feat: Consent-Service Module nach Compliance migriert (DSR, E-Mail-Templates, Legal Docs, Banner)
All checks were successful
CI / go-lint (push) Has been skipped
CI / python-lint (push) Has been skipped
CI / nodejs-lint (push) Has been skipped
CI / test-go-ai-compliance (push) Successful in 36s
CI / test-python-backend-compliance (push) Successful in 31s
CI / test-python-document-crawler (push) Successful in 23s
CI / test-python-dsms-gateway (push) Successful in 18s

5-Phasen-Migration: Go consent-service Proxies durch native Python/FastAPI ersetzt.

Phase 1 — DSR (Betroffenenrechte): 6 Tabellen, 30 Endpoints, Frontend-API umgestellt
Phase 2 — E-Mail-Templates: 5 Tabellen, 20 Endpoints, neues Frontend, SDK_STEPS erweitert
Phase 3 — Legal Documents Extension: User Consents, Audit Log, Cookie-Kategorien
Phase 4 — Banner Consent: Device-Consents, Site-Configs, Kategorien, Vendors
Phase 5 — Cleanup: DSR-Proxy aus main.py entfernt, Frontend-URLs aktualisiert

148 neue Tests (50 + 47 + 26 + 25), alle bestanden.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Benjamin Admin
2026-03-05 00:36:24 +01:00
parent 2211cb9349
commit b7c1a5da1a
23 changed files with 7146 additions and 542 deletions

View File

@@ -0,0 +1,138 @@
"""
SQLAlchemy models for Banner Consent — Device-basierte Cookie-Consents.
Tables:
- compliance_banner_consents: Anonyme Geraete-Consents
- compliance_banner_consent_audit_log: Immutable Audit
- compliance_banner_site_configs: Site-Konfiguration
- compliance_banner_category_configs: Consent-Kategorien pro Site
- compliance_banner_vendor_configs: Third-Party-Vendor-Tracking
"""
import uuid
from datetime import datetime
from sqlalchemy import (
Column, String, Text, Boolean, Integer, DateTime, Index, JSON
)
from sqlalchemy.dialects.postgresql import UUID
from classroom_engine.database import Base
class BannerConsentDB(Base):
"""Anonymer Device-basierter Cookie-Consent."""
__tablename__ = 'compliance_banner_consents'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
site_id = Column(Text, nullable=False)
device_fingerprint = Column(Text, nullable=False)
categories = Column(JSON, default=list)
vendors = Column(JSON, default=list)
ip_hash = Column(Text)
user_agent = Column(Text)
consent_string = Column(Text)
expires_at = Column(DateTime)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_banner_consent_tenant', 'tenant_id'),
Index('idx_banner_consent_site', 'site_id'),
Index('idx_banner_consent_device', 'device_fingerprint'),
)
class BannerConsentAuditLogDB(Base):
"""Immutable Audit-Trail fuer Banner-Consents."""
__tablename__ = 'compliance_banner_consent_audit_log'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
consent_id = Column(UUID(as_uuid=True))
action = Column(Text, nullable=False)
site_id = Column(Text, nullable=False)
device_fingerprint = Column(Text)
categories = Column(JSON, default=list)
ip_hash = Column(Text)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
__table_args__ = (
Index('idx_banner_audit_tenant', 'tenant_id'),
Index('idx_banner_audit_site', 'site_id'),
Index('idx_banner_audit_created', 'created_at'),
)
class BannerSiteConfigDB(Base):
"""Site-Konfiguration fuer Consent-Banner."""
__tablename__ = 'compliance_banner_site_configs'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
site_id = Column(Text, nullable=False)
site_name = Column(Text)
site_url = Column(Text)
banner_title = Column(Text, default='Cookie-Einstellungen')
banner_description = Column(Text, default='Wir verwenden Cookies, um Ihnen die bestmoegliche Erfahrung zu bieten.')
privacy_url = Column(Text)
imprint_url = Column(Text)
dsb_name = Column(Text)
dsb_email = Column(Text)
theme = Column(JSON, default=dict)
tcf_enabled = Column(Boolean, default=False)
is_active = Column(Boolean, nullable=False, default=True)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_banner_site_config', 'tenant_id', 'site_id', unique=True),
)
class BannerCategoryConfigDB(Base):
"""Consent-Kategorien pro Site."""
__tablename__ = 'compliance_banner_category_configs'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
site_config_id = Column(UUID(as_uuid=True), nullable=False)
category_key = Column(Text, nullable=False)
name_de = Column(Text, nullable=False)
name_en = Column(Text)
description_de = Column(Text)
description_en = Column(Text)
is_required = Column(Boolean, nullable=False, default=False)
sort_order = Column(Integer, nullable=False, default=0)
is_active = Column(Boolean, nullable=False, default=True)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
__table_args__ = (
Index('idx_banner_cat_config', 'site_config_id'),
)
class BannerVendorConfigDB(Base):
"""Third-Party-Vendor-Tracking pro Site."""
__tablename__ = 'compliance_banner_vendor_configs'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
site_config_id = Column(UUID(as_uuid=True), nullable=False)
vendor_name = Column(Text, nullable=False)
vendor_url = Column(Text)
category_key = Column(Text, nullable=False)
description_de = Column(Text)
description_en = Column(Text)
cookie_names = Column(JSON, default=list)
retention_days = Column(Integer, default=365)
is_active = Column(Boolean, nullable=False, default=True)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
__table_args__ = (
Index('idx_banner_vendor_config', 'site_config_id'),
)

