Initial commit: PESCO NCR system
Complete Non-Conformance Report system replacing the PowerApps/SharePoint
prototype: FastAPI + SQLAlchemy 2 (async) + Alembic + MySQL 8 backend,
React 18 + Vite + TypeScript + MUI frontend, Entra ID auth (MSAL / JWKS,
group-gated), Microsoft Graph delegated Mail.Send notifications (OBO),
six-stage workflow state machine with server-side enforcement, atomic
NCR-YYYY-NNNN numbering, attachments with camera capture, immutable
field-level audit trail, admin reopen, reports + CSV export, WeasyPrint
PDF traveler, Power BI reporting views + read-only DB user, documented
VISUAL ERP job-lookup stub, pytest suite (26 tests), docker-compose
deployment.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 11:41:22 -06:00
|
|
|
#!/bin/bash
|
|
|
|
|
# Runs once, on first initialization of the MySQL data volume.
|
|
|
|
|
# Creates the read-only reporting account used by the Power BI gateway.
|
|
|
|
|
#
|
|
|
|
|
# MySQL allows table-level grants on objects that do not exist yet, so the
|
|
|
|
|
# grants below take effect as soon as Alembic creates the reporting views.
|
|
|
|
|
# For an already-initialized database, run scripts/powerbi_grants.sql instead
|
|
|
|
|
# (see README → "Power BI").
|
2026-07-13 13:45:27 -06:00
|
|
|
#
|
|
|
|
|
# NOTE: this file must stay executable (git mode 100755). The MySQL image
|
|
|
|
|
# *sources* non-executable init scripts into its own entrypoint shell, where
|
|
|
|
|
# stray `set` options can break MySQL's startup. The subshell below keeps
|
|
|
|
|
# everything scoped even if that happens.
|
|
|
|
|
(
|
|
|
|
|
set -e
|
Initial commit: PESCO NCR system
Complete Non-Conformance Report system replacing the PowerApps/SharePoint
prototype: FastAPI + SQLAlchemy 2 (async) + Alembic + MySQL 8 backend,
React 18 + Vite + TypeScript + MUI frontend, Entra ID auth (MSAL / JWKS,
group-gated), Microsoft Graph delegated Mail.Send notifications (OBO),
six-stage workflow state machine with server-side enforcement, atomic
NCR-YYYY-NNNN numbering, attachments with camera capture, immutable
field-level audit trail, admin reopen, reports + CSV export, WeasyPrint
PDF traveler, Power BI reporting views + read-only DB user, documented
VISUAL ERP job-lookup stub, pytest suite (26 tests), docker-compose
deployment.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 11:41:22 -06:00
|
|
|
|
2026-07-13 13:45:27 -06:00
|
|
|
if [ -z "${POWERBI_RO_PASSWORD:-}" ]; then
|
|
|
|
|
echo "[init] POWERBI_RO_PASSWORD not set - skipping powerbi_ro user creation."
|
|
|
|
|
else
|
|
|
|
|
mysql -u root -p"${MYSQL_ROOT_PASSWORD}" <<SQL
|
Initial commit: PESCO NCR system
Complete Non-Conformance Report system replacing the PowerApps/SharePoint
prototype: FastAPI + SQLAlchemy 2 (async) + Alembic + MySQL 8 backend,
React 18 + Vite + TypeScript + MUI frontend, Entra ID auth (MSAL / JWKS,
group-gated), Microsoft Graph delegated Mail.Send notifications (OBO),
six-stage workflow state machine with server-side enforcement, atomic
NCR-YYYY-NNNN numbering, attachments with camera capture, immutable
field-level audit trail, admin reopen, reports + CSV export, WeasyPrint
PDF traveler, Power BI reporting views + read-only DB user, documented
VISUAL ERP job-lookup stub, pytest suite (26 tests), docker-compose
deployment.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 11:41:22 -06:00
|
|
|
CREATE USER IF NOT EXISTS 'powerbi_ro'@'%' IDENTIFIED BY '${POWERBI_RO_PASSWORD}';
|
|
|
|
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_full\` TO 'powerbi_ro'@'%';
|
|
|
|
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_stage_history\` TO 'powerbi_ro'@'%';
|
|
|
|
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_costs\` TO 'powerbi_ro'@'%';
|
|
|
|
|
FLUSH PRIVILEGES;
|
|
|
|
|
SQL
|
2026-07-13 13:45:27 -06:00
|
|
|
echo "[init] powerbi_ro user created with SELECT on reporting views."
|
|
|
|
|
fi
|
|
|
|
|
)
|