Complete Non-Conformance Report system replacing the PowerApps/SharePoint prototype: FastAPI + SQLAlchemy 2 (async) + Alembic + MySQL 8 backend, React 18 + Vite + TypeScript + MUI frontend, Entra ID auth (MSAL / JWKS, group-gated), Microsoft Graph delegated Mail.Send notifications (OBO), six-stage workflow state machine with server-side enforcement, atomic NCR-YYYY-NNNN numbering, attachments with camera capture, immutable field-level audit trail, admin reopen, reports + CSV export, WeasyPrint PDF traveler, Power BI reporting views + read-only DB user, documented VISUAL ERP job-lookup stub, pytest suite (26 tests), docker-compose deployment. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
34 lines
732 B
Python
34 lines
732 B
Python
from pydantic import BaseModel, field_validator
|
|
|
|
from app.domain import ALL_ROLES
|
|
from app.schemas.common import AppModel, UTCDateTime
|
|
|
|
|
|
class UserRef(AppModel):
|
|
id: int
|
|
display_name: str
|
|
email: str
|
|
|
|
|
|
class UserOut(UserRef):
|
|
employee_id: str | None = None
|
|
is_active: bool
|
|
roles: list[str]
|
|
last_login_at: UTCDateTime | None = None
|
|
|
|
|
|
class MeOut(UserOut):
|
|
auth_mode: str = "entra"
|
|
|
|
|
|
class RolesUpdateIn(BaseModel):
|
|
roles: list[str]
|
|
|
|
@field_validator("roles")
|
|
@classmethod
|
|
def _valid_roles(cls, v: list[str]) -> list[str]:
|
|
unknown = set(v) - ALL_ROLES
|
|
if unknown:
|
|
raise ValueError(f"Unknown roles: {', '.join(sorted(unknown))}")
|
|
return sorted(set(v))
|