||||
sa_type=DateTime(timezone=True), # type: ignore
|
||||
)
|
||||
owner_id: uuid.UUID = Field(
|
||||
foreign_key="user.id", nullable=False, ondelete="CASCADE"
|
||||
)
|
||||
@@ -85,6 +104,7 @@ class Item(ItemBase, table=True):
|
||||
class ItemPublic(ItemBase):
|
||||
id: uuid.UUID
|
||||
owner_id: uuid.UUID
|
||||
created_at: datetime | None = None
|
||||
|
||||
|
||||
class ItemsPublic(SQLModel):
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
import logging
|
||||
|
||||
from sqlalchemy import Engine
|
||||
from sqlmodel import Session, select
|
||||
from tenacity import after_log, before_log, retry, stop_after_attempt, wait_fixed
|
||||
|
||||
from app.core.db import engine
|
||||
|
||||
logging.basicConfig(level=logging.INFO)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
max_tries = 60 * 5 # 5 minutes
|
||||
wait_seconds = 1
|
||||
|
||||
|
||||
@retry(
|
||||
stop=stop_after_attempt(max_tries),
|
||||
wait=wait_fixed(wait_seconds),
|
||||
before=before_log(logger, logging.INFO),
|
||||
after=after_log(logger, logging.WARN),
|
||||
)
|
||||
def init(db_engine: Engine) -> None:
|
||||
try:
|
||||
# Try to create session to check if DB is awake
|
||||
with Session(db_engine) as session:
|
||||
session.exec(select(1))
|
||||
except Exception as e:
|
||||
logger.error(e)
|
||||
raise e
|
||||
|
||||
|
||||
def main() -> None:
|
||||
logger.info("Initializing service")
|
||||
init(engine)
|
||||
logger.info("Service finished initializing")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -1,10 +1,10 @@
|
||||
import logging
|
||||
from dataclasses import dataclass
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from datetime import UTC, datetime, timedelta
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
import emails # type: ignore
|
||||
import emails
|
||||
import jwt
|
||||
from jinja2 import Template
|
||||
from jwt.exceptions import InvalidTokenError
|
||||
@@ -24,9 +24,10 @@ class EmailData:
|
||||
|
||||
def render_email_template(*, template_name: str, context: dict[str, Any]) -> str:
|
||||
template_str = (
|
||||
Path(__file__).parent / "email-templates" / "build" / template_name
|
||||
Path(__file__).parent / "email-templates" / template_name
|
||||
).read_text()
|
||||
html_content = Template(template_str).render(context)
|
||||
template: Template = Template(template_str)
|
||||
html_content = template.render(context)
|
||||
return html_content
|
||||
|
||||
|
||||
@@ -37,7 +38,8 @@ def send_email(
|
||||
html_content: str = "",
|
||||
) -> None:
|
||||
assert settings.emails_enabled, "no provided configuration for email variables"
|
||||
message = emails.Message(
|
||||
assert settings.EMAILS_FROM_EMAIL # For type checker
|
||||
message = emails.message.Message(
|
||||
subject=subject,
|
||||
html=html_content,
|
||||
mail_from=(settings.EMAILS_FROM_NAME, settings.EMAILS_FROM_EMAIL),
|
||||
@@ -102,7 +104,7 @@ def generate_new_account_email(
|
||||
|
||||
def generate_password_reset_token(email: str) -> str:
|
||||
delta = timedelta(hours=settings.EMAIL_RESET_TOKEN_EXPIRE_HOURS)
|
||||
now = datetime.now(timezone.utc)
|
||||
now = datetime.now(UTC)
|
||||
expires = now + delta
|
||||
exp = expires.timestamp()
|
||||
encoded_jwt = jwt.encode(
|
||||
|
||||
+22
-20
@@ -2,34 +2,30 @@
|
||||
name = "app"
|
||||
version = "0.1.0"
|
||||
description = ""
|
||||
requires-python = ">=3.10,<4.0"
|
||||
requires-python = ">=3.14,<4.0"
|
||||
dependencies = [
|
||||
"fastapi[standard]<1.0.0,>=0.114.2",
|
||||
"python-multipart<1.0.0,>=0.0.7",
|
||||
"fastapi[standard]>=0.141.1,<1.0.0",
|
||||
"python-multipart<1.0.0,>=0.0.27",
|
||||
"email-validator<3.0.0.0,>=2.1.0.post1",
|
||||
"passlib[bcrypt]<2.0.0,>=1.7.4",
|
||||
"tenacity<9.0.0,>=8.2.3",
|
||||
"pydantic>2.0",
|
||||
"emails<1.0,>=0.6",
|
||||
"emails>=1.1.2,<2.0",
|
||||
"jinja2<4.0.0,>=3.1.4",
|
||||
"alembic<2.0.0,>=1.12.1",
|
||||
"alembic>=1.19.1,<2.0.0",
|
||||
"httpx<1.0.0,>=0.25.1",
|
||||
"psycopg[binary]<4.0.0,>=3.1.13",
|
||||
"sqlmodel<1.0.0,>=0.0.21",
|
||||
# Pin bcrypt until passlib supports the latest
|
||||
"bcrypt==4.3.0",
|
||||
"psycopg[binary]>=3.3.4,<4.0.0",
|
||||
"sqlmodel>=0.0.39,<1.0.0",
|
||||
"pydantic-settings<3.0.0,>=2.2.1",
|
||||
"sentry-sdk[fastapi]<2.0.0,>=1.40.6",
|
||||
"pyjwt<3.0.0,>=2.8.0",
|
||||
"sentry-sdk[fastapi]>=2.68.1,<3.0.0",
|
||||
"pyjwt<3.0.0,>=2.13.0",
|
||||
"pwdlib[argon2,bcrypt]>=0.3.1",
|
||||
]
|
||||
|
||||
[tool.uv]
|
||||
dev-dependencies = [
|
||||
"pytest<8.0.0,>=7.4.3",
|
||||
"mypy<2.0.0,>=1.8.0",
|
||||
[dependency-groups]
|
||||
dev = [
|
||||
"pytest<10.0.0,>=7.4.3",
|
||||
"mypy<3.0.0,>=1.8.0",
|
||||
"ty>=0.0.25",
|
||||
"ruff<1.0.0,>=0.2.2",
|
||||
"pre-commit<4.0.0,>=3.6.2",
|
||||
"types-passlib<2.0.0.0,>=1.7.7.20240106",
|
||||
"coverage<8.0.0,>=7.4.3",
|
||||
]
|
||||
|
||||
@@ -42,7 +38,7 @@ strict = true
|
||||
exclude = ["venv", ".venv", "alembic"]
|
||||
|
||||
[tool.ruff]
|
||||
target-version = "py310"
|
||||
target-version = "py314"
|
||||
exclude = ["alembic"]
|
||||
|
||||
[tool.ruff.lint]
|
||||
@@ -78,3 +74,9 @@ sort = "-Cover"
|
||||
|
||||
[tool.coverage.html]
|
||||
show_contexts = true
|
||||
|
||||
[tool.ty.terminal]
|
||||
error-on-warning = true
|
||||
|
||||
[tool.fastapi]
|
||||
entrypoint = "app.main:app"
|
||||
|
||||
@@ -4,5 +4,6 @@ set -e
|
||||
set -x
|
||||
|
||||
mypy app
|
||||
ty check app
|
||||
ruff check app
|
||||
ruff format app --check
|
||||
|
||||
@@ -3,9 +3,6 @@
|
||||
set -e
|
||||
set -x
|
||||
|
||||
# Let the DB start
|
||||
python app/backend_pre_start.py
|
||||
|
||||
# Run migrations
|
||||
alembic upgrade head
|
||||
|
||||
|
||||
@@ -3,6 +3,6 @@
|
||||
set -e
|
||||
set -x
|
||||
|
||||
coverage run -m pytest tests/
|
||||
FASTAPI_ENV=development coverage run -m pytest tests/
|
||||
coverage report
|
||||
coverage html --title "${@-coverage}"
|
||||
|
||||
@@ -2,6 +2,4 @@
|
||||
set -e
|
||||
set -x
|
||||
|
||||
python app/tests_pre_start.py
|
||||
|
||||
bash scripts/test.sh "$@"
|
||||
|
||||
@@ -60,7 +60,7 @@ def test_read_item_not_enough_permissions(
|
||||
f"{settings.API_V1_STR}/items/{item.id}",
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert response.status_code == 400
|
||||
assert response.status_code == 403
|
||||
content = response.json()
|
||||
assert content["detail"] == "Not enough permissions"
|
||||
|
||||
@@ -121,7 +121,7 @@ def test_update_item_not_enough_permissions(
|
||||
headers=normal_user_token_headers,
|
||||
json=data,
|
||||
)
|
||||
assert response.status_code == 400
|
||||
assert response.status_code == 403
|
||||
content = response.json()
|
||||
assert content["detail"] == "Not enough permissions"
|
||||
|
||||
@@ -159,6 +159,6 @@ def test_delete_item_not_enough_permissions(
|
||||
f"{settings.API_V1_STR}/items/{item.id}",
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert response.status_code == 400
|
||||
assert response.status_code == 403
|
||||
content = response.json()
|
||||
assert content["detail"] == "Not enough permissions"
|
||||
|
||||
@@ -1,12 +1,13 @@
|
||||
from unittest.mock import patch
|
||||
|
||||
from fastapi.testclient import TestClient
|
||||
from pwdlib.hashers.bcrypt import BcryptHasher
|
||||
from sqlmodel import Session
|
||||
|
||||
from app.core.config import settings
|
||||
from app.core.security import verify_password
|
||||
from app.core.security import get_password_hash, verify_password
|
||||
from app.crud import create_user
|
||||
from app.models import UserCreate
|
||||
from app.models import User, UserCreate
|
||||
from app.utils import generate_password_reset_token
|
||||
from tests.utils.user import user_authentication_headers
|
||||
from tests.utils.utils import random_email, random_lower_string
|
||||
@@ -58,7 +59,9 @@ def test_recovery_password(
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert r.status_code == 200
|
||||
assert r.json() == {"message": "Password recovery email sent"}
|
||||
assert r.json() == {
|
||||
"message": "If that email is registered, we sent a password recovery link"
|
||||
}
|
||||
|
||||
|
||||
def test_recovery_password_user_not_exits(
|
||||
@@ -69,7 +72,11 @@ def test_recovery_password_user_not_exits(
|
||||
f"{settings.API_V1_STR}/password-recovery/{email}",
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert r.status_code == 404
|
||||
# Should return 200 with generic message to prevent email enumeration attacks
|
||||
assert r.status_code == 200
|
||||
assert r.json() == {
|
||||
"message": "If that email is registered, we sent a password recovery link"
|
||||
}
|
||||
|
||||
|
||||
def test_reset_password(client: TestClient, db: Session) -> None:
|
||||
@@ -99,7 +106,8 @@ def test_reset_password(client: TestClient, db: Session) -> None:
|
||||
assert r.json() == {"message": "Password updated successfully"}
|
||||
|
||||
db.refresh(user)
|
||||
assert verify_password(new_password, user.hashed_password)
|
||||
verified, _ = verify_password(new_password, user.hashed_password)
|
||||
assert verified
|
||||
|
||||
|
||||
def test_reset_password_invalid_token(
|
||||
@@ -116,3 +124,68 @@ def test_reset_password_invalid_token(
|
||||
assert "detail" in response
|
||||
assert r.status_code == 400
|
||||
assert response["detail"] == "Invalid token"
|
||||
|
||||
|
||||
def test_login_with_bcrypt_password_upgrades_to_argon2(
|
||||
client: TestClient, db: Session
|
||||
) -> None:
|
||||
"""Test that logging in with a bcrypt password hash upgrades it to argon2."""
