Sets up the project skeleton: - FastAPI app factory with lifespan, request-id middleware, and RFC 9457 problem+json error handlers - Async SQLAlchemy 2.0 over MySQL (asyncmy), with a constraint naming convention in place before the first migration and async Alembic - Keycloak as a pure resource server: OIDC discovery, cached JWKS with rotation-aware refresh, and require_roles dependencies - Devcontainer running MySQL 8.4 and Keycloak 26.7 as compose siblings, with the realm (clients, roles, test users) imported on first boot - Test suite covering the endpoints plus the token validator itself, exercised against a locally generated RSA keypair - uv packaging, ruff, mypy --strict, pre-commit, Gitea CI, prod Dockerfile Two Keycloak-in-containers traps are handled explicitly and documented in the README: the issuer/internal-URL split (the browser sees localhost:8080, the API sees keycloak:8080) and the audience mapper that stops Keycloak issuing tokens with aud=account. The devices resource is a placeholder proving the routing -> auth -> ORM -> migration path end to end; replace it with the real domain. Co-Authored-By: Claude Opus 5 <[email protected]>
92 lines
1.9 KiB
TOML
92 lines
1.9 KiB
TOML
[project]
|
|
name = "v2x-server"
|
|
version = "0.1.0"
|
|
description = "FastAPI service backed by MySQL with Keycloak-issued OIDC authentication."
|
|
readme = "README.md"
|
|
requires-python = ">=3.13"
|
|
dependencies = [
|
|
"fastapi>=0.115",
|
|
"uvicorn[standard]>=0.32",
|
|
"gunicorn>=23.0",
|
|
"sqlalchemy[asyncio]>=2.0.36",
|
|
"asyncmy>=0.2.10",
|
|
"alembic>=1.14",
|
|
"pydantic>=2.10",
|
|
"pydantic-settings>=2.7",
|
|
"pyjwt[crypto]>=2.10",
|
|
"httpx>=0.28",
|
|
"python-json-logger>=3.2",
|
|
]
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
"pytest>=8.3",
|
|
"pytest-asyncio>=0.25",
|
|
"pytest-cov>=6.0",
|
|
"mypy>=1.14",
|
|
"ruff>=0.9",
|
|
"pre-commit>=4.0",
|
|
"types-pyyaml>=6.0",
|
|
]
|
|
|
|
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/v2x_server"]
|
|
|
|
[tool.uv]
|
|
default-groups = ["dev"]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py313"
|
|
src = ["src", "tests"]
|
|
|
|
[tool.ruff.lint]
|
|
select = [
|
|
"E", # pycodestyle errors
|
|
"W", # pycodestyle warnings
|
|
"F", # pyflakes
|
|
"I", # isort
|
|
"B", # flake8-bugbear
|
|
"C4", # flake8-comprehensions
|
|
"UP", # pyupgrade
|
|
"ASYNC",# flake8-async
|
|
"S", # flake8-bandit
|
|
"T20", # flake8-print
|
|
"SIM", # flake8-simplify
|
|
"RUF",
|
|
]
|
|
ignore = [
|
|
"S101", # assert is fine (pytest)
|
|
]
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
"tests/**" = ["S105", "S106"] # hardcoded test credentials are expected
|
|
"migrations/**" = ["I001"]
|
|
|
|
[tool.mypy]
|
|
python_version = "3.13"
|
|
strict = true
|
|
warn_unreachable = true
|
|
plugins = ["pydantic.mypy"]
|
|
mypy_path = "src"
|
|
packages = ["v2x_server"]
|
|
|
|
[[tool.mypy.overrides]]
|
|
module = ["asyncmy.*", "alembic.*"]
|
|
ignore_missing_imports = true
|
|
|
|
[tool.pytest.ini_options]
|
|
asyncio_mode = "auto"
|
|
asyncio_default_fixture_loop_scope = "session"
|
|
testpaths = ["tests"]
|
|
addopts = "-ra --strict-markers"
|
|
filterwarnings = ["error"]
|
|
|
|
[tool.coverage.run]
|
|
source = ["src/v2x_server"]
|
|
branch = true
|