Skip to content

Repository wiki skeleton

Wiki skeleton

Coverage plan

Core navigation and repository map

  • /openwiki/quickstart.md — entrypoint and task-routing index for the whole wiki; will summarize the major systems, top-level entrypoints, and narrow validation commands.

API routing and deployment entrypoints

  • /openwiki/api/routing.md — API root, versioned/unversioned routing, legacy redirects, API docs endpoints, and the actual request entry path from project URLs to v1 handlers.
  • /openwiki/operations/deployment-entrypoints.md — project URL configuration, debug-toolbar/media exposure in dev, double-version workaround, admin/auth roots, and deployment-facing server routes.

API surface

  • /openwiki/api/overview.md — API gateway, versioning, route families, auth layers, and the cross-cutting request/response/error contract conventions.
  • /openwiki/api/authentication.md — login, refresh, Microsoft auth, API key auth, JWT helpers, and auth-specific tests.
  • /openwiki/api/documents.md — document upload, task polling, document status, metaprocessing, file management, and the async upload pipeline.
  • /openwiki/api/schemas.md — schema CRUD, generation endpoints, import/export, schema versioning, and schema-tenant boundaries.
  • /openwiki/api/tenancy.md — tenant viewsets, tenant switching, tenant membership, tenant-aware permissions, and row-scoped access rules.
  • /openwiki/api/billing.md — billing plan, usage, invoices, payment methods, and org invite flows.
  • /openwiki/api/rules.md — pre/post-processing rules APIs, schema-scoped filtering, and rule validation behavior.
  • /openwiki/api/analytics.md — activity logs, stats, filter options, and analytics endpoints.
  • /openwiki/api/chatbot.md — chatbot endpoint and response shape.
  • /openwiki/api/security.md — CSP reporting, consent, license acceptance, and security-related endpoints.
  • /openwiki/api/files.md — file upload, file serving, preview, cache/JWT access, and storage integration.

Authentication, tenancy, and security details

  • /openwiki/auth/overview.md — JWT utilities, Microsoft auth, API key auth, and identity resolution.
  • /openwiki/auth/login-and-token.md — login, refresh token issuance, throttling, and token payload shape.
  • /openwiki/auth/microsoft-sso.md — Microsoft auth flow, tenant metadata issuance, and cross-checks against internal users.
  • /openwiki/tenancy/overview.md — tenant-aware managers, middleware, RLS, and tenancy migrations.
  • /openwiki/tenancy/access-control.md — tenant resolution, membership checks, and auth-to-tenant coupling.
  • /openwiki/tenancy/manager-behavior.md — global/shared rows, filtered managers, and unfiltered access patterns.
  • /openwiki/tenancy/background-access.md — worker and signal code paths that bypass request-scoped tenant resolution.
  • /openwiki/security/overview.md — auth, consent, API keys, CSRF/CSP, and tenant-bound security invariants.
  • /openwiki/security/endpoints.md — API-key, consent, license, and CSP endpoints.
  • /openwiki/security/secrets-and-headers.md — security-sensitive headers, env gates, and external scanner/API-key contracts.
  • /openwiki/security/virus-scan-gate.md — file safety scanning gate and failure modes.

Schema subsystem

  • /openwiki/schemas/overview.md — schema data model, schema versioning, schema value contract, rule attachments, tenant isolation, and schemas’ role in document processing.
  • /openwiki/schemas/generation.md — synchronous and async schema generation request lifecycle, job state machine, cleanup, and service internals.
  • /openwiki/schemas/versioning.md — schema chain semantics, current-version rules, and max-version cleanup.
  • /openwiki/schemas/tenant-boundaries.md — schema tenant scoping, rule tenant filtering, and consumer visibility.
  • /openwiki/schemas/import-export.md — schema import/export surfaces and round-trip constraints.
  • /openwiki/schemas/rules.md — rule linkage semantics and validation workflow.

Document subsystem

  • /openwiki/documents/overview.md — ProcessingDocument model, status lifecycle, edit history, status endpoints, and document list/query behavior.
  • /openwiki/documents/state-machine.md — ProcessingDocument lifecycle, task correlation, and status transitions.
  • /openwiki/documents/polling-and-signals.md — task polling semantics, signal-driven downstream effects, and verification/rejection behavior.
  • /openwiki/documents/upload-processing.md — upload request validation, orchestration, Celery task flow, fallback path, and persistence invariants.
  • /openwiki/documents/file-management.md — reusable file uploads, preview generation, duplicate detection, and storage backends.
  • /openwiki/documents/classification.md — agent document classification, mixed-content handling, and page filtering.
  • /openwiki/documents/edit-history.md — audit diff format, patch rules, and one-time edit constraints.
  • /openwiki/documents/rejection-flow.md — rejection report endpoint, external-service callbacks, and document/submission update semantics.

