New-client onboarding: provision resources/services/owner login, drop EA (#24)
Test backoffice (smb-crm) / test (push) Has been cancelled
Test backoffice (smb-crm) / test (push) Has been cancelled
n8n/onboarding.json now provisions a default resource (with Mon-Sat 09:00-18:00 hours so the public booking page has slots immediately), a starter service, and an owner-login user for every new client, recording the temp password via the existing credentials CRM entity -- gated behind an If check so a failed user creation can't leave a stale credentials row. The EA-provisioning chain (service/provider creation against Easy!Appointments) is removed entirely. Adds POST /api/resources, /api/services, /api/owner_users to the backoffice API for n8n to call, backed by booking_db.py's existing tenancy-safe create_* helpers. Also adds "slug" to db.py's clients column list -- it was already a DB column (#17) but the generic /api/clients POST silently dropped it, so onboarding could never actually set a client's public-facing slug. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+75
-1
@@ -7,7 +7,7 @@ machine-to-machine ingest path (n8n) is gated by the CRM_API_TOKEN header.
|
||||
import os
|
||||
import re
|
||||
import time
|
||||
from datetime import datetime, date, timezone
|
||||
from datetime import datetime, date, time as dtime, timezone
|
||||
from decimal import Decimal
|
||||
|
||||
from flask import Flask, jsonify, request, Response
|
||||
@@ -209,6 +209,80 @@ def delete_entity(entity, ident):
|
||||
return jsonify({"deleted": ident})
|
||||
|
||||
|
||||
def _parse_hours_time(value):
|
||||
try:
|
||||
return dtime.fromisoformat(str(value))
|
||||
except (TypeError, ValueError):
|
||||
return None
|
||||
|
||||
|
||||
@app.post("/api/resources")
|
||||
def create_resource_route():
|
||||
"""Onboarding provisioning (#24): a default bookable resource for a new
|
||||
client, with opening hours set inline so the public /book/<slug> page has
|
||||
a slot grid to show immediately -- a resource without resource_hours has
|
||||
no available slots (booking_api._available_slots)."""
|
||||
if not authed():
|
||||
return jsonify({"error": "forbidden"}), 403
|
||||
body = request.get_json(force=True, silent=True) or {}
|
||||
client_id = body.get("client_id")
|
||||
name = (body.get("name") or "").strip()
|
||||
if not client_id or not name:
|
||||
return jsonify({"error": "client_id and name required"}), 400
|
||||
row = bdb.create_resource(client_id, name)
|
||||
for h in body.get("hours") or []:
|
||||
opens_at = _parse_hours_time(h.get("opens_at"))
|
||||
closes_at = _parse_hours_time(h.get("closes_at"))
|
||||
if opens_at is None or closes_at is None:
|
||||
continue
|
||||
bdb.set_resource_hours(client_id, row["resource_id"], h.get("weekday"),
|
||||
opens_at, closes_at)
|
||||
with db.connect() as conn, conn.cursor() as cur:
|
||||
log_activity(cur, client_id, "add resource", f"resource_id={row['resource_id']}")
|
||||
conn.commit()
|
||||
return jsonify({"resource_id": row["resource_id"]}), 201
|
||||
|
||||
|
||||
@app.post("/api/services")
|
||||
def create_service_route():
|
||||
"""Onboarding provisioning (#24): a starter service for a new client."""
|
||||
if not authed():
|
||||
return jsonify({"error": "forbidden"}), 403
|
||||
body = request.get_json(force=True, silent=True) or {}
|
||||
client_id = body.get("client_id")
|
||||
name = (body.get("name") or "").strip()
|
||||
duration_minutes = body.get("duration_minutes")
|
||||
if not client_id or not name or not duration_minutes:
|
||||
return jsonify({"error": "client_id, name and duration_minutes required"}), 400
|
||||
row = bdb.create_service(client_id, name, duration_minutes, price=body.get("price"))
|
||||
with db.connect() as conn, conn.cursor() as cur:
|
||||
log_activity(cur, client_id, "add service", f"service_id={row['service_id']}")
|
||||
conn.commit()
|
||||
return jsonify({"service_id": row["service_id"]}), 201
|
||||
|
||||
|
||||
@app.post("/api/owner_users")
|
||||
def create_owner_user_route():
|
||||
"""Onboarding provisioning (#24): the owner's login for a new client, with
|
||||
a temp password the caller (n8n) is expected to record via the
|
||||
credentials CRM entity, same as it did for the retired EA login."""
