aboutsummaryrefslogtreecommitdiff
path: root/jb/views/auth.py
diff options
context:
space:
mode:
authorstuppie2026-09-01 11:56:05 -0600
committerstuppie2026-09-01 11:56:05 -0600
commitc991d4f51254b1c81fa6e0e19b0ba94b8c5f61c4 (patch)
tree34598a150db7c85b7e0ee50d1ced31bda74d271c /jb/views/auth.py
parent3f8d178d38686c1a5d71d94ebccdb61701469e95 (diff)
downloadamt-jb-c991d4f51254b1c81fa6e0e19b0ba94b8c5f61c4.tar.gz
amt-jb-c991d4f51254b1c81fa6e0e19b0ba94b8c5f61c4.zip
add GRApiManager. py-utils to generalresearch
Diffstat (limited to 'jb/views/auth.py')
-rw-r--r--jb/views/auth.py36
1 files changed, 27 insertions, 9 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py
index 0591294..06dbdde 100644
--- a/jb/views/auth.py
+++ b/jb/views/auth.py
@@ -6,8 +6,9 @@ has resolved an email address to its stable user identifier, call
"""
from typing import Annotated
+from urllib.parse import urlencode
-from fastapi import APIRouter, Depends, Response, status
+from fastapi import APIRouter, Depends, HTTPException, Response, status
from fastapi.responses import HTMLResponse
from jb.api.auth import (
@@ -15,11 +16,13 @@ from jb.api.auth import (
create_session,
get_authenticated_user,
)
-from jb.api.magic_token import consume_magic_token
+from jb.api.magic_token import consume_magic_token, create_magic_token
from jb.config import settings
+from jb.decorators import gr_api_manager
from jb.models.auth import (
MagicLinkExchangeRequest,
- AuthenticatedUser,
+ AccountLogin,
+ User,
email_to_product_user_id,
)
from jb.settings import BASE_HTML
@@ -27,6 +30,20 @@ from jb.settings import BASE_HTML
auth_router = APIRouter(prefix="/auth", tags=["Auth"])
+@auth_router.post("/magic-link/request")
+def request_mock_magic_link(body: AccountLogin) -> dict[str, str]:
+ """Create a magic link without sending email in development."""
+ if not settings.debug:
+ raise HTTPException(status_code=status.HTTP_404_NOT_FOUND)
+
+ # todo: send email here
+
+ user = User(email=body.email)
+ token = create_magic_token(str(user.email))
+ query = urlencode({"token": token})
+ return {"magic_link": f"/auth/magic-link/?{query}"}
+
+
@auth_router.get("/magic-link/", response_class=HTMLResponse, include_in_schema=False)
def magic_link_landing_page() -> HTMLResponse:
"""Serve the SPA without redeeming the token; email prefetches are harmless."""
@@ -44,11 +61,12 @@ def magic_link_landing_page() -> HTMLResponse:
def exchange_magic_link(body: MagicLinkExchangeRequest, response: Response) -> None:
"""Exchange a magic link only after its landing page makes an explicit POST."""
user_email = consume_magic_token(body.token)
- product_user_id = email_to_product_user_id(user_email)
- # todo: hit thl to make sure this user exists
+ user = User.model_validate({'email': user_email})
+ # hit thl to make sure this user exists
+ user = gr_api_manager.ensure_user_exists(user)
- session_token = create_session(product_user_id)
+ session_token = create_session(user.product_user_id)
response.set_cookie(
key=SESSION_COOKIE_NAME,
value=session_token,
@@ -60,10 +78,10 @@ def exchange_magic_link(body: MagicLinkExchangeRequest, response: Response) -> N
)
-@auth_router.get("/session", response_model=AuthenticatedUser)
+@auth_router.get("/session", response_model=User)
def get_session(
- user: Annotated[AuthenticatedUser, Depends(get_authenticated_user)],
-) -> AuthenticatedUser:
+ user: Annotated[User, Depends(get_authenticated_user)],
+) -> User:
return user