|
||||
email = random_email()
|
||||
password = random_lower_string()
|
||||
|
||||
# Create a bcrypt hash directly (simulating legacy password)
|
||||
bcrypt_hasher = BcryptHasher()
|
||||
bcrypt_hash = bcrypt_hasher.hash(password)
|
||||
assert bcrypt_hash.startswith("$2") # bcrypt hashes start with $2
|
||||
|
||||
user = User(email=email, hashed_password=bcrypt_hash, is_active=True)
|
||||
db.add(user)
|
||||
db.commit()
|
||||
db.refresh(user)
|
||||
|
||||
assert user.hashed_password.startswith("$2")
|
||||
|
||||
login_data = {"username": email, "password": password}
|
||||
r = client.post(f"{settings.API_V1_STR}/login/access-token", data=login_data)
|
||||
assert r.status_code == 200
|
||||
tokens = r.json()
|
||||
assert "access_token" in tokens
|
||||
|
||||
db.refresh(user)
|
||||
|
||||
# Verify the hash was upgraded to argon2
|
||||
assert user.hashed_password.startswith("$argon2")
|
||||
|
||||
verified, updated_hash = verify_password(password, user.hashed_password)
|
||||
assert verified
|
||||
# Should not need another update since it's already argon2
|
||||
assert updated_hash is None
|
||||
|
||||
|
||||
def test_login_with_argon2_password_keeps_hash(client: TestClient, db: Session) -> None:
|
||||
"""Test that logging in with an argon2 password hash does not update it."""
|
||||
email = random_email()
|
||||
password = random_lower_string()
|
||||
|
||||
# Create an argon2 hash (current default)
|
||||
argon2_hash = get_password_hash(password)
|
||||
assert argon2_hash.startswith("$argon2")
|
||||
|
||||
# Create user with argon2 hash
|
||||
user = User(email=email, hashed_password=argon2_hash, is_active=True)
|
||||
db.add(user)
|
||||
db.commit()
|
||||
db.refresh(user)
|
||||
|
||||
original_hash = user.hashed_password
|
||||
|
||||
login_data = {"username": email, "password": password}
|
||||
r = client.post(f"{settings.API_V1_STR}/login/access-token", data=login_data)
|
||||
assert r.status_code == 200
|
||||
tokens = r.json()
|
||||
assert "access_token" in tokens
|
||||
|
||||
db.refresh(user)
|
||||
|
||||
assert user.hashed_password == original_hash
|
||||
assert user.hashed_password.startswith("$argon2")
|
||||
|
||||
@@ -8,6 +8,7 @@ from app import crud
|
||||
from app.core.config import settings
|
||||
from app.core.security import verify_password
|
||||
from app.models import User, UserCreate
|
||||
from tests.utils.user import create_random_user
|
||||
from tests.utils.utils import random_email, random_lower_string
|
||||
|
||||
|
||||
@@ -56,7 +57,7 @@ def test_create_user_new_email(
|
||||
assert user.email == created_user["email"]
|
||||
|
||||
|
||||
def test_get_existing_user(
|
||||
def test_get_existing_user_as_superuser(
|
||||
client: TestClient, superuser_token_headers: dict[str, str], db: Session
|
||||
) -> None:
|
||||
username = random_email()
|
||||
@@ -75,6 +76,17 @@ def test_get_existing_user(
|
||||
assert existing_user.email == api_user["email"]
|
||||
|
||||
|
||||
def test_get_non_existing_user_as_superuser(
|
||||
client: TestClient, superuser_token_headers: dict[str, str]
|
||||
) -> None:
|
||||
r = client.get(
|
||||
f"{settings.API_V1_STR}/users/{uuid.uuid4()}",
|
||||
headers=superuser_token_headers,
|
||||
)
|
||||
assert r.status_code == 404
|
||||
assert r.json() == {"detail": "User not found"}
|
||||
|
||||
|
||||
def test_get_existing_user_current_user(client: TestClient, db: Session) -> None:
|
||||
username = random_email()
|
||||
password = random_lower_string()
|
||||
@@ -103,10 +115,28 @@ def test_get_existing_user_current_user(client: TestClient, db: Session) -> None
|
||||
|
||||
|
||||
def test_get_existing_user_permissions_error(
|
||||
client: TestClient, normal_user_token_headers: dict[str, str]
|
||||
db: Session,
|
||||
client: TestClient,
|
||||
normal_user_token_headers: dict[str, str],
|
||||
) -> None:
|
||||
user = create_random_user(db)
|
||||
|
||||
r = client.get(
|
||||
f"{settings.API_V1_STR}/users/{uuid.uuid4()}",
|
||||
f"{settings.API_V1_STR}/users/{user.id}",
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert r.status_code == 403
|
||||
assert r.json() == {"detail": "The user doesn't have enough privileges"}
|
||||
|
||||
|
||||
def test_get_non_existing_user_permissions_error(
|
||||
client: TestClient,
|
||||
normal_user_token_headers: dict[str, str],
|
||||
) -> None:
|
||||
user_id = uuid.uuid4()
|
||||
|
||||
r = client.get(
|
||||
f"{settings.API_V1_STR}/users/{user_id}",
|
||||
headers=normal_user_token_headers,
|
||||
)
|
||||
assert r.status_code == 403
|
||||
@@ -212,7 +242,8 @@ def test_update_password_me(
|
||||
user_db = db.exec(user_query).first()
|
||||
assert user_db
|
||||
assert user_db.email == settings.FIRST_SUPERUSER
|
||||
assert verify_password(new_password, user_db.hashed_password)
|
||||
verified, _ = verify_password(new_password, user_db.hashed_password)
|
||||
assert verified
|
||||
|
||||
# Revert to the old password to keep consistency in test
|
||||
old_data = {
|
||||
@@ -227,7 +258,10 @@ def test_update_password_me(
|
||||
db.refresh(user_db)
|
||||
|
||||
assert r.status_code == 200
|
||||
assert verify_password(settings.FIRST_SUPERUSER_PASSWORD, user_db.hashed_password)
|
||||
verified, _ = verify_password(
|
||||
settings.FIRST_SUPERUSER_PASSWORD, user_db.hashed_password
|
||||
)
|
||||
assert verified
|
||||
|
||||
|
||||
def test_update_password_me_incorrect_password(
|
||||
@@ -301,7 +335,8 @@ def test_register_user(client: TestClient, db: Session) -> None:
|
||||
assert user_db
|
||||
assert user_db.email == username
|
||||
assert user_db.full_name == full_name
|
||||
assert verify_password(password, user_db.hashed_password)
|
||||
verified, _ = verify_password(password, user_db.hashed_password)
|
||||
assert verified
|
||||
|
||||
|
||||
def test_register_user_already_exists_error(client: TestClient) -> None:
|
||||
|
||||
@@ -13,7 +13,7 @@ from tests.utils.utils import get_superuser_token_headers
|
||||
|
||||
|
||||
@pytest.fixture(scope="session", autouse=True)
|
||||
def db() -> Generator[Session, None, None]:
|
||||
def db() -> Generator[Session]:
|
||||
with Session(engine) as session:
|
||||
init_db(session)
|
||||
yield session
|
||||
@@ -25,7 +25,7 @@ def db() -> Generator[Session, None, None]:
|
||||
|
||||
|
||||
@pytest.fixture(scope="module")
|
||||
def client() -> Generator[TestClient, None, None]:
|
||||
def client() -> Generator[TestClient]:
|
||||
with TestClient(app) as c:
|
||||
yield c
|
||||
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
from fastapi.encoders import jsonable_encoder
|
||||
from pwdlib.hashers.bcrypt import BcryptHasher
|
||||
from sqlmodel import Session
|
||||
|
||||
from app import crud
|
||||
@@ -44,9 +45,9 @@ def test_check_if_user_is_active(db: Session) -> None:
|
||||
def test_check_if_user_is_active_inactive(db: Session) -> None:
|
||||
email = random_email()
|
||||
password = random_lower_string()
|
||||
user_in = UserCreate(email=email, password=password, disabled=True)
|
||||
user_in = UserCreate(email=email, password=password, is_active=False)
|
||||
user = crud.create_user(session=db, user_create=user_in)
|
||||
assert user.is_active
|
||||
assert user.is_active is False
|
||||
|
||||
|
||||
def test_check_if_user_is_superuser(db: Session) -> None:
|
||||
@@ -88,4 +89,42 @@ def test_update_user(db: Session) -> None:
|
||||
user_2 = db.get(User, user.id)
|
||||
assert user_2
|
||||
assert user.email == user_2.email
|
||||
assert verify_password(new_password, user_2.hashed_password)
|
||||
verified, _ = verify_password(new_password, user_2.hashed_password)
|
||||
assert verified
|
||||
|
||||
|
||||
def test_authenticate_user_with_bcrypt_upgrades_to_argon2(db: Session) -> None:
|
||||
"""Test that a user with bcrypt password hash gets upgraded to argon2 on login."""
