Files
chatballs/apps/backend/hub_platform/platform/errors.py
T
Andrey 549d1faada ✨ feat(platform): implement C06 tenant provisioning and Platform API
Single idempotent write boundary provision_organization coordinates
Organization, OWNER membership or invitation, subscription/usage,
system departments sales/support, audit and transactional outbox in one
transaction under set_local_tenant.

- New hub_platform.platform domain: PlatformOperator, hash-only
  PlatformToken, OrganizationProvisioning process record with state
  machine PENDING/IN_PROGRESS/WAITING_FOR_OWNER/COMPLETED/FAILED.
- Platform API POST platform.custocrm.ru/api/v1/organizations: machine
  token auth + capability platform.organizations.provision, Idempotency-Key
  header, replay/conflict handling, no secrets in response.
- OWNER invitation accept (accept_invitation + auth view) activates
  organization, subscription and first usage period; idempotent re-accept
  does not duplicate membership or period.
- DB write boundary (tenancy/0005): platform INSERT/UPDATE on
  identity_organization and platform DML + tenant-isolation policy on
  identity_department/identity_employeeprofile; Organization.status
  ACTIVE/PENDING_OWNER (identity/0015).
- System department codes centralised in identity/system_departments.

Machine token without MFA is an owner-approved deviation from
ADR-HUB-0031 section 9; human+MFA platform login belongs to track D.
concurrent_p2p_calls derived from membership count is a separate C07
decision (PLAN-CUSTOCRM-0003 section 12).

Gate: idempotent replay creates no second tenant; operator never becomes
OWNER; provisioning creates no AI-agent/product/connection/demo data.

Full backend regression 379 passed (one pre-existing unrelated SOCKS5
test); 19 C06 targeted tests passed. UI unchanged. Production
migration/deploy, publication of production PlanVersion and bootstrap of
the production platform token are not part of this commit.
2026-07-15 16:58:32 +03:00

24 lines
529 B
Python

from __future__ import annotations
class ProvisioningError(Exception):
"""Base class for provisioning domain errors. message is safe to expose."""
status_code: int = 400
def __init__(self, message: str, *, code: str = "") -> None:
super().__init__(message)
self.code = code
class ProvisioningConflict(ProvisioningError):
status_code = 409
class ProvisioningValidation(ProvisioningError):
status_code = 400
class ProvisioningOwnerUnavailable(ProvisioningError):
status_code = 422