View File

@@ -0,0 +1,209 @@
"""
SQLAlchemy models for DSR — Data Subject Requests (Betroffenenanfragen nach DSGVO Art. 15-21).
Tables:
- compliance_dsr_requests: Haupttabelle fuer Betroffenenanfragen
- compliance_dsr_status_history: Status-Audit-Trail
- compliance_dsr_communications: Kommunikation mit Betroffenen
- compliance_dsr_templates: Kommunikationsvorlagen
- compliance_dsr_template_versions: Versionierte Template-Inhalte
- compliance_dsr_exception_checks: Art. 17(3) Ausnahmepruefungen
"""
import uuid
from datetime import datetime
from sqlalchemy import (
Column, String, Text, Boolean, DateTime, JSON, Index
)
from sqlalchemy.dialects.postgresql import UUID
from classroom_engine.database import Base
class DSRRequestDB(Base):
"""DSR request — Betroffenenanfrage nach DSGVO Art. 15-21."""
__tablename__ = 'compliance_dsr_requests'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
request_number = Column(Text, nullable=False)
request_type = Column(Text, nullable=False, default='access')
status = Column(Text, nullable=False, default='intake')
priority = Column(Text, nullable=False, default='normal')
# Antragsteller
requester_name = Column(Text, nullable=False)
requester_email = Column(Text, nullable=False)
requester_phone = Column(Text)
requester_address = Column(Text)
requester_customer_id = Column(Text)
# Anfrage-Details
source = Column(Text, nullable=False, default='email')
source_details = Column(Text)
request_text = Column(Text)
notes = Column(Text)
internal_notes = Column(Text)
# Fristen
received_at = Column(DateTime, nullable=False, default=datetime.utcnow)
deadline_at = Column(DateTime, nullable=False)
extended_deadline_at = Column(DateTime)
extension_reason = Column(Text)
extension_approved_by = Column(Text)
extension_approved_at = Column(DateTime)
# Identitaetspruefung
identity_verified = Column(Boolean, nullable=False, default=False)
verification_method = Column(Text)
verified_at = Column(DateTime)
verified_by = Column(Text)
verification_notes = Column(Text)
verification_document_ref = Column(Text)
# Zuweisung
assigned_to = Column(Text)
assigned_at = Column(DateTime)
assigned_by = Column(Text)
# Abschluss
completed_at = Column(DateTime)
completion_notes = Column(Text)
rejection_reason = Column(Text)
rejection_legal_basis = Column(Text)
# Typ-spezifische Daten
erasure_checklist = Column(JSON, default=list)
data_export = Column(JSON, default=dict)
rectification_details = Column(JSON, default=dict)
objection_details = Column(JSON, default=dict)
affected_systems = Column(JSON, default=list)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
created_by = Column(Text, default='system')
updated_by = Column(Text)
__table_args__ = (
Index('idx_dsr_requests_tenant', 'tenant_id'),
Index('idx_dsr_requests_status', 'status'),
Index('idx_dsr_requests_type', 'request_type'),
Index('idx_dsr_requests_priority', 'priority'),
Index('idx_dsr_requests_assigned', 'assigned_to'),
Index('idx_dsr_requests_deadline', 'deadline_at'),
Index('idx_dsr_requests_received', 'received_at'),
)
class DSRStatusHistoryDB(Base):
"""Status-Audit-Trail fuer DSR Requests."""
__tablename__ = 'compliance_dsr_status_history'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
dsr_id = Column(UUID(as_uuid=True), nullable=False)
previous_status = Column(Text)
new_status = Column(Text, nullable=False)
changed_by = Column(Text)
comment = Column(Text)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
__table_args__ = (
Index('idx_dsr_history_dsr', 'dsr_id'),
Index('idx_dsr_history_created', 'created_at'),
)
class DSRCommunicationDB(Base):
"""Kommunikation mit Betroffenen (E-Mail, Portal, intern)."""
__tablename__ = 'compliance_dsr_communications'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
dsr_id = Column(UUID(as_uuid=True), nullable=False)
communication_type = Column(Text, nullable=False, default='outgoing')
channel = Column(Text, nullable=False, default='email')
subject = Column(Text)
content = Column(Text, nullable=False)
template_used = Column(Text)
attachments = Column(JSON, default=list)
sent_at = Column(DateTime)
sent_by = Column(Text)
received_at = Column(DateTime)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
created_by = Column(Text, default='system')
__table_args__ = (
Index('idx_dsr_comms_dsr', 'dsr_id'),
)
class DSRTemplateDB(Base):
"""Kommunikationsvorlagen fuer DSR."""
__tablename__ = 'compliance_dsr_templates'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
name = Column(Text, nullable=False)
template_type = Column(Text, nullable=False)
request_type = Column(Text)
language = Column(Text, nullable=False, default='de')
is_active = Column(Boolean, nullable=False, default=True)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_dsr_templates_tenant', 'tenant_id'),
Index('idx_dsr_templates_type', 'template_type'),
)
class DSRTemplateVersionDB(Base):
"""Versionierte Template-Inhalte."""
__tablename__ = 'compliance_dsr_template_versions'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
template_id = Column(UUID(as_uuid=True), nullable=False)
version = Column(Text, nullable=False, default='1.0')
subject = Column(Text, nullable=False)
body_html = Column(Text, nullable=False)
body_text = Column(Text)
status = Column(Text, nullable=False, default='draft')
published_at = Column(DateTime)
published_by = Column(Text)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
created_by = Column(Text, default='system')
__table_args__ = (
Index('idx_dsr_tpl_versions_template', 'template_id'),
Index('idx_dsr_tpl_versions_status', 'status'),
)
class DSRExceptionCheckDB(Base):
"""Art. 17(3) Ausnahmepruefungen fuer Loeschanfragen."""
__tablename__ = 'compliance_dsr_exception_checks'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
dsr_id = Column(UUID(as_uuid=True), nullable=False)
check_code = Column(Text, nullable=False)
article = Column(Text, nullable=False)
label = Column(Text, nullable=False)
description = Column(Text)
applies = Column(Boolean)
notes = Column(Text)
checked_by = Column(Text)
checked_at = Column(DateTime)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
__table_args__ = (
Index('idx_dsr_exception_dsr', 'dsr_id'),
)

