Files
boc/landvex-admin
Bernt aee0f09db8 landvex: Fixar och tester klara för alla komponenter
- Datafabrik: Dockerfile fix, agentorkestrering fungerar
- Vision: Identify-modell, FAISS, OCR alla testade
- API: Alla 7 integrationstester passerade
- Upplösare: Entitetsupplösning verifierad
2026-07-05 06:41:32 +00:00
..

LandveX Enterprise Platform - Admin Backend

Complete admin backend design for LandveX Enterprise Platform serving municipalities (kommuner) and enterprises.

Architecture Overview

┌─────────────────────────────────────────────────────────┐
│                    React 19 Frontend                     │
│              (Admin Dashboard UI)                        │
└─────────────────────────────────────────────────────────┘
                           │
                           ▼
┌─────────────────────────────────────────────────────────┐
│              FastAPI Backend (Python)                    │
│  Auth · Tenants · Users · Billing · Audit · Reports     │
└─────────────────────────────────────────────────────────┘
                           │
           ┌───────────────┼───────────────┐
           ▼               ▼               ▼
    ┌──────────┐   ┌──────────┐   ┌──────────┐
    │PostgreSQL│   │  Redis   │   │  Stripe  │
    │  (Data)  │   │ (Cache)  │   │(Payments)│
    └──────────┘   └──────────┘   └──────────┘

Features

1. Customer Management (Tenants)

  • Multi-tenant architecture with complete isolation
  • Support for municipalities (kommuner) and enterprises
  • Organization profiles with org numbers
  • Tenant-specific settings and configurations

2. User Management with Roles

  • RBAC (Role-Based Access Control) system
  • Predefined roles: Superadmin, Admin, Editor, Viewer, API
  • Custom role creation with granular permissions
  • User invitation and activation workflow
  • Account locking after failed login attempts
  • MFA (Multi-Factor Authentication) support

3. Tenant Isolation

  • Row-Level Security (RLS) in PostgreSQL
  • Tenant resolution via JWT claims or API keys
  • Automatic query filtering by tenant_id
  • Separate data contexts per tenant

4. Audit Logging

  • Comprehensive action logging
  • User activity tracking
  • Resource change history
  • IP address and user agent capture
  • Severity levels (info, warning, critical)
  • Export capabilities (CSV/JSON)

5. API Key Management

  • Secure key generation with prefix identification
  • Scope-based permissions per key
  • Rate limiting per key
  • Key expiration and revocation
  • Usage tracking

6. Billing & Subscriptions

  • Subscription plan management
  • Stripe integration for payments
  • Invoice generation and PDF export
  • Payment method management
  • MRR and revenue tracking

7. Reports & Analytics

  • Custom report builder
  • Scheduled report generation
  • Multiple output formats (PDF, CSV, JSON)
  • Dashboard with KPI widgets
  • API usage analytics

8. Plugin Management

  • Plugin marketplace
  • Tenant-specific plugin installation
  • Plugin configuration per tenant
  • System vs optional plugins
  • Version management

Project Structure

landvex-admin/
├── design.md                 # Complete design document
├── docker-compose.yml        # Local development stack
├── api/
│   └── openapi.yaml         # OpenAPI 3.1 specification
├── backend/
│   ├── app/
│   │   ├── main.py          # FastAPI entry point
│   │   ├── config.py        # Configuration
│   │   ├── database.py      # DB connection
│   │   ├── models/          # SQLAlchemy models
│   │   │   ├── tenant.py
│   │   │   ├── user.py
│   │   │   ├── billing.py
│   │   │   ├── api_key.py
│   │   │   ├── audit.py
│   │   │   ├── report.py
│   │   │   └── plugin.py
│   │   ├── api/             # API routes
│   │   │   ├── deps.py      # Dependencies
│   │   │   └── v1/
│   │   │       ├── auth.py
│   │   │       ├── tenants.py
│   │   │       ├── users.py
│   │   │       ├── roles.py
│   │   │       ├── api_keys.py
│   │   │       ├── billing.py
│   │   │       ├── audit.py
│   │   │       ├── reports.py
│   │   │       ├── plugins.py
│   │   │       └── dashboard.py
│   │   ├── core/            # Security & utilities
│   │   │   ├── security.py  # Password, JWT, API keys
│   │   │   ├── permissions.py # RBAC
│   │   │   └── exceptions.py
│   │   └── services/        # Business logic
│   ├── Dockerfile
│   └── requirements.txt
└── frontend/
    ├── src/
    │   ├── App.tsx
    │   ├── components/
    │   │   └── layout/
    │   │       ├── Layout.tsx
    │   │       ├── Sidebar.tsx
    │   │       └── TopBar.tsx
    │   ├── pages/
    │   │   ├── Dashboard.tsx
    │   │   ├── Tenants/
    │   │   ├── Users/
    │   │   ├── Roles/
    │   │   ├── Billing/
    │   │   ├── AuditLogs/
    │   │   ├── Reports/
    │   │   └── Plugins/
    │   ├── hooks/
    │   │   ├── useAuth.ts
    │   │   └── usePermissions.ts
    │   ├── stores/
    │   │   └── authStore.ts
    │   └── lib/
    │       └── api.ts
    ├── Dockerfile
    └── package.json

Quick Start

Prerequisites

  • Docker & Docker Compose
  • Node.js 20+ (for local frontend dev)
  • Python 3.11+ (for local backend dev)

Local Development

# Start all services
docker-compose up -d

# Backend API: http://localhost:8000
# Frontend: http://localhost:5173
# API Docs: http://localhost:8000/docs

Environment Variables

# Backend
DATABASE_URL=postgresql+asyncpg://landvex:password@db:5432/landvex_admin
REDIS_URL=redis://redis:6379/0
SECRET_KEY=your-secret-key
JWT_ALGORITHM=HS256
ACCESS_TOKEN_EXPIRE_MINUTES=30
REFRESH_TOKEN_EXPIRE_DAYS=7
STRIPE_SECRET_KEY=sk_test_...
STRIPE_WEBHOOK_SECRET=whsec_...

# Frontend
VITE_API_URL=http://localhost:8000/api/v1

Security Features

  • Authentication: JWT tokens with refresh token rotation
  • Password Hashing: Argon2id
  • API Keys: SHA-256 hashed with prefix identification
  • Authorization: RBAC with wildcard permissions
  • Tenant Isolation: Row-Level Security in PostgreSQL
  • Audit Logging: All state-changing operations logged
  • Rate Limiting: Per-key and per-user limits
  • CORS: Configurable allowed origins
  • Security Headers: HSTS, CSP, X-Frame-Options, etc.

API Endpoints

Category Endpoints
Auth POST /auth/login, POST /auth/refresh, POST /auth/mfa/verify
Tenants GET /tenants, POST /tenants, GET /tenants/{id}
Users GET /users, POST /users, PATCH /users/{id}
Roles GET /roles, POST /roles, PATCH /roles/{id}
API Keys GET /api-keys, POST /api-keys, POST /api-keys/{id}/revoke
Billing GET /billing/plans, GET /billing/invoices
Audit GET /audit-logs, GET /audit-logs/export
Reports GET /reports, POST /reports/{id}/run
Plugins GET /plugins, POST /plugins/{id}/install
Dashboard GET /dashboard/summary

License

Proprietary - LandveX Enterprise Platform