|
||||
email = random_email()
|
||||
password = random_lower_string()
|
||||
|
||||
# Create a bcrypt hash directly (simulating legacy password)
|
||||
bcrypt_hasher = BcryptHasher()
|
||||
bcrypt_hash = bcrypt_hasher.hash(password)
|
||||
assert bcrypt_hash.startswith("$2") # bcrypt hashes start with $2
|
||||
|
||||
# Create user with bcrypt hash directly in the database
|
||||
user = User(email=email, hashed_password=bcrypt_hash)
|
||||
db.add(user)
|
||||
db.commit()
|
||||
db.refresh(user)
|
||||
|
||||
# Verify the hash is bcrypt before authentication
|
||||
assert user.hashed_password.startswith("$2")
|
||||
|
||||
# Authenticate - this should upgrade the hash to argon2
|
||||
authenticated_user = crud.authenticate(session=db, email=email, password=password)
|
||||
assert authenticated_user
|
||||
assert authenticated_user.email == email
|
||||
|
||||
db.refresh(authenticated_user)
|
||||
|
||||
# Verify the hash was upgraded to argon2
|
||||
assert authenticated_user.hashed_password.startswith("$argon2")
|
||||
|
||||
verified, updated_hash = verify_password(
|
||||
password, authenticated_user.hashed_password
|
||||
)
|
||||
assert verified
|
||||
# Should not need another update since it's already argon2
|
||||
assert updated_hash is None
|
||||
|
||||
@@ -1,33 +0,0 @@
|
||||
from unittest.mock import MagicMock, patch
|
||||
|
||||
from sqlmodel import select
|
||||
|
||||
from app.backend_pre_start import init, logger
|
||||
|
||||
|
||||
def test_init_successful_connection() -> None:
|
||||
engine_mock = MagicMock()
|
||||
|
||||
session_mock = MagicMock()
|
||||
exec_mock = MagicMock(return_value=True)
|
||||
session_mock.configure_mock(**{"exec.return_value": exec_mock})
|
||||
|
||||
with (
|
||||
patch("sqlmodel.Session", return_value=session_mock),
|
||||
patch.object(logger, "info"),
|
||||
patch.object(logger, "error"),
|
||||
patch.object(logger, "warn"),
|
||||
):
|
||||
try:
|
||||
init(engine_mock)
|
||||
connection_successful = True
|
||||
except Exception:
|
||||
connection_successful = False
|
||||
|
||||
assert (
|
||||
connection_successful
|
||||
), "The database connection should be successful and not raise an exception."
|
||||
|
||||
assert session_mock.exec.called_once_with(
|
||||
select(1)
|
||||
), "The session should execute a select statement once."
|
||||
@@ -1,33 +0,0 @@
|
||||
from unittest.mock import MagicMock, patch
|
||||
|
||||
from sqlmodel import select
|
||||
|
||||
from app.tests_pre_start import init, logger
|
||||
|
||||
|
||||
def test_init_successful_connection() -> None:
|
||||
engine_mock = MagicMock()
|
||||
|
||||
session_mock = MagicMock()
|
||||
exec_mock = MagicMock(return_value=True)
|
||||
session_mock.configure_mock(**{"exec.return_value": exec_mock})
|
||||
|
||||
with (
|
||||
patch("sqlmodel.Session", return_value=session_mock),
|
||||
patch.object(logger, "info"),
|
||||
patch.object(logger, "error"),
|
||||
patch.object(logger, "warn"),
|
||||
):
|
||||
try:
|
||||
init(engine_mock)
|
||||
connection_successful = True
|
||||
except Exception:
|
||||
connection_successful = False
|
||||
|
||||
assert (
|
||||
connection_successful
|
||||
), "The database connection should be successful and not raise an exception."
|
||||
|
||||
assert session_mock.exec.called_once_with(
|
||||
select(1)
|
||||
), "The session should execute a select statement once."
|
||||
Generated
-1659
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,61 @@
|
||||
services:
|
||||
|
||||
proxy:
|
||||
restart: always
|
||||
ports:
|
||||
# Listen on port 80, default for HTTP, necessary to redirect to HTTPS
|
||||
- "80:80"
|
||||
# Listen on port 443, default for HTTPS
|
||||
- "443:443"
|
||||
volumes:
|
||||
# Mount the volume to store the certificates
|
||||
- traefik-certificates:/certificates
|
||||
command:
|
||||
# Enable Docker in Traefik, so that it reads labels from Docker services
|
||||
- --providers.docker
|
||||
# Do not expose all Docker services, only the ones explicitly exposed
|
||||
- --providers.docker.exposedbydefault=false
|
||||
# Create an entrypoint "http" listening on port 80
|
||||
- --entrypoints.http.address=:80
|
||||
# Redirect all HTTP traffic to HTTPS
|
||||
- --entrypoints.http.http.redirections.entrypoint.to=https
|
||||
- --entrypoints.http.http.redirections.entrypoint.scheme=https
|
||||
# Create an entrypoint "https" listening on port 443
|
||||
- --entrypoints.https.address=:443
|
||||
# Store the Let's Encrypt certificates in the mounted volume
|
||||
- --certificatesresolvers.le.acme.storage=/certificates/acme.json
|
||||
# Use the TLS Challenge for Let's Encrypt
|
||||
- --certificatesresolvers.le.acme.tlschallenge=true
|
||||
# Enable the access log, with HTTP requests
|
||||
- --accesslog
|
||||
# Enable the Traefik log, for configurations and errors
|
||||
- --log
|
||||
|
||||
db:
|
||||
restart: always
|
||||
|
||||
adminer:
|
||||
restart: always
|
||||
labels:
|
||||
# Route HTTPS traffic for the Adminer subdomain
|
||||
- traefik.http.routers.adminer-https.rule=Host(`adminer.${DOMAIN:?Variable not set}`)
|
||||
- traefik.http.routers.adminer-https.entrypoints=https
|
||||
- traefik.http.routers.adminer-https.tls=true
|
||||
# Use the Let's Encrypt resolver
|
||||
- traefik.http.routers.adminer-https.tls.certresolver=le
|
||||
|
||||
backend:
|
||||
restart: always
|
||||
environment:
|
||||
FRONTEND_HOST: https://${DOMAIN:?Variable not set}
|
||||
labels:
|
||||
# Route HTTPS traffic for this domain
|
||||
- traefik.http.routers.backend-https.rule=Host(`${DOMAIN:?Variable not set}`)
|
||||
- traefik.http.routers.backend-https.entrypoints=https
|
||||
- traefik.http.routers.backend-https.tls=true
|
||||
# Use the Let's Encrypt resolver
|
||||
- traefik.http.routers.backend-https.tls.certresolver=le
|
||||
|
||||
volumes:
|
||||
# Create a volume to store the certificates, even if the container is recreated
|
||||
traefik-certificates:
|
||||
@@ -0,0 +1,100 @@
|
||||
services:
|
||||
|
||||
proxy:
|
||||
image: traefik:v3.7
|
||||
ports:
|
||||
- "80:80"
|
||||
- "8090:8080"
|
||||
# Duplicate the command from compose.yml to add --api.insecure=true
|
||||
command:
|
||||
# Enable Docker in Traefik, so that it reads labels from Docker services
|
||||
- --providers.docker
|
||||
# Do not expose all Docker services, only the ones explicitly exposed
|
||||
- --providers.docker.exposedbydefault=false
|
||||
# Create an entrypoint "http" listening on port 80
|
||||
- --entrypoints.http.address=:80
|
||||
# Enable the access log, with HTTP requests
|
||||
- --accesslog
|
||||
# Enable the Traefik log, for configurations and errors
|
||||
- --log
|
||||
# Enable debug logging for local development
|
||||
- --log.level=DEBUG
|
||||
# Enable the Dashboard and API
|
||||
- --api
|
||||
# Enable the Dashboard and API in insecure mode for local development
|
||||
- --api.insecure=true
|
||||
db:
|
||||
ports:
|
||||
- "5432:5432"
|
||||
|
||||
adminer:
|
||||
ports:
|
||||
- "8080:8080"
|
||||
|
||||
backend:
|
||||
ports:
|
||||
- "8000:8000"
|
||||
build:
|
||||
context: .
