Skip to content

Add anonymous analytics and TOTP-protected staff administration - #280

Merged
nonprofittechy merged 3 commits into
mainfrom
feat/162-staff-privacy-analytics
Oct 3, 2026
Merged

nonprofittechy merged 3 commits into
mainfrom
feat/162-staff-privacy-analytics

Conversation

@nonprofittechy

@nonprofittechy nonprofittechy commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

LITEFile needs durable usage reporting and a restricted way to handle account support and verified deletion requests. This adds a private Django staff backend with jurisdiction-scoped account-management and reporting roles, mandatory TOTP for every role (including superusers), and permanent anonymous aggregate counters.

Closes #162.

Changes

  • Collect allowlisted workflow metrics for case types, jurisdictions, new/existing filings, first observed matters, case sides, self/other filing, ZIP codes, and document preparation. Reports and CSV exports use the same filters and suppress small cohorts and related subtotals. Staff, debug, stand-in-document, and designated test traffic are excluded.
  • Provide scoped account lookup, session revocation, and account-wide or selected-filing deletion. The review → verification → permanent confirmation flow inventories original/prepared/historical uploads, erases exact S3 object versions and delete markers, and retains a retry manifest after failures. Frozen drafts, session guards, shared-file/correction blockers, and extraction/submission checks prevent incomplete cleanup from being reported as successful. Anonymous counters survive deletion; backup/provider disposition is tracked separately.
  • Require local passwords plus TOTP with replay protection, throttling, and fifteen-minute staff sessions. Superusers provision staff and independent jurisdiction roles. The configurable staff URL has no public navigation link; native forms retain same-origin CSRF evidence.
  • Add explicit environment-variable bootstrap with no default password and no credential overwrites, local-only synthetic fixtures, and a deployment/recovery/privacy runbook. Bootstrap credentials and local database contents are not committed.

Validation

  • Regression suite: 1,418 passed, 2 skipped, 3 deselected. The three excluded live Tyler profile/authentication tests previously failed because the external test server returned HTTP 403; they were not replaced with mocks or changed.
  • Bootstrap tests generate credentials at runtime; all 11 bootstrap tests passed on the final setup commit.
  • Ruff formatting/lint, template formatting/lint, ty, Bandit, and migration consistency checks passed.
  • Tested migration upgrade from 0030, current/historical upload inventory, production-shaped collection, and TOTP console bootstrap against a temporary SQLite database.
  • Verified native Chromium TOTP sign-in and the complete deletion flow on a temporary synthetic local account. Regression tests cover CSRF/origin rejection, scope separation, S3 failure/retry/version deletion, late saves/uploads, analytics deduplication, suppression, and CSV/dashboard consistency.

Rollout

Apply migrations and provision the initial administrator/TOTP device before use. Collection, export, and deletion switches default off. Enable deletion only after all web/worker instances have upgraded; approve verification, disclosure, retention, and backup/provider procedures before production activation. The existing extraction supervisor rolls up queued usage events, with standalone retry/pruning commands available.

Setup, local demo, IAM requirements, recovery, and data boundaries: staff privacy and analytics runbook.

@gitguardian

gitguardian Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@nonprofittechy
nonprofittechy force-pushed the feat/162-staff-privacy-analytics branch from 439c775 to deb4b69 Compare October 3, 2026 00:29
@nonprofittechy
nonprofittechy merged commit 8b69735 into main Oct 3, 2026
8 checks passed
@nonprofittechy
nonprofittechy deleted the feat/162-staff-privacy-analytics branch October 3, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Collect analytics + allow managing privacy requests

1 participant