diff options
Diffstat (limited to 'jb/views/auth.py')
| -rw-r--r-- | jb/views/auth.py | 20 |
1 files changed, 13 insertions, 7 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py index ba1a6f8..e6410a6 100644 --- a/jb/views/auth.py +++ b/jb/views/auth.py @@ -86,8 +86,10 @@ def authenticate_invite_amt_account_link( @auth_router.post("/magic-link/request/") def request_magic_link(body: AccountLogin) -> dict[str, str]: - """Create a magic link.""" - email = str(body.email) + return _request_magic_link(str(body.email)) + + +def _request_magic_link(email: str) -> dict[str, str]: token = create_magic_token(user_email=email) if settings.debug: @@ -181,15 +183,19 @@ def _exchange_magic_link( @auth_router.post("/link-amt/request/") -def link_amt_account(body: AmtAccountLink) -> dict[str, str]: +def link_amt_account( + body: AmtAccountLink, + gr_api: Annotated[GRApiManager, Depends(get_gr_api_manager)], +) -> dict[str, str]: """Link an AMT account and login.""" email = str(body.email) amt_worker_id = body.amt_worker_id - # TODO! Prevent a user that's already transitioned their account, from being - # TODO! able to continuously create this special link token. - # TODO! Max Notes: this seems to be handled within the gr-api, and that - # TODO! can raise, the following line would / should fail if needed. + # If the email already has transitioned, treat this as a login request + user = User.model_validate({"email": email}) + user_exists = gr_api.get_user_if_exists(user.product_user_id) + if user_exists: + return _request_magic_link(email) token = create_amt_account_link_token(email=email, amt_worker_id=amt_worker_id) |