|
||||
dockerfile: backend/Dockerfile
|
||||
# command: sleep infinity # Infinite loop to keep container alive doing nothing
|
||||
command:
|
||||
- fastapi
|
||||
- dev
|
||||
- --host
|
||||
- "0.0.0.0"
|
||||
develop:
|
||||
watch:
|
||||
- path: ./backend
|
||||
action: sync
|
||||
target: /app/backend
|
||||
ignore:
|
||||
- .venv
|
||||
- path: ./backend/pyproject.toml
|
||||
action: rebuild
|
||||
- path: ./frontend
|
||||
action: rebuild
|
||||
ignore:
|
||||
- ./frontend/node_modules
|
||||
- ./frontend/dist
|
||||
- ./frontend/blob-report
|
||||
- ./frontend/test-results
|
||||
# TODO: remove once coverage is done locally
|
||||
volumes:
|
||||
- ./backend/htmlcov:/app/backend/htmlcov
|
||||
environment:
|
||||
FASTAPI_ENV: "development"
|
||||
SMTP_HOST: "mailpit"
|
||||
SMTP_PORT: "1025"
|
||||
SMTP_TLS: "false"
|
||||
|
||||
mailpit:
|
||||
image: axllent/mailpit
|
||||
ports:
|
||||
- "8025:8025"
|
||||
- "1025:1025"
|
||||
|
||||
playwright:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: frontend/Dockerfile.playwright
|
||||
args:
|
||||
- NODE_ENV=production
|
||||
ipc: host
|
||||
depends_on:
|
||||
- backend
|
||||
- mailpit
|
||||
environment:
|
||||
- FIRST_SUPERUSER=${FIRST_SUPERUSER:?Variable not set}
|
||||
- FIRST_SUPERUSER_PASSWORD=${FIRST_SUPERUSER_PASSWORD:?Variable not set}
|
||||
- PLAYWRIGHT_BASE_URL=http://backend:8000
|
||||
- VITE_API_URL=http://backend:8000
|
||||
- MAILPIT_HOST=http://mailpit:8025
|
||||
# For the reports when run locally
|
||||
- PLAYWRIGHT_HTML_HOST=0.0.0.0
|
||||
- CI=${CI:-}
|
||||
volumes:
|
||||
- ./frontend/blob-report:/app/frontend/blob-report
|
||||
- ./frontend/test-results:/app/frontend/test-results
|
||||
ports:
|
||||
- 9323:9323
|
||||
+88
@@ -0,0 +1,88 @@
|
||||
services:
|
||||
|
||||
proxy:
|
||||
image: traefik:v3.7
|
||||
volumes:
|
||||
# Add Docker as a mounted volume, so that Traefik can read the labels of other services
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
command:
|
||||
# Enable Docker in Traefik, so that it reads labels from Docker services
|
||||
- --providers.docker
|
||||
# Do not expose all Docker services, only the ones explicitly exposed
|
||||
- --providers.docker.exposedbydefault=false
|
||||
# Create an entrypoint "http" listening on port 80
|
||||
- --entrypoints.http.address=:80
|
||||
# Enable the access log, with HTTP requests
|
||||
- --accesslog
|
||||
# Enable the Traefik log, for configurations and errors
|
||||
- --log
|
||||
|
||||
db:
|
||||
image: postgres:18
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U postgres -d app"]
|
||||
interval: 10s
|
||||
retries: 5
|
||||
start_period: 30s
|
||||
timeout: 10s
|
||||
volumes:
|
||||
- app-db-data:/var/lib/postgresql
|
||||
environment:
|
||||
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Variable not set}
|
||||
- POSTGRES_DB=app
|
||||
|
||||
adminer:
|
||||
image: adminer
|
||||
depends_on:
|
||||
- db
|
||||
environment:
|
||||
- ADMINER_DESIGN=pepa-linha-dark
|
||||
labels:
|
||||
# Enable Traefik for this service
|
||||
- traefik.enable=true
|
||||
# Route HTTP traffic for the Adminer subdomain
|
||||
- traefik.http.routers.adminer-http.rule=Host(`adminer.${DOMAIN:-localhost}`)
|
||||
- traefik.http.routers.adminer-http.entrypoints=http
|
||||
# Define the port inside of the Docker service to use
|
||||
- traefik.http.services.adminer.loadbalancer.server.port=8080
|
||||
|
||||
backend:
|
||||
image: backend:latest
|
||||
depends_on:
|
||||
db:
|
||||
condition: service_healthy
|
||||
restart: true
|
||||
environment:
|
||||
PROJECT_NAME: ${PROJECT_NAME:?Variable not set}
|
||||
SECRET_KEY: ${SECRET_KEY:?Variable not set}
|
||||
FIRST_SUPERUSER: ${FIRST_SUPERUSER:?Variable not set}
|
||||
FIRST_SUPERUSER_PASSWORD: ${FIRST_SUPERUSER_PASSWORD:?Variable not set}
|
||||
SMTP_HOST: ${SMTP_HOST}
|
||||
SMTP_USER: ${SMTP_USER:-}
|
||||
SMTP_PASSWORD: ${SMTP_PASSWORD:-}
|
||||
EMAILS_FROM_EMAIL: ${EMAILS_FROM_EMAIL}
|
||||
DATABASE_URL: postgresql://postgres:${POSTGRES_PASSWORD:?Variable not set}@db:5432/app
|
||||
SENTRY_DSN: ${SENTRY_DSN:-}
|
||||
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:8000/api/v1/utils/health-check/"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
|
||||
build:
|
||||
context: .
|
||||
dockerfile: backend/Dockerfile
|
||||
labels:
|
||||
# Enable Traefik for this service
|
||||
- traefik.enable=true
|
||||
|
||||
# Define the port inside of the Docker service to use
|
||||
- traefik.http.services.backend.loadbalancer.server.port=8000
|
||||
|
||||
# Route HTTP traffic for this domain
|
||||
- traefik.http.routers.backend-http.rule=Host(`${DOMAIN:-localhost}`)
|
||||
- traefik.http.routers.backend-http.entrypoints=http
|
||||
|
||||
volumes:
|
||||
app-db-data:
|
||||
-100
@@ -1,100 +0,0 @@
|
||||
project_name:
|
||||
type: str
|
||||
help: The name of the project, shown to API users (in .env)
|
||||
default: FastAPI Project
|
||||
|
||||
stack_name:
|
||||
type: str
|
||||
help: The name of the stack used for Docker Compose labels (no spaces) (in .env)
|
||||
default: fastapi-project
|
||||
|
||||
secret_key:
|
||||
type: str
|
||||
help: |
|
||||
'The secret key for the project, used for security,
|
||||
stored in .env, you can generate one with:
|
||||
python -c "import secrets; print(secrets.token_urlsafe(32))"'
|
||||
default: changethis
|
||||
|
||||
first_superuser:
|
||||
type: str
|
||||
help: The email of the first superuser (in .env)
|
||||
default: admin@example.com
|
||||
|
||||
first_superuser_password:
|
||||
type: str
|
||||
help: The password of the first superuser (in .env)
|
||||
default: changethis
|
||||
|
||||
smtp_host:
|
||||
type: str
|
||||
help: The SMTP server host to send emails, you can set it later in .env
|
||||
default: ""
|
||||
|
||||
smtp_user:
|
||||
type: str
|
||||
help: The SMTP server user to send emails, you can set it later in .env
|
||||
default: ""
|
||||
|
||||
smtp_password:
|
||||
type: str
|
||||
help: The SMTP server password to send emails, you can set it later in .env
|
||||
default: ""
|
||||
|
||||
emails_from_email:
|
||||
type: str
|
||||
help: The email account to send emails from, you can set it later in .env
|
||||
default: info@example.com
|
||||
|
||||
postgres_password:
|
||||
type: str
|
||||
help: |
|
||||
'The password for the PostgreSQL database, stored in .env,
|
||||
you can generate one with:
|
||||
python -c "import secrets; print(secrets.token_urlsafe(32))"'
|
||||
default: changethis
|
||||
|
||||
sentry_dsn:
|
||||
type: str
|
||||
help: The DSN for Sentry, if you are using it, you can set it later in .env
|
||||
default: ""
|
||||
|
||||
_exclude:
|
||||
# Global
|
||||
- .vscode
|
||||
- .mypy_cache
|
||||
# Python
|
||||
- __pycache__
|
||||
- app.egg-info
|
||||
- "*.pyc"
|
||||
- .mypy_cache
|
||||
- .coverage
|
||||
- htmlcov
|
||||
- .cache
|
||||
- .venv
|
||||
# Frontend
|
||||
# Logs
|
||||
- logs
|
||||
- "*.log"
|
||||
- npm-debug.log*
|
||||
- yarn-debug.log*
|
||||
- yarn-error.log*
|
||||
- pnpm-debug.log*
|
||||
- lerna-debug.log*
|
||||
- node_modules
|
||||
- dist
|
||||
- dist-ssr
|
||||
- "*.local"
|
||||
# Editor directories and files
|
||||
- .idea
|
||||
- .DS_Store
|
||||
- "*.suo"
|
||||
- "*.ntvs*"
|
||||
- "*.njsproj"
|
||||
- "*.sln"
|
||||
- "*.sw?"
|
||||
|
||||
_answers_file: .copier/.copier-answers.yml
|
||||
|
||||
_tasks:
|
||||
- ["{{ _copier_python }}", .copier/update_dotenv.py]
|
||||
@@ -0,0 +1,129 @@
|
||||
# FastAPI Project - Docker Compose Deployment
|
||||
|
||||
You can deploy the project to your own remote server with Docker Compose. The deployment configuration includes Traefik to handle HTTPS and route incoming traffic to the application.
|
||||
|
||||
## Preparation
|
||||
|
||||
* Have a remote server ready and available.
|
||||
* Configure DNS records pointing to the server for the application domain and any supporting service subdomains you want to expose, such as `fastapi-project.example.com` and `adminer.fastapi-project.example.com`.
|
||||
* Install and configure [Docker](https://docs.docker.com/engine/install/) on the remote server (Docker Engine, not Docker Desktop).
|
||||
|
||||
## Copy the Code
|
||||
|
||||
```bash
|
||||
rsync -av --exclude=".git/" --filter=":- .gitignore" ./ root@your-server.example.com:/root/code/app/
|
||||
```
|
||||
|
||||
The `--filter=":- .gitignore"` option tells `rsync` to use the same ignore rules as Git, excluding files such as the Python virtual environment.
|
||||
|
||||
## Configure the Application
|
||||
|
||||
### Environment Variables
|
||||
|
||||
Set the application domain, project name, and first superuser email:
|
||||
|
||||
```bash
|
||||
export DOMAIN=fastapi-project.example.com
|
||||
export PROJECT_NAME="Full Stack FastAPI Project"
|
||||
export FIRST_SUPERUSER=admin@example.com
|
||||
```
|
||||
|
||||
You can also configure these environment variables as needed:
|
||||
|
||||
* `SMTP_HOST`: The SMTP server host from your email provider.
|
||||
* `SMTP_USER`: The SMTP server user.
|
||||
* `EMAILS_FROM_EMAIL`: The email account used to send emails.
|
||||
* `SENTRY_DSN`: The DSN for Sentry.
|
||||
|
||||
### Secrets
|
||||
|
||||
Generate and set secure values for the database password, token signing key, and first superuser password:
|
||||
|
||||
```bash
|
||||
export POSTGRES_PASSWORD="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
|
||||
export SECRET_KEY="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
|
||||
export FIRST_SUPERUSER_PASSWORD="$(python -c 'import secrets; print(secrets.token_urlsafe(32))')"
|
||||
```
|
||||
|
||||
To use an authenticated email provider, also set `SMTP_PASSWORD`.
|
||||
|
||||
## Deploy
|
||||
|
||||
```bash
|
||||
cd /root/code/app/
|
||||
docker compose -f compose.yml -f compose.deploy.yml build
|
||||
docker compose -f compose.yml -f compose.deploy.yml run --rm backend bash scripts/prestart.sh
|
||||
docker compose -f compose.yml -f compose.deploy.yml up -d
|
||||
```
|
||||
|
||||
The `compose.deploy.yml` file adds HTTPS and automatic certificate handling to the shared `compose.yml` configuration. Explicitly listing both files excludes the local settings from `compose.override.yml`.
