Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Guide for AI coding agents working on the Commerce System Demo project.

Commerce System Demo is a FastAPI-based commerce service that provides RESTful APIs for managing products, categories, and implementing search functionality. The project includes built-in observability with OpenTelemetry metrics, logging, and distributed tracing.

**Current Version**: 0.1.5 (following [Semantic Versioning](https://semver.org/))
**Current Version**: 0.2.0 (following [Semantic Versioning](https://semver.org/))

## Setup Commands

Expand Down Expand Up @@ -109,7 +109,7 @@ app/

### Docker

- **Build image**: `docker build -t commerce-system-demo:0.1.5 .`
- **Build image**: `docker build -t commerce-system-demo:0.2.0 .`
- **View Dockerfile**: Includes Python dependencies, migration scripts, and app code
- **Build context**: Includes `scripts/`, `app/`, and `observability/` directories

Expand Down Expand Up @@ -192,7 +192,7 @@ This project follows [Semantic Versioning 2.0.0](https://semver.org/):
- **MINOR**: Backward-compatible new features
- **PATCH**: Backward-compatible bug fixes

Current version is **0.1.5** (initial development). Version is defined in:
Current version is **0.2.0** (initial development). Version is defined in:
- `pyproject.toml` (project metadata)
- `app/main.py` (FastAPI version)
- `app/observability/metrics.py` (meter version)
Expand Down
36 changes: 35 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,44 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

- Enhanced search with full-text indexing support
- Bulk import/export endpoints for products and categories
- Rate limiting and request throttling
- Advanced filtering options for product search
- Product images storage optimization

## [0.2.0] - 2026-03-22

### Added

- Rate limiting with slowapi — IP-based throttling on search endpoint with configurable default and per-route limits
- `rate_limit_default` and `rate_limit_search` settings in `app/core/config.py`
- Alembic migration framework with async PostgreSQL support (`alembic/` directory, `alembic.ini`)
- Initial Alembic migration (`001_initial_schema.py`) matching the existing `create_all` schema
- `timed_execute_all`, `timed_execute_one` helpers in `app/observability/db_timing.py` for instrumented query execution
- `_escape_like()` utility in `app/services/product_service.py` for sanitizing LIKE metacharacters
- `field_serializer` on `ProductUpdate.image_url` to serialize `AnyHttpUrl` to plain `str`
- Integration tests for category depth limits, cycle detection, self-reference rejection, and LIKE injection
- Documentation in README clarifying `.env` setup steps with a table of key variables and defaults

### Changed

- Search query uses `COUNT(*) OVER()` window function instead of a separate count query, eliminating a second database roundtrip
- Category depth validation (`validate_category_parent`) consolidated from N+1 sequential queries to a single recursive CTE
- Category reparent validation (`validate_category_reparent`) consolidated from 4 sequential queries to a single combined CTE query
- `get_session` dependency now reads from `request.app.state.session_factory` (proper DI via app state) instead of module-level globals
- Application lifespan stores `engine` and `session_factory` on `app.state`
- Health endpoint reads engine from `request.app.state.engine` instead of importing `get_engine()`
- `create_schema()` / `drop_schema()` accept an optional `engine` parameter
- Test fixtures set `app.state.engine` and `app.state.session_factory` explicitly (httpx ASGITransport skips ASGI lifespan)

### Fixed

- LIKE metacharacters (`%`, `_`, `\`) in search queries are now escaped, preventing wildcard injection
- `ProductUpdate.image_url` now serializes correctly from `AnyHttpUrl` to `str` for database persistence

### Security

- Added IP-based rate limiting to protect against request flooding
- Escaped LIKE wildcards in user-supplied search input to prevent pattern injection

## [0.1.5] - 2026-03-22

### Fixed
Expand Down
13 changes: 12 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -496,12 +496,23 @@ python3 -m venv .venv
pip install -e '.[dev]'
```

3. Copy environment config and adjust DB credentials if needed:
3. Copy environment config and adjust as needed:

