normogen/backend/src/app.rs
goose eb2c2aa546
Some checks failed
Lint and Build / format (pull_request) Successful in 39s
Lint and Build / clippy (pull_request) Successful in 1m40s
Lint and Build / build (pull_request) Successful in 3m45s
Lint and Build / test (pull_request) Failing after 2m55s
feat: per-profile DEKs + multi-profile (Phase A2, #3)
Implements the 3-tier key model from the multi-person sharing ADR:
each account owns multiple profiles (a person or pet — a 'subject of
care'), and each profile has its own random AES-256-GCM DEK. All
health data is now encrypted under the active profile's DEK, not the
account-wide DEK. The account DEK wraps each profile DEK; the server
stores only opaque wrapped blobs.

Per the ADR: DB wipe, no migration (no real user data). This unblocks
Phase B (sharing) — there is now a per-profile key to wrap to a
recipient's X25519 public key.

Backend:
- Profile model: owner_account_id, kind (human/pet), relationship,
  wrapped_profile_dek + iv. ProfileRepository gains find_all_by_owner,
  find_by_profile_id_owned, update_profile, delete_profile — all
  ownership-scoped.
- Profile handlers: GET/POST /api/profiles, GET/PUT/DELETE
  /api/profiles/:id. Removed /api/profiles/me. Renamed users.rs
  get_profile/update_profile (the /api/users/me handlers) to
  get_account/update_account to resolve a name collision.
- Register accepts default_profile_* fields and auto-creates the self
  profile when the client provides a wrapped profile DEK.
- HealthStatistic + Appointment gain profile_id and ?profile_id=
  filtering (health stats previously had no profile binding).
- New profile_tests.rs: multi-profile CRUD + ownership isolation +
  register-with-default-profile. Fixed the zk health-stat test to
  send the now-required profile_id.

Frontend:
- crypto/keys.ts: generateProfileDek, wrapProfileDek, unwrapProfileDek
  + in-memory per-profile DEK store with an active-profile concept.
- useProfileStore rewritten: holds profiles[], activeProfileId;
  loadProfiles unwraps each profile DEK; create/update/delete. All 11
  encrypt/decrypt sites switched from getEncKey() to
  getActiveProfileDek(). load actions pass ?profile_id= so only the
  active profile's rows come back.
- ProfileEditor rewritten for the new store (edit active profile,
  create/delete). New ProfileSwitcher in the Dashboard AppBar.
- MedicationManager / AppointmentsManager use the active profile id
  instead of the hardcoded profile_<user_id>.
- 2 new crypto tests for per-profile DEK isolation; updated store +
  component tests for the active-profile-DEK model.

Verification: backend cargo build/clippy/fmt green, tests compile
(integration tests run in CI — Mongo is fixed there). Frontend
tsc clean, 30/30 tests pass.

