Implement MVP: Anonymous feedback submission (User Story 1)
Complete implementation of Phase 1-3 (64 tasks): - Phase 1: Project setup with Flask, pytest, configuration - Phase 2: Core infrastructure (auth, models, services, testing) - Phase 3: Anonymous feedback submission with file uploads Features: - Anonymous feedback submission (text and/or up to 3 file attachments) - Multi-language support (any language accepted) - File validation (type, size) and virus scanning (ClamAV) - Product management with active/archived status - File-based storage with YAML metadata - User authentication system (Flask-Login) - CSRF protection and rate limiting - Test coverage: 10 passing tests (contract + integration) Security: - No IP address logging (FR-055 compliance) - File type whitelist and size limits (10MB max) - Virus scanning with graceful degradation - Filename sanitization and secure storage Test Results: - 8 contract tests passed - 2 integration tests passed - End-to-end workflow verified 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
"""Flask application factory"""
|
||||
import os
|
||||
from flask import Flask
|
||||
from flask_login import LoginManager
|
||||
from flask_limiter import Limiter
|
||||
from flask_limiter.util import get_remote_address
|
||||
from flask_wtf.csrf import CSRFProtect
|
||||
|
||||
|
||||
def create_app(config_name='development'):
|
||||
"""Create and configure the Flask application
|
||||
|
||||
Args:
|
||||
config_name: Configuration environment (development, production, testing)
|
||||
|
||||
Returns:
|
||||
Flask application instance
|
||||
"""
|
||||
app = Flask(__name__)
|
||||
|
||||
# Load configuration
|
||||
if config_name == 'production':
|
||||
from config.production import ProductionConfig
|
||||
app.config.from_object(ProductionConfig)
|
||||
elif config_name == 'testing':
|
||||
from config.testing import TestingConfig
|
||||
app.config.from_object(TestingConfig)
|
||||
else:
|
||||
from config.development import DevelopmentConfig
|
||||
app.config.from_object(DevelopmentConfig)
|
||||
|
||||
# Ensure data directory exists
|
||||
os.makedirs(app.config['DATA_DIR'], exist_ok=True)
|
||||
|
||||
# Initialize Flask-WTF CSRF Protection
|
||||
csrf = CSRFProtect()
|
||||
csrf.init_app(app)
|
||||
|
||||
# Initialize Flask-Login
|
||||
login_manager = LoginManager()
|
||||
login_manager.init_app(app)
|
||||
login_manager.login_view = 'auth.login'
|
||||
login_manager.login_message = 'Please log in to access this page.'
|
||||
|
||||
@login_manager.user_loader
|
||||
def load_user(user_id):
|
||||
"""Load user by ID for Flask-Login"""
|
||||
from app.models.user import User
|
||||
return User.get_by_id(user_id)
|
||||
|
||||
# Initialize Flask-Limiter
|
||||
limiter = Limiter(
|
||||
app=app,
|
||||
key_func=get_remote_address,
|
||||
storage_uri=app.config['RATELIMIT_STORAGE_URL'],
|
||||
default_limits=[f"{app.config['RATELIMIT_PER_HOUR']}/hour"] if app.config.get('RATELIMIT_ENABLED') else []
|
||||
)
|
||||
|
||||
# Register blueprints
|
||||
from app.routes import submission, dashboard, admin, auth
|
||||
app.register_blueprint(submission.bp)
|
||||
app.register_blueprint(dashboard.bp)
|
||||
app.register_blueprint(admin.bp)
|
||||
app.register_blueprint(auth.bp)
|
||||
|
||||
# Set index route
|
||||
@app.route('/')
|
||||
def index():
|
||||
"""Welcome page"""
|
||||
from flask import render_template
|
||||
return render_template('index.html')
|
||||
|
||||
return app
|
||||
Reference in New Issue
Block a user