"""SQLAlchemy model for the users table.""" # Import uuid import uuid from sqlalchemy import Column, String, Boolean, DateTime, func from sqlalchemy.dialects.postgresql import UUID, JSONB # Import Base from app.database from app.database import Base # Define class User class User(Base): """User model for authentication and authorization. Possible roles: - admin: Full system access - red_tech: Red team technician - can create and edit tests - blue_tech: Blue team technician - can create and edit tests - red_lead: Red team lead - can validate tests - blue_lead: Blue team lead - can validate tests - viewer: Read-only access (default) """ # Assign __tablename__ = "users" __tablename__ = "users" # Assign id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4) id = Column(UUID(as_uuid=True), primary_key=True, default=uuid.uuid4) # Assign username = Column(String, unique=True, nullable=False) username = Column(String, unique=True, nullable=False) # Assign email = Column(String, nullable=True) email = Column(String, nullable=True) # Assign hashed_password = Column(String, nullable=False) hashed_password = Column(String, nullable=False) # Assign role = Column(String, nullable=False, default="viewer") role = Column(String, nullable=False, default="viewer") # Assign is_active = Column(Boolean, default=True) is_active = Column(Boolean, default=True) # Assign must_change_password = Column(Boolean, default=True) must_change_password = Column(Boolean, default=True) # Assign created_at = Column(DateTime(timezone=True), server_default=func.now()) created_at = Column(DateTime(timezone=True), server_default=func.now()) # Assign last_login = Column(DateTime, nullable=True) last_login = Column(DateTime, nullable=True) notification_preferences = Column(JSONB, nullable=True, server_default='{"email_on_test_validated": true, "email_on_campaign_completed": true, "email_on_new_mitre_techniques": false, "in_app_all": true}') jira_account_id = Column(String(100), nullable=True) jira_api_token = Column(String(500), nullable=True) # personal Atlassian token jira_email = Column(String(255), nullable=True) # Atlassian email (overrides account email) tempo_api_token = Column(String(500), nullable=True) # personal Tempo API token