```bash
cp .env.example .env
```

The `.env` file is **not** committed to the repository (it is listed in `.gitignore`). The provided `.env.example` contains sensible defaults for local development. Key variables you may want to review:

| Variable | Default | Purpose |
|---|---|---|
| `DATABASE_URL` | `postgresql+asyncpg://postgres:postgres@localhost:5432/commerce_demo` | PostgreSQL connection string. Change host/port/credentials to match your local setup, or leave as-is when using Docker Compose (it provisions the DB automatically). |
| `TELEMETRY_ENABLED` | `true` | Set to `false` if you are not running the observability stack. |
| `API_PREFIX` | `/api/v1` | URL prefix for all API routes. |
| `AUTO_CREATE_SCHEMA` | `true` | Creates tables on startup when no Alembic migration has been run yet. |

> **Tip:** When using **Docker Compose** (Option A below), the compose file passes its own `DATABASE_URL` pointing at the containerized PostgreSQL, so the value in `.env` is only used if you run the dev server directly on the host (Option C).

### 8.2. Development Server

#### Option A: Run full stack with Docker Compose (recommended)
Expand Down
147 changes: 147 additions & 0 deletions alembic.ini
Original file line number Diff line number Diff line change
@@ -0,0 +1,147 @@
# A generic, single database configuration.

[alembic]
# path to migration scripts.
# this is typically a path given in POSIX (e.g. forward slashes)
# format, relative to the token %(here)s which refers to the location of this
# ini file
script_location = %(here)s/alembic

# template used to generate migration file names; The default value is %%(rev)s_%%(slug)s
# Uncomment the line below if you want the files to be prepended with date and time
# see https://alembic.sqlalchemy.org/en/latest/tutorial.html#editing-the-ini-file
# for all available tokens
# file_template = %%(year)d_%%(month).2d_%%(day).2d_%%(hour).2d%%(minute).2d-%%(rev)s_%%(slug)s
# Or organize into date-based subdirectories (requires recursive_version_locations = true)
# file_template = %%(year)d/%%(month).2d/%%(day).2d_%%(hour).2d%%(minute).2d_%%(second).2d_%%(rev)s_%%(slug)s

# sys.path path, will be prepended to sys.path if present.
# defaults to the current working directory. for multiple paths, the path separator
# is defined by "path_separator" below.
prepend_sys_path = .

# timezone to use when rendering the date within the migration file
# as well as the filename.
# If specified, requires the tzdata library which can be installed by adding
# `alembic[tz]` to the pip requirements.
# string value is passed to ZoneInfo()
# leave blank for localtime
# timezone =

# max length of characters to apply to the "slug" field
# truncate_slug_length = 40

# set to 'true' to run the environment during
# the 'revision' command, regardless of autogenerate
# revision_environment = false

# set to 'true' to allow .pyc and .pyo files without
# a source .py file to be detected as revisions in the
# versions/ directory
# sourceless = false

# version location specification; This defaults
# to <script_location>/versions. When using multiple version
# directories, initial revisions must be specified with --version-path.
# The path separator used here should be the separator specified by "path_separator"
# below.
# version_locations = %(here)s/bar:%(here)s/bat:%(here)s/alembic/versions

# path_separator; This indicates what character is used to split lists of file
# paths, including version_locations and prepend_sys_path within configparser
# files such as alembic.ini.
# The default rendered in new alembic.ini files is "os", which uses os.pathsep
# to provide os-dependent path splitting.
#
# Note that in order to support legacy alembic.ini files, this default does NOT
# take place if path_separator is not present in alembic.ini. If this
# option is omitted entirely, fallback logic is as follows:
#
# 1. Parsing of the version_locations option falls back to using the legacy
# "version_path_separator" key, which if absent then falls back to the legacy
# behavior of splitting on spaces and/or commas.
# 2. Parsing of the prepend_sys_path option falls back to the legacy
# behavior of splitting on spaces, commas, or colons.
#
# Valid values for path_separator are:
#
# path_separator = :
# path_separator = ;
# path_separator = space
# path_separator = newline
#
# Use os.pathsep. Default configuration used for new projects.
path_separator = os


