Andrey 092553941f feat(support): verify product support token and start session
SPEC-HUB-0011 §12 (алгоритм start) + §14 (error model).

- token.py: HS256 JWT verify через stdlib (hmac/hashlib/base64), envelope claims
  (iss/aud/contract/iat/exp/jti/data). RS256/EdDSA — TODO.
- jsonpath.py: ограниченный JSONPath-subset ($.field, $.a.b, $.arr[0].field).
- session.py: verify_and_resolve (channel policy → token → contract → schema →
  identity/operator/ai/search extraction) + start_support_session (snapshot upsert,
  create-or-continue conversation, audit success/denied). Raw token не сохраняется
  и не логируется — только хэш jti.
- errors.py: машинные коды (TOKEN_*, CONTRACT_*, PAYLOAD_SCHEMA_INVALID, ...) +
  SupportSessionError; публичное сообщение безопасное.
- services.py: register_contract / set_contract_status (зеркало products).
- selectors.py / serializers.py / views.py / urls.py: CRUD контрактов (IsOwner),
  POST /api/v1/support/sessions/ (AllowAny, продукт→Hub), snapshot-by-subject.
- Публичный error envelope {error, message} для start (как OrderIngestView).
2026-07-09 00:55:03 +03:00
2026-07-05 04:32:13 +03:00
2026-06-26 15:10:36 +03:00
2026-06-26 15:10:36 +03:00
2026-06-17 18:14:16 +03:00
2026-06-17 18:41:41 +03:00
2026-06-26 15:10:36 +03:00
2026-06-26 15:10:36 +03:00

Edevs Hub

Canonical implementation workspace for hub.edevs.tech.

Local start

Copy-Item .env.example .env
.\scripts\start.ps1

The local compose stack contains:

  • Django ASGI backend and background worker;
  • PostgreSQL;
  • Redis;
  • Internal Hub UI;
  • Web Chat UI;
  • local Nginx reverse proxy.

No production secrets are stored in the repository.

Default local URLs:

  • Internal Hub UI: http://localhost:5173
  • Django admin: http://localhost:8010/admin/
  • Web Chat: http://localhost:5175
  • Backend API: http://localhost:8010/api/v1

Local accounts (TOTP disabled). These credentials are fixed — do not change them:

  • OWNER — owner@edevs.tech / Owner-Local-2026
  • OPERATOR — a.kotova@edevs.tech / Operator-Local-2026

Bootstrap the organization and both accounts:

docker compose run --rm backend python manage.py bootstrap_owner --email owner@edevs.tech --password Owner-Local-2026 --name "Иван Петров"

Tests

All suites run in Docker, so no manual environment is required — the test runners auto-detect themselves and relax production hardening (secret-key fail-fast, SSL redirect, throttling) for the duration of the run.

Run everything (backend tests, frontend unit tests, typechecks):

.\scripts\check.ps1

Individual suites:

# Backend (pytest + pytest-django)
docker compose run --rm backend pytest

# Frontend unit tests (vitest)
docker compose run --rm internal-ui npm run test

# End-to-end (Playwright, internal-ui) — auto-starts the dev server
npx playwright install chromium   # one-time
npx playwright test --project=internal-ui

Backend pytest configuration lives in apps/backend/pytest.ini (it must sit next to manage.py so it is also visible inside the backend container).

Languages
Python 54.4%
TypeScript 35.6%
CSS 8.2%
Shell 0.8%
JavaScript 0.6%
Other 0.3%