|
||||
if not authed():
|
||||
return jsonify({"error": "forbidden"}), 403
|
||||
body = request.get_json(force=True, silent=True) or {}
|
||||
client_id = body.get("client_id")
|
||||
email = (body.get("email") or "").strip().lower()
|
||||
password = body.get("password") or ""
|
||||
if not client_id or not email or not password:
|
||||
return jsonify({"error": "client_id, email and password required"}), 400
|
||||
if bdb.find_user_by_email(email) is not None:
|
||||
return jsonify({"error": "email already in use"}), 409
|
||||
row = bdb.create_user(client_id, email, password)
|
||||
with db.connect() as conn, conn.cursor() as cur:
|
||||
log_activity(cur, client_id, "add owner user", f"user_id={row['user_id']}")
|
||||
conn.commit()
|
||||
return jsonify({"user_id": row["user_id"]}), 201
|
||||
|
||||
|
||||
@app.get("/api/owner_users")
|
||||
def list_owner_users():
|
||||
"""Owner-accounts list for the CRM dashboard's new tab (#19). Requires
|
||||
|
||||
@@ -20,7 +20,7 @@ TABLES = {
|
||||
"cols": ["client_id", "business_name", "owner_name", "email", "phone",
|
||||
"niche", "tier", "status", "domain", "stack_notes", "vault_ref",
|
||||
"services", "billing_cycle", "monthly_fee_eur", "start_date",
|
||||
"renewal_date", "created_at", "notes", "notify_channel"],
|
||||
"renewal_date", "created_at", "notes", "notify_channel", "slug"],
|
||||
"dates": ["start_date", "renewal_date"],
|
||||
"timestamps": ["created_at"],
|
||||
"numbers": ["monthly_fee_eur"],
|
||||
|
||||
@@ -0,0 +1,124 @@
|
||||
"""Flask test client / real-DB integration tests for the onboarding
|
||||
provisioning endpoints (#24): POST /api/resources, /api/services, and
|
||||
/api/owner_users, used by n8n/onboarding.json in place of the retired EA
|
||||
provider-account chain.
|
||||
"""
|
||||
import pytest
|
||||
|
||||
import app as app_module
|
||||
import booking_db as bdb
|
||||
from app import app as flask_app
|
||||
|
||||
CLIENT_A = "C-TEST-PROV-A"
|
||||
CLIENT_B = "C-TEST-PROV-B"
|
||||
AUTH = {"X-CRM-Token": "test-crm-token"}
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def client(monkeypatch):
|
||||
flask_app.config["TESTING"] = True
|
||||
monkeypatch.setattr(app_module, "CRM_TOKEN", "test-crm-token")
|
||||
return flask_app.test_client()
|
||||
|
||||
|
||||
def _insert_client(client_id):
|
||||
with bdb.db.connect() as conn, conn.cursor() as cur:
|
||||
cur.execute(
|
||||
"INSERT INTO clients (client_id, business_name) VALUES (%s, %s) "
|
||||
"ON CONFLICT (client_id) DO NOTHING",
|
||||
(client_id, "Café " + client_id))
|
||||
conn.commit()
|
||||
|
||||
|
||||
# ---- /api/clients slug (generic entity POST, #24) ----
|
||||
|
||||
def test_create_client_persists_slug(client):
|
||||
resp = client.post("/api/clients", headers=AUTH, json={
|
||||
"business_name": "Slug Test Client", "slug": "slug-test-abcd"})
|
||||
assert resp.status_code == 201
|
||||
client_id = resp.get_json()["added"]
|
||||
assert bdb.get_client_by_slug("slug-test-abcd")["client_id"] == client_id
|
||||
|
||||
|
||||
# ---- /api/resources ----
|
||||
|
||||
def test_create_resource_requires_crm_token(client):
|
||||
