This repository has been archived on 2026-06-09. You can view files and clone it, but cannot push or open issues or pull requests.
wedding-app/apps/api/pyproject.toml

38 lines
709 B
TOML
Raw Normal View History

feat: rewrite backend in Python (FastAPI + SQLAlchemy + boto3) Same routes, same Docker topology, same env vars. Frontend untouched. Backend swap: - Hono on Node -> FastAPI on Python 3.12, served by uvicorn behind Caddy. - Drizzle on Node -> SQLAlchemy 2.0 async (asyncpg driver) with declarative models that mirror the previous schema 1:1. Migrations are still plain SQL files (apps/api/app/migrations/) run idempotently at startup by app/db/migrate.py via asyncpg, tracking each file's sha256 in a schema_migrations table. - aws4fetch -> boto3 wrapped in asyncio.to_thread so the async routes do not block on MinIO/S3 calls. The presign_put / init_multipart / complete_multipart / head / delete contract is unchanged so the React client sees the same /api/uploads/* payloads. - Cookie+JWT admin auth -> pyjwt + FastAPI Cookie() dependency. constant-time password compare. Same 7-day HttpOnly cookie shape. - QR code: qrcode lib + reportlab. /api/qrcode keeps format=png|svg|pdf; the PDF is still A6 with the couple's names + 'Aponte a câmera' CTA. - Pydantic-settings replaces the zod env loader and still fails fast on missing required vars. Routes ported with identical paths and JSON shapes: - public: /api/event, /api/gallery, /api/qrcode, /api/stats - uploads: /api/uploads/init, /{id}/confirm, /{id}/abort - admin: /login, /logout, /me, /event (GET+PATCH), /uploads (GET with ?status, ?kind=photo|video, ?q= for search), /uploads/{id} (PATCH for author/message edit), /uploads/{id}/{approve,reject,cover}, /uploads/{id} (DELETE), /event/cover (DELETE), /uploads/bulk, /stats. Build pipeline: - Dockerfile: stage 1 builds the React/Vite SPA with pnpm; stage 2 is python:3.12-slim that installs deps via uv (fast, reproducible), copies the app/, and copies the SPA dist from stage 1 into /app/public so the FastAPI process serves both /api/* and the SPA assets. - docker-compose.yml unchanged: postgres + minio + minio-init + app + caddy. Same env vars (DATABASE_URL, S3_*, ADMIN_PASSWORD, SESSION_SECRET, ALLOWED_ADMIN_EMAILS, AUTO_MIGRATE). - Removed apps/api from the pnpm workspace; root package.json now only scripts the web. Makefile centralizes dev/build/docker commands so the Python side has the same DX as the Node side did.
2026-06-07 19:45:20 -03:00
[project]
name = "wedding-api"
version = "0.1.0"
description = "Backend for the wedding photos app"
requires-python = ">=3.12"
dependencies = [
"fastapi[standard]==0.115.5",
"uvicorn[standard]==0.32.1",
"sqlalchemy[asyncio]==2.0.36",
"asyncpg==0.30.0",
"boto3==1.35.66",
"qrcode[pil]==8.0",
"reportlab==4.2.5",
"pydantic-settings==2.6.1",
"pyjwt==2.10.0",
"email-validator==2.2.0",
feat: HEIC->JPEG transcoding and Postgres + MinIO backup sidecars HEIC handling - pillow-heif joins the deps; app/lib/transcode.py registers the HEIF opener and exposes heic_to_jpeg(bytes, quality=88) with EXIF rotation applied so portrait iPhone photos do not show sideways. - Storage gains get_bytes / put_bytes so the server can read the uploaded HEIC out of MinIO, decode it, and put a JPEG back. - /api/uploads/{id}/confirm now runs the transcode after the HEAD check passes when mime_type is image/heic or image/heif: writes the JPEG under a sibling key, deletes the HEIC, and updates the upload row's storage_key / mime_type / size_bytes. Failures fall back to keeping the HEIC so an upload is never lost in transit; the admin can re-upload if a particular file is unrenderable. Backups (two sidecars in docker-compose.yml) - postgres-backup uses prodrigestivill/postgres-backup-local:16-alpine with BACKUP_SCHEDULE_DB (default @daily) and layered retention (days/weeks/months) writing to ./backups/postgres on the host. - media-backup is an alpine container that pulls mc on boot, sets up an alias for the in-cluster MinIO, optionally adds a remote alias (R2/B2/S3 via BACKUP_REMOTE_*), and runs mc mirror on a configurable cron schedule. Local mirror always; remote mirror only when BACKUP_REMOTE_* are set. - Both write to ./backups/ on the host (bind mount), so the operator can rsync the directory off-box without touching containers. - .env.example documents every new variable, including a R2 example for the remote target, and TZ for cron alignment. Local backups directory is .gitignore'd so accidental commits do not ship someone else's wedding photos to GitHub.
