Keep map reads open; gate admin UI/nav and object mutations behind env-based admin credentials, and default parser batch limit to 10. Co-authored-by: Cursor <cursoragent@cursor.com>
27 lines
987 B
Python
27 lines
987 B
Python
import os
|
|
|
|
from fastapi import Header, HTTPException
|
|
|
|
from .auth import decode_access_token
|
|
|
|
|
|
def verify_internal_token(
|
|
x_internal_token: str | None = Header(default=None, alias="X-Internal-Token"),
|
|
) -> None:
|
|
expected = os.getenv("INTERNAL_TOKEN", "dev-internal-token")
|
|
if not x_internal_token or x_internal_token != expected:
|
|
raise HTTPException(status_code=401, detail="Invalid internal token")
|
|
|
|
|
|
def verify_admin(
|
|
authorization: str | None = Header(default=None),
|
|
) -> str:
|
|
"""Require Authorization: Bearer <admin JWT>. Returns username (sub)."""
|
|
if not authorization or not authorization.startswith("Bearer "):
|
|
raise HTTPException(status_code=401, detail="Missing or invalid Authorization header")
|
|
token = authorization.removeprefix("Bearer ").strip()
|
|
if not token:
|
|
raise HTTPException(status_code=401, detail="Missing or invalid Authorization header")
|
|
payload = decode_access_token(token)
|
|
return str(payload["sub"])
|