M0: repo scaffold, backend skeleton, schema + migrations, dev compose, docs

- Apache-2.0, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, issue templates
- FastAPI app with /api/v1 healthz/readyz/system-status (honest AI disclosure)
- Full SQLAlchemy schema (users, devices, refresh tokens, recordings, assets,
  upload sessions, transcripts, summaries, tags, jobs, exports) + Alembic
  migrations incl. Postgres FTS tsvector columns
- Settings via SHONAR_* env only; local + S3 storage abstraction with
  path-traversal-safe keys
- Docker dev compose (postgres+redis, 127.0.0.1-only); CI workflow; scripts
- shared/openapi.json contract generated from app
This commit is contained in:
avi 2026-09-08 13:23:45 -05:00
commit 5fab96e824
46 changed files with 3616 additions and 0 deletions

23
SECURITY.md Normal file
View file

@ -0,0 +1,23 @@
# Security Policy
**Do not open public issues for security problems.** Email the maintainers
directly (see README contact). We aim to acknowledge within 72 hours.
## Scope
- Authentication / authorization bypass
- Data leakage between users
- Path traversal / unauthorized file access
- Injection (SQL, command, template)
- Secrets exposure in API responses
## Out of scope
- Physical device access
- Social engineering
- Vulnerabilities in optional third-party AI providers you configure
## What this project guarantees
See `docs/security.md` for the honest security model, including what is NOT
implemented (at-rest encryption is documented but not enabled by default).