Keep map reads open; gate admin UI/nav and object mutations behind env-based admin credentials, and default parser batch limit to 10. Co-authored-by: Cursor <cursoragent@cursor.com>
42 lines
1.1 KiB
Python
42 lines
1.1 KiB
Python
from fastapi import APIRouter, Depends, HTTPException
|
|
from pydantic import BaseModel, Field
|
|
|
|
from ..auth import (
|
|
admin_credentials_configured,
|
|
create_access_token,
|
|
verify_credentials,
|
|
)
|
|
from ..deps import verify_admin
|
|
|
|
router = APIRouter(prefix="/admin/auth", tags=["auth"])
|
|
|
|
|
|
class LoginRequest(BaseModel):
|
|
username: str = Field(min_length=1)
|
|
password: str = Field(min_length=1)
|
|
|
|
|
|
class TokenResponse(BaseModel):
|
|
access_token: str
|
|
token_type: str = "bearer"
|
|
|
|
|
|
class MeResponse(BaseModel):
|
|
username: str
|
|
role: str = "admin"
|
|
|
|
|
|
@router.post("/login", response_model=TokenResponse)
|
|
def login(payload: LoginRequest):
|
|
if not admin_credentials_configured():
|
|
raise HTTPException(status_code=503, detail="Admin auth is not configured")
|
|
if not verify_credentials(payload.username, payload.password):
|
|
raise HTTPException(status_code=401, detail="Invalid username or password")
|
|
token = create_access_token(username=payload.username.strip())
|
|
return TokenResponse(access_token=token)
|
|
|
|
|
|
@router.get("/me", response_model=MeResponse)
|
|
def me(username: str = Depends(verify_admin)):
|
|
return MeResponse(username=username)
|