View File

@@ -0,0 +1,135 @@
"""
SQLAlchemy models for E-Mail-Templates — Benachrichtigungsvorlagen fuer DSGVO-Compliance.
Tables:
- compliance_email_templates: Template-Definitionen
- compliance_email_template_versions: Versionierte Inhalte mit Approval-Workflow
- compliance_email_template_approvals: Genehmigungen/Ablehnungen
- compliance_email_send_logs: Audit-Trail gesendeter E-Mails
- compliance_email_template_settings: Globale Branding-Einstellungen
"""
import uuid
from datetime import datetime
from sqlalchemy import (
Column, String, Text, Boolean, Integer, DateTime, JSON, Index
)
from sqlalchemy.dialects.postgresql import UUID
from classroom_engine.database import Base
class EmailTemplateDB(Base):
"""E-Mail-Template Definition."""
__tablename__ = 'compliance_email_templates'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
template_type = Column(Text, nullable=False)
name = Column(Text, nullable=False)
description = Column(Text)
category = Column(Text, nullable=False, default='general')
is_active = Column(Boolean, nullable=False, default=True)
sort_order = Column(Integer, nullable=False, default=0)
variables = Column(JSON, default=list)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_email_tpl_tenant', 'tenant_id'),
Index('idx_email_tpl_type', 'template_type'),
Index('idx_email_tpl_category', 'category'),
)
class EmailTemplateVersionDB(Base):
"""Versionierte E-Mail-Template-Inhalte."""
__tablename__ = 'compliance_email_template_versions'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
template_id = Column(UUID(as_uuid=True), nullable=False)
version = Column(Text, nullable=False, default='1.0')
language = Column(Text, nullable=False, default='de')
subject = Column(Text, nullable=False)
body_html = Column(Text, nullable=False)
body_text = Column(Text)
status = Column(Text, nullable=False, default='draft')
submitted_at = Column(DateTime)
submitted_by = Column(Text)
published_at = Column(DateTime)
published_by = Column(Text)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
created_by = Column(Text, default='system')
__table_args__ = (
Index('idx_email_tpl_ver_template', 'template_id'),
Index('idx_email_tpl_ver_status', 'status'),
)
class EmailTemplateApprovalDB(Base):
"""Approval-Workflow fuer Template-Versionen."""
__tablename__ = 'compliance_email_template_approvals'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
version_id = Column(UUID(as_uuid=True), nullable=False)
action = Column(Text, nullable=False, default='approve')
comment = Column(Text)
approved_by = Column(Text)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
__table_args__ = (
Index('idx_email_tpl_appr_version', 'version_id'),
)
class EmailSendLogDB(Base):
"""Audit-Trail gesendeter E-Mails."""
__tablename__ = 'compliance_email_send_logs'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
template_type = Column(Text, nullable=False)
version_id = Column(UUID(as_uuid=True))
recipient = Column(Text, nullable=False)
subject = Column(Text, nullable=False)
status = Column(Text, nullable=False, default='sent')
variables = Column(JSON, default=dict)
error_message = Column(Text)
sent_at = Column(DateTime, default=datetime.utcnow, nullable=False)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
__table_args__ = (
Index('idx_email_logs_tenant', 'tenant_id'),
Index('idx_email_logs_type', 'template_type'),
Index('idx_email_logs_sent', 'sent_at'),
)
class EmailTemplateSettingsDB(Base):
"""Globale E-Mail-Einstellungen (Branding)."""
__tablename__ = 'compliance_email_template_settings'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
sender_name = Column(Text, default='Datenschutzbeauftragter')
sender_email = Column(Text, default='datenschutz@example.de')
reply_to = Column(Text)
logo_url = Column(Text)
primary_color = Column(Text, default='#4F46E5')
secondary_color = Column(Text, default='#7C3AED')
footer_text = Column(Text, default='Datenschutzhinweis: Diese E-Mail enthaelt vertrauliche Informationen.')
company_name = Column(Text)
company_address = Column(Text)
created_at = Column(DateTime, default=datetime.utcnow, nullable=False)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_email_settings_tenant', 'tenant_id', unique=True),
)

