kitchen/backend/requirements.txt
jtricerolph bcc94024e3 Pre-deploy security/correctness fixes (port log E17)
- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret)
  — KDS reads kitchen_db directly (E16), nothing ever called this endpoint
- Add expires_at to dispute_attachments; public attachment links now expire
  after 30 days instead of staying valid forever (A4)
- Add services/upload_validation.py: sniff real file content via python-magic
  instead of trusting the client-supplied Content-Type header, plus a 20MB
  cap. Applied across invoices/logbook/food_flags/credit_notes/disputes
  upload endpoints (A5) — disputes previously had no file-type check at all
- Fix nginx client_max_body_size drift (800m -> the plan's intended 20m)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-06 14:44:58 +00:00

45 lines
968 B
Text

# Web framework
fastapi==0.109.0
uvicorn[standard]==0.27.0
python-multipart==0.0.6
# Database
sqlalchemy==2.0.25
asyncpg==0.29.0
psycopg2-binary==2.9.9
# Authentication — python-jose verifies the central hnf_session JWT
python-jose[cryptography]==3.3.0
# OCR — Azure Document Intelligence
azure-ai-formrecognizer==3.3.0
# Image processing
Pillow==10.2.0
# Real content-type sniffing for uploads (A5) — trusts file bytes, not the
# client-supplied Content-Type header. Needs libmagic1 (see Dockerfile).
python-magic==0.4.27
# PDF processing (highlighting non-stock items)
PyMuPDF==1.23.8
# Spreadsheet parsing
openpyxl==3.1.2
# Utilities
pydantic==2.5.3
pydantic-settings==2.1.0
python-dotenv==1.0.0
aiofiles==23.2.1
# Newbook / Resos / HTTP
httpx==0.27.0
apscheduler==3.10.4
# SambaPOS MSSQL integration (sales reads via POS adapter)
aioodbc==0.5.0
pyodbc==5.1.0
# LLM integration (Claude Haiku) — see docs/archive/LLM-MANIFEST.md
anthropic>=0.40.0