Show registration credentials in client business structure
This commit is contained in:
@@ -12,10 +12,29 @@ from app.modules.clients.models import Client, ClientBusinessUnit, ClientBranch
|
||||
from app.modules.registrations.models import ClientRegistration, RegistrationType
|
||||
from app.modules.core.rbac.deps import get_user_permissions, get_user_roles
|
||||
from app.modules.core.rbac.permission_guard import require_permission
|
||||
from app.modules.credential_vault.models import CredentialVaultEntry
|
||||
from app.modules.credential_vault.service import can_manage_vault, can_open_vault, can_view_entry
|
||||
|
||||
router = APIRouter(prefix="/clients", tags=["client-business-structure"])
|
||||
|
||||
|
||||
CREDENTIAL_CATEGORY_LABELS = {
|
||||
"gst_portal": "GST Portal",
|
||||
"income_tax_portal": "Income Tax Portal",
|
||||
"traces_tds": "TRACES / TDS",
|
||||
"mca_portal": "MCA Portal",
|
||||
"eway_bill": "E-Way Bill",
|
||||
"einvoice": "E-Invoice",
|
||||
"government_portal": "Government / Registration Portal",
|
||||
"banking": "Banking",
|
||||
"email": "Email",
|
||||
"software": "Software",
|
||||
"api_key": "API / Provider",
|
||||
"digital_signature": "Digital Signature / Token",
|
||||
"other": "Other",
|
||||
}
|
||||
|
||||
|
||||
def _tenant_id(request, user):
|
||||
return int(request.session.get("active_tenant_id") or request.session.get("tenant_id") or user.tenant_id)
|
||||
|
||||
@@ -66,11 +85,45 @@ def business_structure_page(request: Request, client_id: int):
|
||||
RegistrationType.sort_order, RegistrationType.name
|
||||
)
|
||||
).scalars().all()
|
||||
|
||||
# Credential Vault stays the single source of truth. This page only surfaces
|
||||
# metadata/actions for credentials linked to the registration rows the user can
|
||||
# already see; encrypted values are never decrypted here.
|
||||
registration_credentials: dict[int, list[CredentialVaultEntry]] = {row.id: [] for row in registrations}
|
||||
can_open_credentials = can_open_vault(db, user)
|
||||
can_manage_credentials = can_manage_vault(db, user)
|
||||
if registrations and can_open_credentials:
|
||||
registration_ids = [int(row.id) for row in registrations]
|
||||
credential_rows = db.execute(
|
||||
select(CredentialVaultEntry).where(
|
||||
CredentialVaultEntry.tenant_id == client.tenant_id,
|
||||
CredentialVaultEntry.client_id == client.id,
|
||||
CredentialVaultEntry.registration_id.in_(registration_ids),
|
||||
).order_by(
|
||||
CredentialVaultEntry.status,
|
||||
CredentialVaultEntry.category,
|
||||
CredentialVaultEntry.title,
|
||||
)
|
||||
).scalars().all()
|
||||
raw_active_branch_id = request.session.get("active_branch_id")
|
||||
active_branch_id = (
|
||||
int(raw_active_branch_id)
|
||||
if raw_active_branch_id not in (None, "", 0, "0")
|
||||
else getattr(user, "branch_id", None)
|
||||
)
|
||||
for credential in credential_rows:
|
||||
if can_view_entry(db, user, credential, active_branch_id):
|
||||
registration_credentials.setdefault(int(credential.registration_id), []).append(credential)
|
||||
|
||||
return templates.TemplateResponse(
|
||||
"modules/clients/templates/clients/business_structure.html",
|
||||
_context(request, db, user, title="Client Business Structure", client=client,
|
||||
businesses=businesses, branches=branches, registrations=registrations,
|
||||
registration_type_codes=registration_type_codes, registration_types=registration_types,
|
||||
registration_credentials=registration_credentials,
|
||||
credential_category_labels=CREDENTIAL_CATEGORY_LABELS,
|
||||
can_open_credentials=can_open_credentials,
|
||||
can_manage_credentials=can_manage_credentials,
|
||||
can_edit="clients.edit" in set(get_user_permissions(db, user.id))),
|
||||
)
|
||||
finally:
|
||||
|
||||
Reference in New Issue
Block a user