# set to 'true' to search source files recursively
# in each "version_locations" directory
# new in Alembic version 1.10
# recursive_version_locations = false

# the output encoding used when revision files
# are written from script.py.mako
# output_encoding = utf-8

# database URL. Overridden at runtime by env.py from DATABASE_URL env var.
sqlalchemy.url =


[post_write_hooks]
# post_write_hooks defines scripts or Python functions that are run
# on newly generated revision scripts. See the documentation for further
# detail and examples

# format using "black" - use the console_scripts runner, against the "black" entrypoint
# hooks = black
# black.type = console_scripts
# black.entrypoint = black
# black.options = -l 79 REVISION_SCRIPT_FILENAME

# lint with attempts to fix using "ruff" - use the module runner, against the "ruff" module
# hooks = ruff
# ruff.type = module
# ruff.module = ruff
# ruff.options = check --fix REVISION_SCRIPT_FILENAME

# Alternatively, use the exec runner to execute a binary found on your PATH
# hooks = ruff
# ruff.type = exec
# ruff.executable = ruff
# ruff.options = check --fix REVISION_SCRIPT_FILENAME

# Logging configuration. This is also consumed by the user-maintained
# env.py script only.
[loggers]
keys = root,sqlalchemy,alembic

[handlers]
keys = console

[formatters]
keys = generic

[logger_root]
level = WARNING
handlers = console
qualname =

[logger_sqlalchemy]
level = WARNING
handlers =
qualname = sqlalchemy.engine

[logger_alembic]
level = INFO
handlers =
qualname = alembic

[handler_console]
class = StreamHandler
args = (sys.stderr,)
level = NOTSET
formatter = generic

[formatter_generic]
format = %(levelname)-5.5s [%(name)s] %(message)s
datefmt = %H:%M:%S
1 change: 1 addition & 0 deletions alembic/README
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Generic single-database configuration with an async dbapi.
73 changes: 73 additions & 0 deletions alembic/env.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
"""Alembic environment configuration for async migrations."""

import asyncio
from logging.config import fileConfig

from sqlalchemy import pool
from sqlalchemy.engine import Connection
from sqlalchemy.ext.asyncio import async_engine_from_config

from alembic import context

# Import all models so that Base.metadata is fully populated.
import app.models # noqa: F401
from app.core.config import get_settings
from app.db.base import Base

config = context.config

# Interpret the config file for Python logging.
if config.config_file_name is not None:
fileConfig(config.config_file_name)

# Point autogenerate at the project's declarative metadata.
target_metadata = Base.metadata

# Override sqlalchemy.url from the application settings (DATABASE_URL env var).
config.set_main_option("sqlalchemy.url", get_settings().database_url)


def run_migrations_offline() -> None:
"""Run migrations in 'offline' mode (emit SQL to stdout)."""
url = config.get_main_option("sqlalchemy.url")
context.configure(
url=url,
target_metadata=target_metadata,
literal_binds=True,
dialect_opts={"paramstyle": "named"},
)

with context.begin_transaction():
context.run_migrations()


def do_run_migrations(connection: Connection) -> None:
context.configure(connection=connection, target_metadata=target_metadata)

with context.begin_transaction():
context.run_migrations()


async def run_async_migrations() -> None:
"""Create an async engine and run migrations."""
connectable = async_engine_from_config(
config.get_section(config.config_ini_section, {}),
prefix="sqlalchemy.",
poolclass=pool.NullPool,
)

async with connectable.connect() as connection:
await connection.run_sync(do_run_migrations)

await connectable.dispose()


def run_migrations_online() -> None:
"""Run migrations in 'online' mode."""
asyncio.run(run_async_migrations())


if context.is_offline_mode():
run_migrations_offline()
else:
run_migrations_online()
28 changes: 28 additions & 0 deletions alembic/script.py.mako
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
"""${message}

Revision ID: ${up_revision}
Revises: ${down_revision | comma,n}
Create Date: ${create_date}

"""
from typing import Sequence, Union

from alembic import op
import sqlalchemy as sa
${imports if imports else ""}

# revision identifiers, used by Alembic.
revision: str = ${repr(up_revision)}
down_revision: Union[str, Sequence[str], None] = ${repr(down_revision)}
branch_labels: Union[str, Sequence[str], None] = ${repr(branch_labels)}
depends_on: Union[str, Sequence[str], None] = ${repr(depends_on)}


def upgrade() -> None:
"""Upgrade schema."""
${upgrades if upgrades else "pass"}


def downgrade() -> None:
"""Downgrade schema."""
${downgrades if downgrades else "pass"}
Loading
Loading