|
||||
|
||||
The backend Docker image builds the frontend, so the server does not need Bun or prebuilt frontend files.
|
||||
|
||||
## Deploy with GitHub Actions
|
||||
|
||||
The included `.github/workflows/deploy-docker-compose.yml` workflow runs the deployment commands on the server when manually triggered from GitHub Actions.
|
||||
|
||||
Use a self-hosted runner only for a repository whose contributors and workflow code you trust. GitHub recommends using self-hosted runners with private repositories because workflows execute directly on the runner machine.
|
||||
|
||||
### Configure Repository Variables and Secrets
|
||||
|
||||
In the repository, go to **Settings** > **Secrets and variables** > **Actions** and add these repository variables:
|
||||
|
||||
* `DOMAIN`
|
||||
* `PROJECT_NAME`
|
||||
* `FIRST_SUPERUSER`
|
||||
|
||||
To enable emails, add these optional repository variables:
|
||||
|
||||
* `SMTP_HOST`
|
||||
* `SMTP_USER`
|
||||
* `EMAILS_FROM_EMAIL`
|
||||
|
||||
To enable Sentry, add the optional `SENTRY_DSN` repository variable.
|
||||
|
||||
Add these repository secrets:
|
||||
|
||||
* `POSTGRES_PASSWORD`
|
||||
* `SECRET_KEY`
|
||||
* `FIRST_SUPERUSER_PASSWORD`
|
||||
|
||||
To use an authenticated email provider, add the optional `SMTP_PASSWORD` repository secret.
|
||||
|
||||
### Install a Self-Hosted Runner
|
||||
|
||||
On the server, create a dedicated user and grant it access to Docker:
|
||||
|
||||
```bash
|
||||
sudo adduser github
|
||||
sudo usermod -aG docker github
|
||||
sudo su - github
|
||||
```
|
||||
|
||||
In the GitHub repository, go to **Settings** > **Actions** > **Runners**, select **New self-hosted runner**, choose Linux, and follow the commands GitHub provides to download, configure, and register the runner. Install it in `/home/github/actions-runner`.
|
||||
|
||||
After registering the runner, exit the `github` user session and install the runner as a system service:
|
||||
|
||||
```bash
|
||||
exit
|
||||
cd /home/github/actions-runner
|
||||
sudo ./svc.sh install github
|
||||
sudo ./svc.sh start
|
||||
sudo ./svc.sh status
|
||||
```
|
||||
|
||||
See GitHub's guides for [adding a self-hosted runner](https://docs.github.com/en/actions/how-tos/manage-runners/self-hosted-runners/add-runners) and [configuring the runner as a service](https://docs.github.com/en/actions/how-tos/manage-runners/self-hosted-runners/configure-the-application?platform=linux).
|
||||
|
||||
### Run the Deployment
|
||||
|
||||
When the runner is online, open the repository's **Actions** tab, select **Deploy with Docker Compose**, and select **Run workflow**.
|
||||
|
||||
## URLs
|
||||
|
||||
Replace `fastapi-project.example.com` with your domain.
|
||||
|
||||
Application (frontend and API): `https://fastapi-project.example.com`
|
||||
|
||||
Interactive API docs: `https://fastapi-project.example.com/docs`
|
||||
|
||||
Adminer: `https://adminer.fastapi-project.example.com`
|
||||
+50
-262
@@ -1,309 +1,97 @@
|
||||
# FastAPI Project - Deployment
|
||||
|
||||
You can deploy the project using Docker Compose to a remote server.
|
||||
Deploy the project to [FastAPI Cloud](https://fastapicloud.com) with the included GitHub Actions workflow.
|
||||
|
||||
This project expects you to have a Traefik proxy handling communication to the outside world and HTTPS certificates.
|
||||
## Create the FastAPI Cloud Application
|
||||
|
||||
You can use CI/CD (continuous integration and continuous deployment) systems to deploy automatically, there are already configurations to do it with GitHub Actions.
|
||||
Create an application in FastAPI Cloud and set its [Application Directory](https://fastapicloud.com/docs/builds-and-deployments/application-directory/) to `backend`.
|
||||
|
||||
But you have to configure a couple things first. 🤓
|
||||
Connect a PostgreSQL database using the [Neon](https://fastapicloud.com/docs/integrations/neon-integration/) or [Supabase](https://fastapicloud.com/docs/integrations/supabase-integration/) integration. Both integrations configure a `DATABASE_URL` secret automatically. You can also configure `DATABASE_URL` manually for another PostgreSQL provider.
|
||||
|
||||
## Preparation
|
||||
## Configure the Application
|
||||
|
||||
* Have a remote server ready and available.
|
||||
* Configure the DNS records of your domain to point to the IP of the server you just created.
|
||||
* Configure a wildcard subdomain for your domain, so that you can have multiple subdomains for different services, e.g. `*.fastapi-project.example.com`. This will be useful for accessing different components, like `dashboard.fastapi-project.example.com`, `api.fastapi-project.example.com`, `traefik.fastapi-project.example.com`, `adminer.fastapi-project.example.com`, etc. And also for `staging`, like `dashboard.staging.fastapi-project.example.com`, `adminer.staging.fastapi-project.example.com`, etc.
|
||||
* Install and configure [Docker](https://docs.docker.com/engine/install/) on the remote server (Docker Engine, not Docker Desktop).
|
||||
### Environment Variables
|
||||
|
||||
## Public Traefik
|
||||
Add these required [environment variables](https://fastapicloud.com/docs/builds-and-deployments/environment-variables/) to the FastAPI Cloud application:
|
||||
|
||||
We need a Traefik proxy to handle incoming connections and HTTPS certificates.
|
||||
* `PROJECT_NAME`: The name of the project, used in the API documentation and emails.
|
||||
* `FIRST_SUPERUSER`: The email address of the first superuser.
|
||||
* `FRONTEND_HOST`: The public URL of the application, such as the generated `https://your-app.fastapicloud.dev` URL or a custom domain.
|
||||
|
||||
You need to do these next steps only once.
|
||||
To enable emails, add these optional environment variables with values from your email provider:
|
||||
|
||||
### Traefik Docker Compose
|
||||
* `SMTP_HOST`
|
||||
* `SMTP_USER`
|
||||
* `EMAILS_FROM_EMAIL`
|
||||
|
||||
* Create a remote directory to store your Traefik Docker Compose file:
|
||||
To enable Sentry, configure `SENTRY_DSN`.
|
||||
|
||||
```bash
|
||||
mkdir -p /root/code/traefik-public/
|
||||
```
|
||||
### Secrets
|
||||
|
||||
Copy the Traefik Docker Compose file to your server. You could do it by running the command `rsync` in your local terminal:
|
||||
Add these required values and mark them as secrets:
|
||||
|
||||
```bash
|
||||
rsync -a docker-compose.traefik.yml root@your-server.example.com:/root/code/traefik-public/
|
||||
```
|
||||
|
||||
### Traefik Public Network
|
||||
|
||||
This Traefik will expect a Docker "public network" named `traefik-public` to communicate with your stack(s).
|
||||
|
||||
This way, there will be a single public Traefik proxy that handles the communication (HTTP and HTTPS) with the outside world, and then behind that, you could have one or more stacks with different domains, even if they are on the same single server.
|
||||
|
||||
To create a Docker "public network" named `traefik-public` run the following command in your remote server:
|
||||
|
||||
```bash
|
||||
docker network create traefik-public
|
||||
```
|
||||
|
||||
### Traefik Environment Variables
|
||||
|
||||
The Traefik Docker Compose file expects some environment variables to be set in your terminal before starting it. You can do it by running the following commands in your remote server.
|
||||
|
||||
* Create the username for HTTP Basic Auth, e.g.:
|
||||
|
||||
```bash
|
||||
export USERNAME=admin
|
||||
```
|
||||
|
||||
* Create an environment variable with the password for HTTP Basic Auth, e.g.:
|
||||
|
||||
```bash
|
||||
export PASSWORD=changethis
|
||||
```
|
||||
|
||||
* Use openssl to generate the "hashed" version of the password for HTTP Basic Auth and store it in an environment variable:
|
||||
|
||||
```bash
|
||||
export HASHED_PASSWORD=$(openssl passwd -apr1 $PASSWORD)
|
||||
```
|
||||
|
||||
To verify that the hashed password is correct, you can print it:
|
||||
|
||||
```bash
|
||||
echo $HASHED_PASSWORD
|
||||
```
|
||||
|
||||
* Create an environment variable with the domain name for your server, e.g.:
|
||||
|
||||
```bash
|
||||
export DOMAIN=fastapi-project.example.com
|
||||
```
|
||||
|
||||
* Create an environment variable with the email for Let's Encrypt, e.g.:
|
||||
|
||||
```bash
|
||||
export EMAIL=admin@example.com
|
||||
```
|
||||
|
||||
**Note**: you need to set a different email, an email `@example.com` won't work.
|
||||
|
||||
### Start the Traefik Docker Compose
|
||||
|
||||
Go to the directory where you copied the Traefik Docker Compose file in your remote server:
|
||||
|
||||
```bash
|
||||
cd /root/code/traefik-public/
|
||||
```
|
||||
|
||||
Now with the environment variables set and the `docker-compose.traefik.yml` in place, you can start the Traefik Docker Compose running the following command:
|
||||
|
||||
```bash
|
||||
docker compose -f docker-compose.traefik.yml up -d
|
||||
```
|
||||
|
||||
## Deploy the FastAPI Project
|
||||
|
||||
Now that you have Traefik in place you can deploy your FastAPI project with Docker Compose.
|
||||
|
||||
**Note**: You might want to jump ahead to the section about Continuous Deployment with GitHub Actions.
|
||||
|
||||
## Environment Variables
|
||||
|
||||
You need to set some environment variables first.
|
||||
|
||||
Set the `ENVIRONMENT`, by default `local` (for development), but when deploying to a server you would put something like `staging` or `production`:
|
||||
|
||||
```bash
|
||||
export ENVIRONMENT=production
|
||||
```
|
||||
|
||||
Set the `DOMAIN`, by default `localhost` (for development), but when deploying you would use your own domain, for example:
|
||||
|
||||
```bash
|
||||
export DOMAIN=fastapi-project.example.com
|
||||
```
|
||||
|
||||
You can set several variables, like:
|
||||
|
||||
* `PROJECT_NAME`: The name of the project, used in the API for the docs and emails.
