Files
Reklamator/app/__init__.py
T
gurixandClaude adbfd23c26 Implement Phase 5: Product Owner Dashboard (User Story 3)
Add complete dashboard functionality for product owners and administrators to view, filter, search, and manage feedback submissions following Test-First Discipline.

Tests (T093-T105):
- Add 12 contract tests for dashboard routes (authentication, listing, filtering, search, detail view, status updates, attachment downloads, access control)
- Add 2 integration tests for complete dashboard workflow and access control enforcement
- All tests written first and verified to fail before implementation

Services (T111-T118):
- Enhance FeedbackStorageService with load_feedback_list() for pagination, filtering, searching, and sorting
- Add load_feedback_detail() to load complete feedback with attachments and analysis
- Add update_feedback_status_by_id() for status management
- Add get_attachment_path() with path traversal prevention

Routes (T119-T134):
- Implement GET /dashboard with filters, search, and pagination (50 items/page)
- Implement GET /feedback/<id> detail view with role-based access control
- Implement POST /feedback/<id>/status for status updates
- Implement GET /feedback/<id>/attachment/<filename> for secure file downloads
- Add access control helpers (administrators see all products, owners see only assigned)

Templates (T135-T136):
- Create dashboard/list.html with filter form, search, and pagination
- Create dashboard/detail.html with status update form and attachment links
- Create error_403.html for access denied
- Create error_404.html for not found

Integration & Bug Fixes:
- Update auth routes to remove /auth prefix and redirect to dashboard after login
- Update Feedback.VALID_STATUSES to include dashboard statuses (in_progress, resolved, closed)
- Register error handlers for 403 and 404 in app factory
- Fix test fixtures to use correct users.yaml format and User.hash_password()

Test Results: 39 passed, 1 skipped (all Phase 5 tests passing)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-10-16 20:11:16 +02:00

87 lines
2.6 KiB
Python

"""Flask application factory"""
import os
from flask import Flask
from flask_login import LoginManager
from flask_limiter import Limiter
from flask_limiter.util import get_remote_address
from flask_wtf.csrf import CSRFProtect
def create_app(config_name='development'):
"""Create and configure the Flask application
Args:
config_name: Configuration environment (development, production, testing)
Returns:
Flask application instance
"""
app = Flask(__name__)
# Load configuration
if config_name == 'production':
from config.production import ProductionConfig
app.config.from_object(ProductionConfig)
elif config_name == 'testing':
from config.testing import TestingConfig
app.config.from_object(TestingConfig)
else:
from config.development import DevelopmentConfig
app.config.from_object(DevelopmentConfig)
# Ensure data directory exists
os.makedirs(app.config['DATA_DIR'], exist_ok=True)
# Initialize Flask-WTF CSRF Protection
csrf = CSRFProtect()
csrf.init_app(app)
# Initialize Flask-Login
login_manager = LoginManager()
login_manager.init_app(app)
login_manager.login_view = 'auth.login'
login_manager.login_message = 'Please log in to access this page.'
@login_manager.user_loader
def load_user(user_id):
"""Load user by ID for Flask-Login"""
from app.models.user import User
return User.get_by_id(user_id)
# Initialize Flask-Limiter
limiter = Limiter(
app=app,
key_func=get_remote_address,
storage_uri=app.config['RATELIMIT_STORAGE_URL'],
default_limits=[f"{app.config['RATELIMIT_PER_HOUR']}/hour"] if app.config.get('RATELIMIT_ENABLED') else []
)
# Register blueprints
from app.routes import submission, dashboard, admin, auth
app.register_blueprint(submission.bp)
app.register_blueprint(dashboard.bp)
app.register_blueprint(admin.bp)
app.register_blueprint(auth.bp)
# Set index route
@app.route('/')
def index():
"""Welcome page"""
from flask import render_template
return render_template('index.html')
# Register error handlers
@app.errorhandler(403)
def forbidden(e):
"""Handle 403 Forbidden errors"""
from flask import render_template
return render_template('error_403.html'), 403
@app.errorhandler(404)
def not_found(e):
"""Handle 404 Not Found errors"""
from flask import render_template
return render_template('error_404.html'), 404
return app