resp = client.post("/api/resources", json={"client_id": CLIENT_A, "name": "Hauptressource"})
|
||||
assert resp.status_code == 403
|
||||
|
||||
|
||||
def test_create_resource_sets_hours(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/resources", headers=AUTH, json={
|
||||
"client_id": CLIENT_A, "name": "Hauptressource",
|
||||
"hours": [{"weekday": 0, "opens_at": "09:00", "closes_at": "18:00"}]})
|
||||
assert resp.status_code == 201
|
||||
resource_id = resp.get_json()["resource_id"]
|
||||
hours = bdb.get_resource_hours(CLIENT_A, resource_id)
|
||||
assert 0 in hours
|
||||
|
||||
|
||||
def test_create_resource_requires_name(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/resources", headers=AUTH, json={"client_id": CLIENT_A})
|
||||
assert resp.status_code == 400
|
||||
|
||||
|
||||
# ---- /api/services ----
|
||||
|
||||
def test_create_service_requires_crm_token(client):
|
||||
resp = client.post("/api/services", json={
|
||||
"client_id": CLIENT_A, "name": "Termin", "duration_minutes": 30})
|
||||
assert resp.status_code == 403
|
||||
|
||||
|
||||
def test_create_service_creates_active_service(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/services", headers=AUTH, json={
|
||||
"client_id": CLIENT_A, "name": "Termin", "duration_minutes": 30})
|
||||
assert resp.status_code == 201
|
||||
service_id = resp.get_json()["service_id"]
|
||||
row = bdb.get_service(CLIENT_A, service_id)
|
||||
assert row["active"] is True
|
||||
assert row["duration_minutes"] == 30
|
||||
|
||||
|
||||
def test_create_service_requires_duration(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/services", headers=AUTH,
|
||||
json={"client_id": CLIENT_A, "name": "Termin"})
|
||||
assert resp.status_code == 400
|
||||
|
||||
|
||||
# ---- /api/owner_users ----
|
||||
|
||||
def test_create_owner_user_requires_crm_token(client):
|
||||
resp = client.post("/api/owner_users", json={
|
||||
"client_id": CLIENT_A, "email": "owner@example.com", "password": "pw12345"})
|
||||
assert resp.status_code == 403
|
||||
|
||||
|
||||
def test_create_owner_user_creates_login(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/owner_users", headers=AUTH, json={
|
||||
"client_id": CLIENT_A, "email": "owner@example.com", "password": "pw12345"})
|
||||
assert resp.status_code == 201
|
||||
user = bdb.find_user_by_email("owner@example.com")
|
||||
assert user["client_id"] == CLIENT_A
|
||||
assert bdb.verify_password(user, "pw12345")
|
||||
|
||||
|
||||
def test_create_owner_user_rejects_duplicate_email(client):
|
||||
_insert_client(CLIENT_A)
|
||||
_insert_client(CLIENT_B)
|
||||
bdb.create_user(CLIENT_A, "owner@example.com", "pw12345")
|
||||
resp = client.post("/api/owner_users", headers=AUTH, json={
|
||||
"client_id": CLIENT_B, "email": "owner@example.com", "password": "pw67890"})
|
||||
assert resp.status_code == 409
|
||||
|
||||
|
||||
def test_create_owner_user_requires_password(client):
|
||||
_insert_client(CLIENT_A)
|
||||
resp = client.post("/api/owner_users", headers=AUTH,
|
||||
json={"client_id": CLIENT_A, "email": "owner@example.com"})
|
||||
assert resp.status_code == 400
|
||||
Reference in New Issue
Block a user