|
||||
* `STACK_NAME`: The name of the stack used for Docker Compose labels and project name, this should be different for `staging`, `production`, etc. You could use the same domain replacing dots with dashes, e.g. `fastapi-project-example-com` and `staging-fastapi-project-example-com`.
|
||||
* `BACKEND_CORS_ORIGINS`: A list of allowed CORS origins separated by commas.
|
||||
* `SECRET_KEY`: The secret key for the FastAPI project, used to sign tokens.
|
||||
* `FIRST_SUPERUSER`: The email of the first superuser, this superuser will be the one that can create new users.
|
||||
* `SECRET_KEY`: A secret key used to sign security tokens.
|
||||
* `FIRST_SUPERUSER_PASSWORD`: The password of the first superuser.
|
||||
* `SMTP_HOST`: The SMTP server host to send emails, this would come from your email provider (E.g. Mailgun, Sparkpost, Sendgrid, etc).
|
||||
* `SMTP_USER`: The SMTP server user to send emails.
|
||||
* `SMTP_PASSWORD`: The SMTP server password to send emails.
|
||||
* `EMAILS_FROM_EMAIL`: The email account to send emails from.
|
||||
* `POSTGRES_SERVER`: The hostname of the PostgreSQL server. You can leave the default of `db`, provided by the same Docker Compose. You normally wouldn't need to change this unless you are using a third-party provider.
|
||||
* `POSTGRES_PORT`: The port of the PostgreSQL server. You can leave the default. You normally wouldn't need to change this unless you are using a third-party provider.
|
||||
* `POSTGRES_PASSWORD`: The Postgres password.
|
||||
* `POSTGRES_USER`: The Postgres user, you can leave the default.
|
||||
* `POSTGRES_DB`: The database name to use for this application. You can leave the default of `app`.
|
||||
* `SENTRY_DSN`: The DSN for Sentry, if you are using it.
|
||||
* `DATABASE_URL`: The PostgreSQL connection URL, configured automatically when using a database integration.
|
||||
|
||||
## GitHub Actions Environment Variables
|
||||
To enable emails with an authenticated provider, add `SMTP_PASSWORD` as a secret.
|
||||
|
||||
There are some environment variables only used by GitHub Actions that you can configure:
|
||||
|
||||
* `LATEST_CHANGES`: Used by the GitHub Action [latest-changes](https://github.com/tiangolo/latest-changes) to automatically add release notes based on the PRs merged. It's a personal access token, read the docs for details.
|
||||
* `SMOKESHOW_AUTH_KEY`: Used to handle and publish the code coverage using [Smokeshow](https://github.com/samuelcolvin/smokeshow), follow their instructions to create a (free) Smokeshow key.
|
||||
|
||||
### Generate secret keys
|
||||
|
||||
Some environment variables in the `.env` file have a default value of `changethis`.
|
||||
|
||||
You have to change them with a secret key, to generate secret keys you can run the following command:
|
||||
You can generate secure values for `SECRET_KEY` and `FIRST_SUPERUSER_PASSWORD` with:
|
||||
|
||||
```bash
|
||||
python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||
```
|
||||
|
||||
Copy the content and use that as password / secret key. And run that again to generate another secure key.
|
||||
## Configure Continuous Deployment
|
||||
|
||||
### Deploy with Docker Compose
|
||||
The included `.github/workflows/deploy.yml` workflow builds the frontend, prepares the database, and deploys the application whenever changes are pushed to `master`. You can also run it manually from the **Actions** tab.
|
||||
|
||||
With the environment variables in place, you can deploy with Docker Compose:
|
||||
Log in to FastAPI Cloud and configure the [deploy token](https://fastapicloud.com/docs/advanced-features/deploy-tokens/) and application ID as GitHub repository secrets:
|
||||
|
||||
```bash
|
||||
docker compose -f docker-compose.yml up -d
|
||||
uv run fastapi login
|
||||
uv run fastapi cloud setup-ci --secrets-only --app-id <your-app-id>
|
||||
```
|
||||
|
||||
For production you wouldn't want to have the overrides in `docker-compose.override.yml`, that's why we explicitly specify `docker-compose.yml` as the file to use.
|
||||
If the GitHub CLI is installed and authenticated, the command configures `FASTAPI_CLOUD_TOKEN` and `FASTAPI_CLOUD_APP_ID` automatically. Otherwise, it prints the values so you can add them in your repository under **Settings** > **Secrets and variables** > **Actions**.
|
||||
|
||||
## Continuous Deployment (CD)
|
||||
The workflow runs database migrations and creates the first superuser before deploying. In the repository's **Settings** > **Secrets and variables** > **Actions** page, add these repository variables:
|
||||
|
||||
You can use GitHub Actions to deploy your project automatically. 😎
|
||||
|
||||
You can have multiple environment deployments.
|
||||
|
||||
There are already two environments configured, `staging` and `production`. 🚀
|
||||
|
||||
### Install GitHub Actions Runner
|
||||
|
||||
* On your remote server, create a user for your GitHub Actions:
|
||||
|
||||
```bash
|
||||
sudo adduser github
|
||||
```
|
||||
|
||||
* Add Docker permissions to the `github` user:
|
||||
|
||||
```bash
|
||||
sudo usermod -aG docker github
|
||||
```
|
||||
|
||||
* Temporarily switch to the `github` user:
|
||||
|
||||
```bash
|
||||
sudo su - github
|
||||
```
|
||||
|
||||
* Go to the `github` user's home directory:
|
||||
|
||||
```bash
|
||||
cd
|
||||
```
|
||||
|
||||
* [Install a GitHub Action self-hosted runner following the official guide](https://docs.github.com/en/actions/hosting-your-own-runners/managing-self-hosted-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-a-repository).
|
||||
|
||||
* When asked about labels, add a label for the environment, e.g. `production`. You can also add labels later.
|
||||
|
||||
After installing, the guide would tell you to run a command to start the runner. Nevertheless, it would stop once you terminate that process or if your local connection to your server is lost.
|
||||
|
||||
To make sure it runs on startup and continues running, you can install it as a service. To do that, exit the `github` user and go back to the `root` user:
|
||||
|
||||
```bash
|
||||
exit
|
||||
```
|
||||
|
||||
After you do it, you will be on the previous user again. And you will be on the previous directory, belonging to that user.
|
||||
|
||||
Before being able to go the `github` user directory, you need to become the `root` user (you might already be):
|
||||
|
||||
```bash
|
||||
sudo su
|
||||
```
|
||||
|
||||
* As the `root` user, go to the `actions-runner` directory inside of the `github` user's home directory:
|
||||
|
||||
```bash
|
||||
cd /home/github/actions-runner
|
||||
```
|
||||
|
||||
* Install the self-hosted runner as a service with the user `github`:
|
||||
|
||||
```bash
|
||||
./svc.sh install github
|
||||
```
|
||||
|
||||
* Start the service:
|
||||
|
||||
```bash
|
||||
./svc.sh start
|
||||
```
|
||||
|
||||
* Check the status of the service:
|
||||
|
||||
```bash
|
||||
./svc.sh status
|
||||
```
|
||||
|
||||
You can read more about it in the official guide: [Configuring the self-hosted runner application as a service](https://docs.github.com/en/actions/hosting-your-own-runners/managing-self-hosted-runners/configuring-the-self-hosted-runner-application-as-a-service).
|
||||
|
||||
### Set Secrets
|
||||
|
||||
On your repository, configure secrets for the environment variables you need, the same ones described above, including `SECRET_KEY`, etc. Follow the [official GitHub guide for setting repository secrets](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#creating-secrets-for-a-repository).
|
||||
|
||||
The current Github Actions workflows expect these secrets:
|
||||
|
||||
* `DOMAIN_PRODUCTION`
|
||||
* `DOMAIN_STAGING`
|
||||
* `STACK_NAME_PRODUCTION`
|
||||
* `STACK_NAME_STAGING`
|
||||
* `EMAILS_FROM_EMAIL`
|
||||
* `PROJECT_NAME`
|
||||
* `FIRST_SUPERUSER`
|
||||
* `FIRST_SUPERUSER_PASSWORD`
|
||||
* `POSTGRES_PASSWORD`
|
||||
|
||||
Add these repository secrets:
|
||||
|
||||
* `DATABASE_URL`
|
||||
* `SECRET_KEY`
|
||||
* `LATEST_CHANGES`
|
||||
* `SMOKESHOW_AUTH_KEY`
|
||||
* `FIRST_SUPERUSER_PASSWORD`
|
||||
|
||||
## GitHub Action Deployment Workflows
|
||||
Use the same values configured in FastAPI Cloud. For `DATABASE_URL`, use the connection URL from your database provider. The database must be reachable from GitHub-hosted runners so the preparation step can connect to it.
|
||||
|
||||
There are GitHub Action workflows in the `.github/workflows` directory already configured for deploying to the environments (GitHub Actions runners with the labels):
|
||||
The deployment workflow performs these steps:
|
||||
|
||||
* `staging`: after pushing (or merging) to the branch `master`.
|
||||
* `production`: after publishing a release.
|
||||
|
||||
If you need to add extra environments you could use those as a starting point.
|
||||
1. Installs and builds the frontend into `backend/app/frontend`.
|
||||
2. Runs `backend/scripts/prestart.sh` to apply database migrations and create the first superuser.
|
||||
3. Deploys the project with `uv run fastapi deploy`.
|
||||
|
||||
## URLs
|
||||
|
||||
Replace `fastapi-project.example.com` with your domain.
|
||||
Replace `your-app.fastapicloud.dev` with the URL of your FastAPI Cloud application.
|
||||
|
||||
### Main Traefik Dashboard
|
||||
Application (frontend and API): `https://your-app.fastapicloud.dev`
|
||||
|
||||
Traefik UI: `https://traefik.fastapi-project.example.com`
|
||||
Interactive API docs: `https://your-app.fastapicloud.dev/docs`
|
||||
|
||||
### Production
|
||||
## Docker Compose
|
||||
|
||||
Frontend: `https://dashboard.fastapi-project.example.com`
|
||||
For deployment to your own server, see the [Docker Compose deployment guide](./deployment-docker-compose.md).