Closes nothing yet (Phase B/C/D remain). Refs #3.
2026-07-18 23:45:01 -03:00

117 lines
5.6 KiB
Rust

//! Router assembly. Extracted from `main.rs` so integration tests can build the
//! exact same app (routes, middleware, layers) in process against a test
//! database instead of a live server.
use axum::{
routing::{delete, get, post, put},
Router,
};
use tower::ServiceBuilder;
use tower_http::{cors::CorsLayer, trace::TraceLayer};
use crate::config::AppState;
use crate::handlers;
use crate::middleware;
/// Compose the full Axum app: all public + protected routes, the JWT auth
/// layer on protected routes, and the global middleware stack (client-IP
/// resolution, security headers, rate limit, tracing, CORS).
///
/// `main.rs` calls this and wraps it in `into_make_service_with_connect_info`
/// before serving; tests call it and drive it with `oneshot`/`RouterExt`.
pub fn build_app(state: AppState) -> Router {
// Build public routes (no auth required)
let public_routes = Router::new()
.route(
"/health",
get(handlers::health_check).head(handlers::health_check),
)
.route("/ready", get(handlers::ready_check))
.route("/api/auth/register", post(handlers::register))
.route("/api/auth/login", post(handlers::login))
.route("/api/auth/refresh", post(handlers::refresh))
.route("/api/auth/logout", post(handlers::logout))
.route(
"/api/auth/recover-password",
post(handlers::recover_password),
)
.route("/api/auth/recovery-info", get(handlers::recovery_info));
// Build protected routes (auth required)
let protected_routes = Router::new()
// User profile management
.route("/api/users/me", get(handlers::get_account))
.route("/api/users/me", put(handlers::update_account))
.route("/api/users/me", delete(handlers::delete_account))
.route("/api/users/me/change-password", post(handlers::change_password))
// User settings
.route("/api/users/me/settings", get(handlers::get_settings))
.route("/api/users/me/settings", put(handlers::update_settings))
// Share management
.route("/api/shares", post(handlers::create_share))
.route("/api/shares", get(handlers::list_shares))
.route("/api/shares/:id", put(handlers::update_share))
.route("/api/shares/:id", delete(handlers::delete_share))
// Permission checking
.route("/api/permissions/check", post(handlers::check_permission))
// Profile management (Phase A2: multi-profile + per-profile DEKs)
.route("/api/profiles", get(handlers::list_profiles))
.route("/api/profiles", post(handlers::create_profile))
.route("/api/profiles/:id", get(handlers::get_profile))
.route("/api/profiles/:id", put(handlers::update_profile))
.route("/api/profiles/:id", delete(handlers::delete_profile))
// Session management (Phase 2.6)
.route("/api/sessions", get(handlers::get_sessions))
.route("/api/sessions/:id", delete(handlers::revoke_session))
.route("/api/sessions/all", delete(handlers::revoke_all_sessions))
// Medication management (Phase 2.7)
.route("/api/medications", post(handlers::create_medication))
.route("/api/medications", get(handlers::list_medications))
.route("/api/medications/:id", get(handlers::get_medication))
.route("/api/medications/:id", post(handlers::update_medication))
.route("/api/medications/:id/delete", post(handlers::delete_medication))
.route("/api/medications/:id/log", post(handlers::log_dose))
.route("/api/medications/:id/adherence", get(handlers::get_adherence))
// Health statistics management (Phase 2.7)
.route("/api/health-stats", post(handlers::create_health_stat))
.route("/api/health-stats", get(handlers::list_health_stats))
.route("/api/health-stats/:id", get(handlers::get_health_stat))
.route("/api/health-stats/:id", put(handlers::update_health_stat))
.route("/api/health-stats/:id", delete(handlers::delete_health_stat))
// Drug interactions (Phase 2.8)
.route("/api/interactions/check", post(handlers::check_interactions))
.route("/api/interactions/check-new", post(handlers::check_new_medication))
// Appointments
.route("/api/appointments", post(handlers::create_appointment))
.route("/api/appointments", get(handlers::list_appointments))
.route("/api/appointments/:id", get(handlers::get_appointment))
.route("/api/appointments/:id", post(handlers::update_appointment))
.route("/api/appointments/:id/delete", post(handlers::delete_appointment))
.layer(axum::middleware::from_fn_with_state(
state.clone(),
middleware::jwt_auth_middleware,
));
public_routes
.merge(protected_routes)
.with_state(state.clone())
.layer(
ServiceBuilder::new()
// Resolve the client IP once and stash it for handlers/middleware
// (audit logging, account-lockout forensics).
.layer(axum::middleware::from_fn(
middleware::client_ip_middleware,
))
// Security headers (applies to all responses)
.layer(axum::middleware::from_fn(
middleware::security_headers_middleware,
))
// IP-based rate limiting (reads ClientIp from extensions).
.layer(axum::middleware::from_fn_with_state(
state.clone(),
middleware::general_rate_limit_middleware,
))
.layer(TraceLayer::new_for_http())
.layer(CorsLayer::permissive()),
)
}