File serving and previews

  • /openwiki/files/serving-and-previews.md — secure file serving, cache/JWT access, processed-image delivery, browser disposition, and preview semantics.

Services and background execution

  • /openwiki/services/overview.md — service-layer architecture, major pipelines, shared dependencies, and cross-service call graph.
  • /openwiki/services/async-pipelines.md — upload-processing and schema-generation worker pipelines, queueing, on_commit dispatch, and end-to-end flow maps.
  • /openwiki/services/worker-failures.md — fallback execution, retries, cleanup hooks, and partial-failure handling.
  • /openwiki/services/litellm.md — LiteLLM routing, content extraction, payload logging, and model-family selection.
  • /openwiki/services/pdf-processing.md — PDF extraction, OCR, page classification, confidence scoring, and mixed-content handling.
  • /openwiki/services/upload-processing.md — orchestration, repositories, strategies, validators, tasks, and response normalization.
  • /openwiki/services/storage.md — storage factory and backend implementations (Azure, GCP, S3, SFTP).
  • /openwiki/services/pii.md — PII masking and Presidio client integration.
  • /openwiki/services/prompt-generation.md — prompt generation, sanitization, and template assembly.
  • /openwiki/services/schema-import-export.md — schema import/export service internals and validation boundaries.
  • /openwiki/services/parallel-processing.md — parallel PDF execution, page processor, and database handler coordination.
  • /openwiki/services/virus-scan.md — virus scanning service contract and file safety gate.

Business domains

  • /openwiki/billing/overview.md — billing data model, tenant access controls, and settings-area integration.
  • /openwiki/billing/usage-metrics.md — usage aggregation, plan source-of-truth, and AIStudioProcessing-derived counters.
  • /openwiki/billing/invoices-and-payment-methods.md — invoice PDF generation, payment-method storage, and download semantics.
  • /openwiki/analytics/dashboard-endpoints.md — dashboard chart endpoints, time windows, and failure isolation.
  • /openwiki/chatbot/overview.md — chatbot request/response contract and public access assumptions.

Data, tenancy, and persistence

  • /openwiki/architecture/models.md — core model inventory and relationship map across schemas, documents, tenants, billing, activity logs, and polling jobs.
  • /openwiki/architecture/domain-models.md — canonical entity graph, stable identifiers, and ownership edges.
  • /openwiki/architecture/persistence-invariants.md — unique constraints, tenant-scoped reads/writes, soft-delete style behavior, and version limits.
  • /openwiki/architecture/polling-owned-tables.md — unmanaged polling-service tables, submission records, delivery flags, and backend read/join-only access contract.
  • /openwiki/architecture/migrations.md — important schema and data migrations that define invariants and operational history.

Tests and verification

  • /openwiki/tests/overview.md — how the test suite is organized, what each major area validates, and which suites to run for targeted changes.
  • /openwiki/tests/contract-matrix.md — map from intent to the contract tests that prove it.
  • /openwiki/tests/auth-and-tenancy.md — auth, token, membership, and tenant-scoping tests.
  • /openwiki/tests/schema-generation.md — schema generation, CRUD, async job, versioning, and import/export tests.
  • /openwiki/tests/async-upload.md — upload submission, background processing, and task polling tests.
  • /openwiki/tests/files-and-security.md — file upload/serve/preview, consent, CSP, and security-gate tests.
  • /openwiki/tests/analytics-and-billing.md — analytics aggregation and billing settings tests.
  • /openwiki/tests/services.md — service-layer unit tests and focused behavioral checks.
  • /openwiki/tests/storage.md — storage backend and virus scan tests.

Evidence brief status

  • API route inventory reviewed from api/urls.py, api/versions/v1_urls.py, and backend_project/urls.py.
  • Schema generation flow reviewed across api/views/schema_views/, api/schema_generator/tasks.py, and api/schema_generator/services/schema_generator_service/schema_generator.py.
  • Document upload and polling flow reviewed across api/views/upload_processing_view.py, api/services/upload_processing/tasks.py, api/views/task_status_view.py, and document models.
  • Rule, auth, file, billing, tenant, analytics, and document-processing surfaces identified from the v1 router and representative view files.
  • Representative tests identified under tests/unit/** and tests/integration/**.

Planned page notes

  • The schema pages will document both the synchronous generation path and the queued job path, including the SchemaGenerationJob state machine and cleanup behavior.
  • The document pages will split upload processing from generic file management because they have different persistence models, lifecycles, and consumers.
  • The services pages will group shared execution pipelines rather than mirror the directory tree, so readers can follow end-to-end flows from view to worker to model.
  • The security/auth/tenancy pages will explain how Microsoft auth, session auth, API keys, and tenant scoping interact at runtime.