|
||||
|
||||
Backend API docs: `https://api.fastapi-project.example.com/docs`
|
||||
## GitHub Repository Automation
|
||||
|
||||
Backend API base URL: `https://api.fastapi-project.example.com`
|
||||
Install the following GitHub Apps to enable the included repository automation:
|
||||
|
||||
Adminer: `https://adminer.fastapi-project.example.com`
|
||||
* [Latest Changes](https://github.com/apps/latest-changes) updates `release-notes.md` when a pull request is merged.
|
||||
* [PR Push](https://github.com/apps/pr-push) lets the pre-commit workflow push automated fixes to pull request branches.
|
||||
* [PR Submit](https://github.com/apps/pr-submit) lets the **Bump pre-commit hooks** and **Prepare Release** workflows create pull requests.
|
||||
|
||||
### Staging
|
||||
|
||||
Frontend: `https://dashboard.staging.fastapi-project.example.com`
|
||||
|
||||
Backend API docs: `https://api.staging.fastapi-project.example.com/docs`
|
||||
|
||||
Backend API base URL: `https://api.staging.fastapi-project.example.com`
|
||||
|
||||
Adminer: `https://adminer.staging.fastapi-project.example.com`
|
||||
To publish code coverage with [Smokeshow](https://github.com/samuelcolvin/smokeshow), add `SMOKESHOW_AUTH_KEY` as a repository secret.
|
||||
|
||||
+84
-165
@@ -1,122 +1,95 @@
|
||||
# FastAPI Project - Development
|
||||
|
||||
## Docker Compose
|
||||
## Local Development
|
||||
|
||||
* Start the local stack with Docker Compose:
|
||||
For local development, run PostgreSQL and Mailpit with Docker Compose, and run the FastAPI and Vite development servers locally.
|
||||
|
||||
Start the supporting services:
|
||||
|
||||
```bash
|
||||
docker compose up -d db mailpit
|
||||
```
|
||||
|
||||
Then, from the `backend` directory, install the dependencies and prepare the database:
|
||||
|
||||
```bash
|
||||
uv sync
|
||||
uv run bash scripts/prestart.sh
|
||||
```
|
||||
|
||||
Start the FastAPI development server:
|
||||
|
||||
```bash
|
||||
uv run fastapi dev
|
||||
```
|
||||
|
||||
In another terminal, from the project root, install the frontend dependencies and start the Vite development server:
|
||||
|
||||
```bash
|
||||
bun install
|
||||
bun run dev
|
||||
```
|
||||
|
||||
Now you can open these URLs:
|
||||
|
||||
Frontend development server: <http://localhost:5173>
|
||||
|
||||
Backend API: <http://localhost:8000>
|
||||
|
||||
Automatic interactive API documentation with Swagger UI: <http://localhost:8000/docs>
|
||||
|
||||
Mailpit: <http://localhost:8025>
|
||||
|
||||
The frontend development server uses the backend at `http://localhost:8000`, as configured in `frontend/.env`.
|
||||
|
||||
### Frontend Served by FastAPI
|
||||
|
||||
Build the frontend from the `frontend` directory:
|
||||
|
||||
```bash
|
||||
bun run build
|
||||
```
|
||||
|
||||
The build is written to `backend/app/frontend` and served by FastAPI at <http://localhost:8000>. Rebuild the frontend after making frontend changes.
|
||||
|
||||
## Full Stack with Docker Compose
|
||||
|
||||
To run the backend and built frontend in Docker Compose:
|
||||
|
||||
```bash
|
||||
docker compose run --rm backend bash scripts/prestart.sh
|
||||
docker compose watch
|
||||
```
|
||||
|
||||
* Now you can open your browser and interact with these URLs:
|
||||
Now you can open these URLs:
|
||||
|
||||
Frontend, built with Docker, with routes handled based on the path: <http://localhost:5173>
|
||||
Application, with the frontend and API served by FastAPI: <http://localhost:8000>
|
||||
|
||||
Backend, JSON based web API based on OpenAPI: <http://localhost:8000>
|
||||
|
||||
Automatic interactive documentation with Swagger UI (from the OpenAPI backend): <http://localhost:8000/docs>
|
||||
Automatic interactive API documentation with Swagger UI: <http://localhost:8000/docs>
|
||||
|
||||
Adminer, database web administration: <http://localhost:8080>
|
||||
|
||||
Traefik UI, to see how the routes are being handled by the proxy: <http://localhost:8090>
|
||||
|
||||
**Note**: The first time you start your stack, it might take a minute for it to be ready. While the backend waits for the database to be ready and configures everything. You can check the logs to monitor it.
|
||||
Mailpit: <http://localhost:8025>
|
||||
|
||||
To check the logs, run (in another terminal):
|
||||
Stop a locally running FastAPI server before starting the Compose backend because both use port `8000`.
|
||||
|
||||
```bash
|
||||
docker compose logs
|
||||
```
|
||||
**Note**: The first time you start the stack, it might take a minute for all the services to be ready. To monitor it, use `docker compose logs`, or `docker compose logs backend` for the backend service.
|
||||
|
||||
To check the logs of a specific service, add the name of the service, e.g.:
|
||||
## Mailpit
|
||||
|
||||
```bash
|
||||
docker compose logs backend
|
||||
```
|
||||
[Mailpit](https://mailpit.axllent.org) captures emails sent during local development instead of delivering them. The local backend connects to it at `localhost:1025`, and the Compose backend connects to the `mailpit` service. Captured emails are available at <http://localhost:8025>.
|
||||
|
||||
## Mailcatcher
|
||||
## Docker Compose Files and Environment Variables
|
||||
|
||||
Mailcatcher is a simple SMTP server that catches all emails sent by the backend during local development. Instead of sending real emails, they are captured and displayed in a web interface.
|
||||
The main `compose.yml` file contains the configuration shared by the whole stack. Docker Compose loads it automatically.
|
||||
|
||||
This is useful for:
|
||||
The `compose.override.yml` file adds local development settings, such as mounting the source code as a volume. Docker Compose also loads it automatically and applies it on top of `compose.yml`.
|
||||
|
||||
* Testing email functionality during development
|
||||
* Verifying email content and formatting
|
||||
* Debugging email-related functionality without sending real emails
|
||||
The `compose.deploy.yml` file contains the deployment-specific settings, including HTTPS and automatic certificate handling. It is explicitly combined with `compose.yml` when deploying the application.
|
||||
|
||||
The backend is automatically configured to use Mailcatcher when running with Docker Compose locally (SMTP on port 1025). All captured emails can be viewed at <http://localhost:1080>.
|
||||
|
||||
## Local Development
|
||||
|
||||
The Docker Compose files are configured so that each of the services is available in a different port in `localhost`.
|
||||
|
||||
For the backend and frontend, they use the same port that would be used by their local development server, so, the backend is at `http://localhost:8000` and the frontend at `http://localhost:5173`.
|
||||
|
||||
This way, you could turn off a Docker Compose service and start its local development service, and everything would keep working, because it all uses the same ports.
|
||||
|
||||
For example, you can stop that `frontend` service in the Docker Compose, in another terminal, run:
|
||||
|
||||
```bash
|
||||
docker compose stop frontend
|
||||
```
|
||||
|
||||
And then start the local frontend development server:
|
||||
|
||||
```bash
|
||||
cd frontend
|
||||
npm run dev
|
||||
```
|
||||
|
||||
Or you could stop the `backend` Docker Compose service:
|
||||
|
||||
```bash
|
||||
docker compose stop backend
|
||||
```
|
||||
|
||||
And then you can run the local development server for the backend:
|
||||
|
||||
```bash
|
||||
cd backend
|
||||
fastapi dev app/main.py
|
||||
```
|
||||
|
||||
## Docker Compose in `localhost.tiangolo.com`
|
||||
|
||||
When you start the Docker Compose stack, it uses `localhost` by default, with different ports for each service (backend, frontend, adminer, etc).
|
||||
|
||||
When you deploy it to production (or staging), it will deploy each service in a different subdomain, like `api.example.com` for the backend and `dashboard.example.com` for the frontend.
|
||||
|
||||
In the guide about [deployment](deployment.md) you can read about Traefik, the configured proxy. That's the component in charge of transmitting traffic to each service based on the subdomain.
|
||||
|
||||
If you want to test that it's all working locally, you can edit the local `.env` file, and change:
|
||||
|
||||
```dotenv
|
||||
DOMAIN=localhost.tiangolo.com
|
||||
```
|
||||
|
||||
That will be used by the Docker Compose files to configure the base domain for the services.
|
||||
|
||||
Traefik will use this to transmit traffic at `api.localhost.tiangolo.com` to the backend, and traffic at `dashboard.localhost.tiangolo.com` to the frontend.
|
||||
|
||||
The domain `localhost.tiangolo.com` is a special domain that is configured (with all its subdomains) to point to `127.0.0.1`. This way you can use that for your local development.
|
||||
|
||||
After you update it, run again:
|
||||
|
||||
```bash
|
||||
docker compose watch
|
||||
```
|
||||
|
||||
When deploying, for example in production, the main Traefik is configured outside of the Docker Compose files. For local development, there's an included Traefik in `docker-compose.override.yml`, just to let you test that the domains work as expected, for example with `api.localhost.tiangolo.com` and `dashboard.localhost.tiangolo.com`.
|
||||
|
||||
## Docker Compose files and env vars
|
||||
|
||||
There is a main `docker-compose.yml` file with all the configurations that apply to the whole stack, it is used automatically by `docker compose`.
|
||||
|
||||
And there's also a `docker-compose.override.yml` with overrides for development, for example to mount the source code as a volume. It is used automatically by `docker compose` to apply overrides on top of `docker-compose.yml`.
|
||||
|
||||
These Docker Compose files use the `.env` file containing configurations to be injected as environment variables in the containers.
|
||||
|
||||
They also use some additional configurations taken from environment variables set in the scripts before calling the `docker compose` command.
|
||||
The backend reads local settings from the `.env` file. Docker Compose also uses it for variable interpolation and passes the settings each container needs.