View File

@@ -0,0 +1,88 @@
"""
SQLAlchemy models for Legal Documents Extension.
Tables:
- compliance_user_consents: End-User Consent-Records
- compliance_consent_audit_log: Immutable Audit-Trail
- compliance_cookie_categories: Cookie-Kategorien fuer Banner
"""
import uuid
from datetime import datetime
from sqlalchemy import (
Column, String, Text, Boolean, Integer, DateTime, Index, JSON
)
from sqlalchemy.dialects.postgresql import UUID
from classroom_engine.database import Base
class UserConsentDB(Base):
"""End-User Consent-Record fuer rechtliche Dokumente."""
__tablename__ = 'compliance_user_consents'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
user_id = Column(Text, nullable=False)
document_id = Column(UUID(as_uuid=True), nullable=False)
document_version_id = Column(UUID(as_uuid=True))
document_type = Column(Text, nullable=False)
consented = Column(Boolean, nullable=False, default=True)
ip_address = Column(Text)
user_agent = Column(Text)
consented_at = Column(DateTime, nullable=False, default=datetime.utcnow)
withdrawn_at = Column(DateTime)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
__table_args__ = (
Index('idx_user_consents_tenant', 'tenant_id'),
Index('idx_user_consents_user', 'user_id'),
Index('idx_user_consents_doc', 'document_id'),
Index('idx_user_consents_type', 'document_type'),
)
class ConsentAuditLogDB(Base):
"""Immutable Audit-Trail fuer Consent-Aktionen."""
__tablename__ = 'compliance_consent_audit_log'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
action = Column(Text, nullable=False)
entity_type = Column(Text, nullable=False)
entity_id = Column(UUID(as_uuid=True))
user_id = Column(Text)
details = Column(JSON, default=dict)
ip_address = Column(Text)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
__table_args__ = (
Index('idx_consent_audit_tenant', 'tenant_id'),
Index('idx_consent_audit_action', 'action'),
Index('idx_consent_audit_created', 'created_at'),
)
class CookieCategoryDB(Base):
"""Cookie-Kategorien fuer Consent-Banner."""
__tablename__ = 'compliance_cookie_categories'
id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4)
tenant_id = Column(UUID(as_uuid=True), nullable=False)
name_de = Column(Text, nullable=False)
name_en = Column(Text)
description_de = Column(Text)
description_en = Column(Text)
is_required = Column(Boolean, nullable=False, default=False)
sort_order = Column(Integer, nullable=False, default=0)
is_active = Column(Boolean, nullable=False, default=True)
created_at = Column(DateTime, nullable=False, default=datetime.utcnow)
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
__table_args__ = (
Index('idx_cookie_cats_tenant', 'tenant_id'),
)