2026-06-07 19:50:29 -03:00
"pillow-heif==0.21.0",
feat: rewrite backend in Python (FastAPI + SQLAlchemy + boto3) Same routes, same Docker topology, same env vars. Frontend untouched. Backend swap: - Hono on Node -> FastAPI on Python 3.12, served by uvicorn behind Caddy. - Drizzle on Node -> SQLAlchemy 2.0 async (asyncpg driver) with declarative models that mirror the previous schema 1:1. Migrations are still plain SQL files (apps/api/app/migrations/) run idempotently at startup by app/db/migrate.py via asyncpg, tracking each file's sha256 in a schema_migrations table. - aws4fetch -> boto3 wrapped in asyncio.to_thread so the async routes do not block on MinIO/S3 calls. The presign_put / init_multipart / complete_multipart / head / delete contract is unchanged so the React client sees the same /api/uploads/* payloads. - Cookie+JWT admin auth -> pyjwt + FastAPI Cookie() dependency. constant-time password compare. Same 7-day HttpOnly cookie shape. - QR code: qrcode lib + reportlab. /api/qrcode keeps format=png|svg|pdf; the PDF is still A6 with the couple's names + 'Aponte a câmera' CTA. - Pydantic-settings replaces the zod env loader and still fails fast on missing required vars. Routes ported with identical paths and JSON shapes: - public: /api/event, /api/gallery, /api/qrcode, /api/stats - uploads: /api/uploads/init, /{id}/confirm, /{id}/abort - admin: /login, /logout, /me, /event (GET+PATCH), /uploads (GET with ?status, ?kind=photo|video, ?q= for search), /uploads/{id} (PATCH for author/message edit), /uploads/{id}/{approve,reject,cover}, /uploads/{id} (DELETE), /event/cover (DELETE), /uploads/bulk, /stats. Build pipeline: - Dockerfile: stage 1 builds the React/Vite SPA with pnpm; stage 2 is python:3.12-slim that installs deps via uv (fast, reproducible), copies the app/, and copies the SPA dist from stage 1 into /app/public so the FastAPI process serves both /api/* and the SPA assets. - docker-compose.yml unchanged: postgres + minio + minio-init + app + caddy. Same env vars (DATABASE_URL, S3_*, ADMIN_PASSWORD, SESSION_SECRET, ALLOWED_ADMIN_EMAILS, AUTO_MIGRATE). - Removed apps/api from the pnpm workspace; root package.json now only scripts the web. Makefile centralizes dev/build/docker commands so the Python side has the same DX as the Node side did.
2026-06-07 19:45:20 -03:00
]
[project.optional-dependencies]
dev = [
"ruff==0.7.4",
"mypy==1.13.0",
"pytest==8.3.3",
"httpx==0.27.2",
]
[tool.ruff]
line-length = 100
target-version = "py312"
[tool.ruff.lint]
select = ["E", "F", "I", "UP", "B", "ASYNC"]
ignore = ["E501"]
[tool.uv]
package = false