|
||||
|
||||
After changing variables, make sure you restart the stack:
|
||||
|
||||
@@ -124,96 +97,42 @@ After changing variables, make sure you restart the stack:
|
||||
docker compose watch
|
||||
```
|
||||
|
||||
## The .env file
|
||||
## The `.env` File
|
||||
|
||||
The `.env` file is the one that contains all your configurations, generated keys and passwords, etc.
|
||||
The tracked `.env` file contains local development defaults, passwords, and other configuration. Its hostnames use `localhost` for processes running on your machine. Docker Compose overrides hostnames such as the database and SMTP server with their Compose service names.
|
||||
|
||||
Depending on your workflow, you could want to exclude it from Git, for example if your project is public. In that case, you would have to make sure to set up a way for your CI tools to obtain it while building or deploying your project.
|
||||
Do not store deployment secrets in `.env`. Configure them as described in the [FastAPI Cloud deployment guide](./deployment.md) or the [Docker Compose deployment guide](./deployment-docker-compose.md).
|
||||
|
||||
One way to do it could be to add each environment variable to your CI/CD system, and updating the `docker-compose.yml` file to read that specific env var instead of reading the `.env` file.
|
||||
## Pre-commit Hooks and Code Linting
|
||||
|
||||
## Pre-commits and code linting
|
||||
|
||||
we are using a tool called [pre-commit](https://pre-commit.com/) for code linting and formatting.
|
||||
|
||||
When you install it, it runs right before making a commit in git. This way it ensures that the code is consistent and formatted even before it is committed.
|
||||
The project uses [prek](https://prek.j178.dev/), a modern alternative to [pre-commit](https://pre-commit.com/), for code linting and formatting.
|
||||
|
||||
You can find a file `.pre-commit-config.yaml` with configurations at the root of the project.
|
||||
|
||||
#### Install pre-commit to run automatically
|
||||
### Install `prek` to Run Automatically
|
||||
|
||||
`pre-commit` is already part of the dependencies of the project, but you could also install it globally if you prefer to, following [the official pre-commit docs](https://pre-commit.com/).
|
||||
`prek` is already part of the dependencies of the project.
|
||||
|
||||
After having the `pre-commit` tool installed and available, you need to "install" it in the local repository, so that it runs automatically before each commit.
|
||||
|
||||
Using `uv`, you could do it with:
|
||||
From the project root, install the Git hook so that `prek` runs automatically before each commit:
|
||||
|
||||
```bash
|
||||
❯ uv run pre-commit install
|
||||
pre-commit installed at .git/hooks/pre-commit
|
||||
uv run prek install -f
|
||||
```
|
||||
|
||||
Now whenever you try to commit, e.g. with:
|
||||
The `-f` flag forces the installation, in case there was already a `pre-commit` hook previously installed.
|
||||
|
||||
Now whenever you try to commit, for example with:
|
||||
|
||||
```bash
|
||||
git commit
|
||||
```
|
||||
|
||||
...pre-commit will run and check and format the code you are about to commit, and will ask you to add that code (stage it) with git again before committing.
|
||||
`prek` will check and format the code you are about to commit. If it modifies any files, add those files to Git again before committing.
|
||||
|
||||
Then you can `git add` the modified/fixed files again and now you can commit.
|
||||
### Run `prek` Manually
|
||||
|
||||
#### Running pre-commit hooks manually
|
||||
|
||||
you can also run `pre-commit` manually on all the files, you can do it using `uv` with:
|
||||
You can also run `prek` manually on all files from the project root:
|
||||
|
||||
```bash
|
||||
❯ uv run pre-commit run --all-files
|
||||
check for added large files..............................................Passed
|
||||
check toml...............................................................Passed
|
||||
check yaml...............................................................Passed
|
||||
ruff.....................................................................Passed
|
||||
ruff-format..............................................................Passed
|
||||
eslint...................................................................Passed
|
||||
prettier.................................................................Passed
|
||||
uv run prek run --all-files
|
||||
```
|
||||
|
||||
## URLs
|
||||
|
||||
The production or staging URLs would use these same paths, but with your own domain.
|
||||
|
||||
### Development URLs
|
||||
|
||||
Development URLs, for local development.
|
||||
|
||||
Frontend: <http://localhost:5173>
|
||||
|
||||
Backend: <http://localhost:8000>
|
||||
|
||||
Automatic Interactive Docs (Swagger UI): <http://localhost:8000/docs>
|
||||
|
||||
Automatic Alternative Docs (ReDoc): <http://localhost:8000/redoc>
|
||||
|
||||
Adminer: <http://localhost:8080>
|
||||
|
||||
Traefik UI: <http://localhost:8090>
|
||||
|
||||
MailCatcher: <http://localhost:1080>
|
||||
|
||||
### Development URLs with `localhost.tiangolo.com` Configured
|
||||
|
||||
Development URLs, for local development.
|
||||
|
||||
Frontend: <http://dashboard.localhost.tiangolo.com>
|
||||
|
||||
Backend: <http://api.localhost.tiangolo.com>
|
||||
|
||||
Automatic Interactive Docs (Swagger UI): <http://api.localhost.tiangolo.com/docs>
|
||||
|
||||
Automatic Alternative Docs (ReDoc): <http://api.localhost.tiangolo.com/redoc>
|
||||
|
||||
Adminer: <http://localhost.tiangolo.com:8080>
|
||||
|
||||
Traefik UI: <http://localhost.tiangolo.com:8090>
|
||||
|
||||
MailCatcher: <http://localhost.tiangolo.com:1080>
|
||||
|
||||
@@ -1,133 +0,0 @@
|
||||
services:
|
||||
|
||||
# Local services are available on their ports, but also available on:
|
||||
# http://api.localhost.tiangolo.com: backend
|
||||
# http://dashboard.localhost.tiangolo.com: frontend
|
||||
# etc. To enable it, update .env, set:
|
||||
# DOMAIN=localhost.tiangolo.com
|
||||
proxy:
|
||||
image: traefik:3.0
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
ports:
|
||||
- "80:80"
|
||||
- "8090:8080"
|
||||
# Duplicate the command from docker-compose.yml to add --api.insecure=true
|
||||
command:
|
||||
# Enable Docker in Traefik, so that it reads labels from Docker services
|
||||
- --providers.docker
|
||||
# Add a constraint to only use services with the label for this stack
|
||||
- --providers.docker.constraints=Label(`traefik.constraint-label`, `traefik-public`)
|
||||
# Do not expose all Docker services, only the ones explicitly exposed
|
||||
- --providers.docker.exposedbydefault=false
|
||||
# Create an entrypoint "http" listening on port 80
|
||||
- --entrypoints.http.address=:80
|
||||
# Create an entrypoint "https" listening on port 443
|
||||
- --entrypoints.https.address=:443
|
||||
# Enable the access log, with HTTP requests
|
||||
- --accesslog
|
||||
# Enable the Traefik log, for configurations and errors
|
||||
- --log
|
||||
# Enable debug logging for local development
|
||||
- --log.level=DEBUG
|
||||
# Enable the Dashboard and API
|
||||
- --api
|
||||
# Enable the Dashboard and API in insecure mode for local development
|
||||
- --api.insecure=true
|
||||
labels:
|
||||
# Enable Traefik for this service, to make it available in the public network
|
||||
- traefik.enable=true
|
||||
- traefik.constraint-label=traefik-public
|
||||
# Dummy https-redirect middleware that doesn't really redirect, only to
|
||||
# allow running it locally
|
||||
- traefik.http.middlewares.https-redirect.contenttype.autodetect=false
|
||||
networks:
|
||||
- traefik-public
|
||||
- default
|
||||
|
||||
db:
|
||||
restart: "no"
|
||||
ports:
|
||||
- "5432:5432"
|
||||
|
||||
adminer:
|
||||
restart: "no"
|
||||
ports:
|
||||
- "8080:8080"
|
||||
|
||||
backend:
|
||||
restart: "no"
|
||||
ports:
|
||||
- "8000:8000"
|
||||
build:
|
||||
context: ./backend
|
||||
# command: sleep infinity # Infinite loop to keep container alive doing nothing
|
||||
command:
|
||||
- fastapi
|
||||
- run
|
||||
- --reload
|
||||
- "app/main.py"
|
||||
develop:
|
||||
watch:
|
||||
- path: ./backend
|
||||
action: sync
|
||||
target: /app
|
||||
ignore:
|
||||
- ./backend/.venv
|
||||
- .venv
|
||||
- path: ./backend/pyproject.toml
|
||||
action: rebuild
|
||||
# TODO: remove once coverage is done locally
|
||||
volumes:
|
||||
- ./backend/htmlcov:/app/htmlcov
|
||||
environment:
|
||||
SMTP_HOST: "mailcatcher"
|
||||
SMTP_PORT: "1025"
|
||||
SMTP_TLS: "false"
|
||||
EMAILS_FROM_EMAIL: "noreply@example.com"
|
||||
|
||||
mailcatcher:
|
||||
image: schickling/mailcatcher
|
||||
ports:
|
||||
- "1080:1080"
|
||||
- "1025:1025"
|
||||
|
||||
frontend:
|
||||
restart: "no"
|
||||
ports:
|
||||
- "5173:80"
|
||||
build:
|
||||
context: ./frontend
|
||||
args:
|
||||
- VITE_API_URL=http://localhost:8000
|
||||
- NODE_ENV=development
|
||||
|
||||
playwright:
|
||||
build:
|
||||
context: ./frontend
|
||||
dockerfile: Dockerfile.playwright
|
||||
args:
|
||||
- VITE_API_URL=http://backend:8000
|
||||
- NODE_ENV=production
|
||||
ipc: host
|
||||
depends_on:
|
||||
- backend
|
||||
- mailcatcher
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
- VITE_API_URL=http://backend:8000
|
||||
- MAILCATCHER_HOST=http://mailcatcher:1080
|
||||
# For the reports when run locally
|
||||
- PLAYWRIGHT_HTML_HOST=0.0.0.0
|
||||
- CI=${CI}
|
||||
volumes:
|
||||
- ./frontend/blob-report:/app/blob-report
|
||||
- ./frontend/test-results:/app/test-results
|
||||
ports:
|
||||
- 9323:9323
|
||||
|
||||
networks:
|
||||
traefik-public:
|
||||
# For local dev, don't expect an external Traefik network
|
||||
external: false
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user