Adds opt-in client-side-encrypted portfolio sync (paid). Browser
PBKDF2(PIN) → AES-GCM, server HKDF(pepper, user_id) outer wrap;
server stores opaque bytes only. Sliding-window rate limit on GET.
- new portfolio_sync table (migration 0015)
- POST/GET/DELETE /api/portfolio/sync + /status
- app/services/portfolio_sync.py crypto + rate limit
- app/routers/sync.py paid-gated
- app/static/js/portfolio-sync.js WebCrypto wrapper
- settings page: enable/disable + PIN modal
- PORTFOLIO_SYNC_PEPPER setting (warn on startup if missing)
Settings + import rework:
- /upload merged into /settings#import (legacy route 302s)
- drop CSV → auto-parse → preview → Import only / Import & sync
- nav slimmed to Dashboard / News / Log
- Settings + Logout moved to a user dropdown
- brand logo links to /
Collateral fixes:
- settings 500: re-fetch User in current session before mutating
referral_code (assign_code_if_missing was refreshing a User
loaded in the auth dep's now-closed session)
- csv_import: distinct error for unfunded T212 pies (all qty=0)
- db.py: drop pool_pre_ping (aiomysql 0.3.2 incompat); pin
isolation_level=READ COMMITTED to avoid gap-lock deadlocks
- alembic env: disable_existing_loggers=False so in-process
migrations don't silence uvicorn's loggers
- docker-compose.override.yml: dev-only volume mount + --reload
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
17 lines
800 B
YAML
17 lines
800 B
YAML
# Local-dev overlay. Auto-loaded by `docker compose up` (no -f flags needed),
|
|
# IGNORED on the VPS because prod uses explicit `-f docker-compose.yml -f
|
|
# docker-compose.prod.yml`. Keep dev-only conveniences here so the base
|
|
# `docker-compose.yml` stays prod-ready.
|
|
|
|
services:
|
|
app:
|
|
# Dev: mount the source over the image's copy so edits on the host
|
|
# land in the container without a rebuild; `--reload` restarts uvicorn
|
|
# when a file changes. Prod bakes the code into the image (Dockerfile)
|
|
# and uses the plain command from docker-compose.yml.
|
|
command: ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000",
|
|
"--workers", "1", "--reload", "--reload-dir", "/app/app"]
|
|
volumes:
|
|
- ./app:/app/app
|
|
ports:
|
|
- "${CASSANDRA_PORT:-8000}:8000"
|