- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret) — KDS reads kitchen_db directly (E16), nothing ever called this endpoint - Add expires_at to dispute_attachments; public attachment links now expire after 30 days instead of staying valid forever (A4) - Add services/upload_validation.py: sniff real file content via python-magic instead of trusting the client-supplied Content-Type header, plus a 20MB cap. Applied across invoices/logbook/food_flags/credit_notes/disputes upload endpoints (A5) — disputes previously had no file-type check at all - Fix nginx client_max_body_size drift (800m -> the plan's intended 20m) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
45 lines
968 B
Text
45 lines
968 B
Text
# Web framework
|
|
fastapi==0.109.0
|
|
uvicorn[standard]==0.27.0
|
|
python-multipart==0.0.6
|
|
|
|
# Database
|
|
sqlalchemy==2.0.25
|
|
asyncpg==0.29.0
|
|
psycopg2-binary==2.9.9
|
|
|
|
# Authentication — python-jose verifies the central hnf_session JWT
|
|
python-jose[cryptography]==3.3.0
|
|
|
|
# OCR — Azure Document Intelligence
|
|
azure-ai-formrecognizer==3.3.0
|
|
|
|
# Image processing
|
|
Pillow==10.2.0
|
|
|
|
# Real content-type sniffing for uploads (A5) — trusts file bytes, not the
|
|
# client-supplied Content-Type header. Needs libmagic1 (see Dockerfile).
|
|
python-magic==0.4.27
|
|
|
|
# PDF processing (highlighting non-stock items)
|
|
PyMuPDF==1.23.8
|
|
|
|
# Spreadsheet parsing
|
|
openpyxl==3.1.2
|
|
|
|
# Utilities
|
|
pydantic==2.5.3
|
|
pydantic-settings==2.1.0
|
|
python-dotenv==1.0.0
|
|
aiofiles==23.2.1
|
|
|
|
# Newbook / Resos / HTTP
|
|
httpx==0.27.0
|
|
apscheduler==3.10.4
|
|
|
|
# SambaPOS MSSQL integration (sales reads via POS adapter)
|
|
aioodbc==0.5.0
|
|
pyodbc==5.1.0
|
|
|
|
# LLM integration (Claude Haiku) — see docs/archive/LLM-MANIFEST.md
|
|
anthropic>=0.40.0
|