Commit Graph

68 Commits

Author SHA1 Message Date
Indiana
852a630fe0 Add Plan 2/7: Frontend, LLM & Realtime Pipeline
Reordered to put a real browsable site first (React frontend served
by FastAPI, Tasks 1-2) ahead of backend-only plumbing (Ollama queue,
Piper TTS, WebSocket session channel, Tasks 3-5) that Plans 3-6 will
build spirit-mode logic on top of.
2026-07-20 17:38:38 +00:00
Indiana
ed5313158d fix: address final-review hygiene items (pydantic config, cookie alias, argon2 exception scope)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 16:00:35 +00:00
Indiana
b8168b69a1 test: cover rate limiter eviction path with mocked time
Added test_hits_expire_after_window_elapses() which uses unittest.mock.patch
to deterministically advance time and verify that expired hits are evicted from
the rolling window. This exercises the while loop in RateLimiter.allow() that
was previously untested.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 15:52:03 +00:00
Indiana
53828dad19 feat: add rate limiter utility 2026-07-20 15:47:56 +00:00
Indiana
10ac364a90 fix: use https base_url in test client so Secure cookies propagate automatically
httpx's cookie jar only auto-attaches Secure cookies to https:// requests.
Switching the ASGITransport client fixture's base_url from http://test to
https://test (no real socket is opened either way) makes it behave like a
browser talking to the Cloudflare-Tunnel-terminated HTTPS edge in
production, eliminating the need for manual client.cookies.set(...)
re-injection workarounds in test_auth.py.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 15:44:01 +00:00
Indiana
3758594896 fix: harden login/logout — secure cookie, server-side session revocation, timing-safe login
Addresses three Important-severity review findings inherited from Task 4's
plan reference code:

- login() now sets secure=True on the session cookie (safe behind the
  Cloudflare Tunnel, which terminates TLS at the edge).
- logout() looks up and deletes the matching AuthSession row before
  clearing the cookie, so a leaked raw token can no longer be replayed
  after logout.
- login() always performs exactly one verify_password call regardless of
  whether the username exists (against a module-level dummy hash for
  nonexistent users), removing the timing oracle that let unauthenticated
  requests distinguish registered from unregistered usernames.

Adds two tests: nonexistent-username login rejection, and logout revoking
the session server-side. Also adjusts two cookie-propagation touch points
in test_auth.py to manually re-inject the qm_session cookie, since
httpx's cookie jar won't auto-attach a Secure cookie to the test
transport's plain http://test base_url (a real browser talking to the
HTTPS tunnel edge wouldn't have this problem).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 15:34:12 +00:00
Indiana
a0723b5237 feat: add login, session cookies, and get_current_user 2026-07-20 15:26:58 +00:00
Indiana
fa725f1a0e fix: move NullPool test fix from db.py into a conftest-local test engine
Production code shouldn't branch on `"pytest" in sys.modules` — it's
fragile and couples db.py to test tooling. Instead, conftest.py now
builds its own dedicated NullPool engine directly from settings, used
only for the drop_all/create_all reset and the get_db override. The
production engine in app/db.py is untouched and never exercised during
tests, so this fully preserves the event-loop fix while keeping prod
code test-agnostic.
2026-07-20 15:22:41 +00:00
Indiana
f31ddd2822 fix: use NullPool for db engine under pytest to avoid cross-event-loop asyncpg errors
Task 3's conftest.py (per plan) reuses the module-level app.db.engine
singleton across every test. pytest-asyncio 0.24 gives each test function
its own event loop by default, and asyncpg connections are bound to the
loop they were opened on. Pooling a connection from a prior test's loop
made subsequent tests fail with "got Future attached to a different loop"
as soon as more than one DB-touching test ran in the same session.

NullPool is applied only when running under pytest (detected via
sys.modules), so production keeps normal connection pooling and only the
test suite pays the cost of a fresh connection per checkout.
2026-07-20 15:14:36 +00:00
Indiana
cfffc7ff59 feat: add user model and registration endpoint 2026-07-20 15:14:31 +00:00
Indiana
9e69c622c9 feat: add settings and async db engine 2026-07-20 15:01:25 +00:00
Indiana
1747c355e0 fix: restore .worktrees/ entry in .gitignore and add backend/tests/__init__.py
- Restored .worktrees/ line that was lost when .gitignore was overwritten in commit 1736dd0
- Added backend/tests/__init__.py as a package marker (was untracked on disk)
- Test suite verified: backend tests pass (1/1)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 14:57:32 +00:00
Indiana
1736dd021b chore: scaffold backend venv, health check, systemd unit 2026-07-20 14:52:53 +00:00
Indiana
7ab8adce83 Rewrite Plan 1 to drop Docker: venv + systemd + apt Postgres
Task 1 now scaffolds a Python venv and a systemd unit template
instead of a Dockerfile/Compose stack. Task 3 installs Postgres
directly via apt and creates dev/test databases on the same
instance. All test-run commands switched from `docker compose run`
to plain `pytest` with exported env vars.
2026-07-20 07:04:39 +00:00
Indiana
3634fed229 Drop Docker from deployment architecture
User's Proxmox LXC CTs run apps as plain venv + systemd services,
not containers. Updated spec sections 2, 6, and 9 to reflect a
bare-metal deployment: Postgres via apt, FastAPI app via uvicorn
under a systemd unit.
2026-07-20 07:02:14 +00:00
Indiana
cadd74f0dd chore: ignore .worktrees directory 2026-07-20 06:54:49 +00:00
Indiana
2b786d8925 Add Plan 1/7: Foundation & Auth implementation plan
Repo scaffold, Docker Compose (app + postgres + isolated postgres_test),
async SQLAlchemy setup, and username/password auth with argon2 hashing
and server-side session cookies. Remaining six plans (LLM/TTS pipeline,
Wire Ghost, EVP, Spirit Radio, Codex, i18n) follow once this lands.
2026-07-20 06:13:03 +00:00
Indiana
709f6b336f Add Quantumancy website design spec
Captures the v1 architecture for the self-hosted spirit-communication
web app: FastAPI + React stack, four launch modes (Spirit Radio, EVP,
Wire Ghost, Ouija/Planchette), hybrid entity/Codex system backed by a
remote CPU-only Ollama instance, and deployment via Docker Compose
behind a Cloudflare Tunnel. ESP32-P4/C6 hardware is scoped out for a
future spec.
2026-07-20 05:53:01 +00:00