diff --git a/.gitignore b/.gitignore index e8ed22a..2281ef2 100644 --- a/.gitignore +++ b/.gitignore @@ -54,3 +54,7 @@ next-env.d.ts # Datenbank-Sicherungen (enthalten Personendaten) – nie committen. .backups/ + +# Datenabzuege aus dem Umzug – enthalten Personendaten +supabase-daten-*.sql +supabase-voll-*.sql diff --git a/docker-compose.traefik.yml b/docker-compose.traefik.yml new file mode 100644 index 0000000..25978db --- /dev/null +++ b/docker-compose.traefik.yml @@ -0,0 +1,22 @@ +services: + app: + # Entfernt die Portfreigabe aus der ursprünglichen Datei + ports: !reset [] + + networks: + - proxy + - default + + labels: + traefik.enable: "true" + traefik.docker.network: proxy + traefik.http.routers.alpenwerk.rule: "Host(`${HOST}`)" + traefik.http.routers.alpenwerk.entrypoints: websecure + traefik.http.routers.alpenwerk.tls: "true" + traefik.http.routers.alpenwerk.tls.certresolver: letsencrypt + traefik.http.services.alpenwerk.loadbalancer.server.port: "3000" + +networks: + proxy: + external: true + name: proxy diff --git a/supabase/migrations/20260826120000_anwendungsrolle_rechte.sql b/supabase/migrations/20260826120000_anwendungsrolle_rechte.sql new file mode 100644 index 0000000..89d86ed --- /dev/null +++ b/supabase/migrations/20260826120000_anwendungsrolle_rechte.sql @@ -0,0 +1,73 @@ +-- Rechte der Anwendungsrolle alpenwerk_app. +-- +-- Auf Supabase wurden diese Rechte von Hand im Dashboard vergeben und standen +-- deshalb in keiner Migration. Beim Umzug in einen eigenen Container fiel das +-- auf: das Schema entstand vollstaendig aus den Migrationen, die Rolle hatte +-- aber weder Tabellen- noch Funktionsrechte — die Anwendung scheiterte mit +-- "permission denied for table profiles", bevor die Anmeldeseite erschien. +-- +-- Ohne diese Datei laesst sich das Projekt auf einer leeren Datenbank nicht +-- in Betrieb nehmen. Genau das ist aber das Ziel: ein Container, den der +-- Kunde selbst hochfaehrt. +-- +-- Die Rolle bleibt **ohne BYPASSRLS**. Diese Rechte sagen nur, welche Objekte +-- sie ueberhaupt anfassen darf; welche Zeilen sie sieht, entscheiden weiterhin +-- die 58 RLS-Policies. + +-- ── Tabellen und Sequenzen ──────────────────────────────────────────── +grant select, insert, update, delete on all tables in schema public to alpenwerk_app; +grant usage, select, update on all sequences in schema public to alpenwerk_app; + +-- Damit kuenftige Migrationen mit neuen Tabellen nicht dieselbe Panne +-- ausloesen. +alter default privileges in schema public grant select, insert, update, delete on tables to alpenwerk_app; +alter default privileges in schema public grant usage, select, update on sequences to alpenwerk_app; + +-- ── Funktionen ──────────────────────────────────────────────────────── +-- Bewusst die einzeln aufgezaehlte Liste aus dem Supabase-Bestand und kein +-- pauschales "on all routines": 20260727150000 hat EXECUTE bei einem Teil der +-- SECURITY-DEFINER-Funktionen absichtlich entzogen. Eine Pauschalvergabe +-- machte das rueckgaengig. +grant execute on function public.add_employee_dependent(payload jsonb) to alpenwerk_app; +grant execute on function public.add_employee_note(payload jsonb) to alpenwerk_app; +grant execute on function public.adjust_karenz_return(payload jsonb) to alpenwerk_app; +grant execute on function public.app_aenderung(p_liste jsonb, p_feld text, p_vorher text, p_nachher text) to alpenwerk_app; +grant execute on function public.app_aenderungsfelder(p_liste jsonb) to alpenwerk_app; +grant execute on function public.app_current_user_id() to alpenwerk_app; +grant execute on function public.app_feld_karte() to alpenwerk_app; +grant execute on function public.app_upsert_user(p_external_id text, p_email text, p_full_name text) to alpenwerk_app; +grant execute on function public.apply_due_pending_changes() to alpenwerk_app; +grant execute on function public.change_employee_data(payload jsonb) to alpenwerk_app; +grant execute on function public.complete_employee_note(payload jsonb) to alpenwerk_app; +grant execute on function public.create_position(payload jsonb) to alpenwerk_app; +grant execute on function public.current_actor_name() to alpenwerk_app; +grant execute on function public.current_hr_user_id() to alpenwerk_app; +grant execute on function public.delete_employee_dependent(payload jsonb) to alpenwerk_app; +grant execute on function public.delete_history_entry(payload jsonb) to alpenwerk_app; +grant execute on function public.delete_position(payload jsonb) to alpenwerk_app; +grant execute on function public.fn_check_history_not_before_entry() to alpenwerk_app; +grant execute on function public.fn_touch_profiles_updated_at() to alpenwerk_app; +grant execute on function public.fn_touch_updated_at() to alpenwerk_app; +grant execute on function public.fn_validate_employee_svnr() to alpenwerk_app; +grant execute on function public.generate_company_email(p_first_name text, p_last_name text) to alpenwerk_app; +grant execute on function public.hire_employee(payload jsonb) to alpenwerk_app; +grant execute on function public.is_hr_admin() to alpenwerk_app; +grant execute on function public.is_hr_user() to alpenwerk_app; +grant execute on function public.is_valid_svnr(p_svnr text, p_birth_date date) to alpenwerk_app; +grant execute on function public.next_position_number() to alpenwerk_app; +grant execute on function public.om_reporting_lines(p_as_of date) to alpenwerk_app; +grant execute on function public.promote_employee(payload jsonb) to alpenwerk_app; +grant execute on function public.record_karenz_return(payload jsonb) to alpenwerk_app; +grant execute on function public.rehire_employee(payload jsonb) to alpenwerk_app; +grant execute on function public.require_hr_admin() to alpenwerk_app; +grant execute on function public.rls_auto_enable() to alpenwerk_app; +grant execute on function public.set_offboarding_task(payload jsonb) to alpenwerk_app; +grant execute on function public.set_onboarding_task(payload jsonb) to alpenwerk_app; +grant execute on function public.set_position_cost_center(payload jsonb) to alpenwerk_app; +grant execute on function public.start_karenz(payload jsonb) to alpenwerk_app; +grant execute on function public.start_offboarding(payload jsonb) to alpenwerk_app; +grant execute on function public.start_onboarding(payload jsonb) to alpenwerk_app; +grant execute on function public.terminate_employee(payload jsonb) to alpenwerk_app; +grant execute on function public.transfer_employee(payload jsonb) to alpenwerk_app; +grant execute on function public.update_history_entry(payload jsonb) to alpenwerk_app; +grant execute on function public.update_position(payload jsonb) to alpenwerk_app;