aboutsummaryrefslogtreecommitdiff
path: root/jb/views
diff options
context:
space:
mode:
Diffstat (limited to 'jb/views')
-rw-r--r--jb/views/auth.py30
1 files changed, 20 insertions, 10 deletions
diff --git a/jb/views/auth.py b/jb/views/auth.py
index 44fef10..bf39b51 100644
--- a/jb/views/auth.py
+++ b/jb/views/auth.py
@@ -2,7 +2,7 @@ from typing import Annotated
from urllib.parse import urlencode
from fastapi import APIRouter, Depends, HTTPException, Response, status
-from fastapi.responses import HTMLResponse, RedirectResponse
+from fastapi.responses import HTMLResponse, JSONResponse, RedirectResponse
from jb.api.auth import (
SESSION_COOKIE_NAME,
@@ -103,6 +103,12 @@ def link_amt_account(body: AmtAccountLink) -> dict[str, str]:
"""Link an AMT account and login."""
email = str(body.email)
amt_worker_id = body.amt_worker_id
+
+ # TODO! Prevent a user that's already transitioned their account, from being
+ # TODO! able to continuously create this special link token.
+ # TODO! Max Notes: this seems to be handled within the gr-api, and that
+ # TODO! can raise, the following line would / should fail if needed.
+
token = create_amt_account_link_token(email=email, amt_worker_id=amt_worker_id)
if settings.debug:
@@ -110,7 +116,7 @@ def link_amt_account(body: AmtAccountLink) -> dict[str, str]:
return {"magic_link": f"{settings.base_url}auth/link-amt/?{query}"}
send_amt_link_email(email=email, magic_token=token)
- return {"detail": "Link sent. Check your inbox and follow the link to log in."}
+ return {}
@auth_router.get("/link-amt/", response_class=HTMLResponse, include_in_schema=False)
@@ -119,14 +125,18 @@ def link_amt_account_landing_page(
token: str | None = None,
) -> HTMLResponse:
"""Serve the account-link SPA without consuming the one-time token."""
- if settings.debug:
- if token is None:
- raise HTTPException(
- status_code=status.HTTP_400_BAD_REQUEST,
- detail="token is required",
- )
- response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
- _exchange_amt_account_link(token, response, gr_api)
+
+ # TODO! Try catch any of this, and if it fails, show the user a
+ # TODO! failed HTML page. As of now, it shows them a failed JSON response.
+
+ if token is None:
+ raise HTTPException(
+ status_code=status.HTTP_400_BAD_REQUEST,
+ detail="token is required",
+ )
+ _response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER)
+ _exchange_amt_account_link(token=token, response=_response, gr_api=gr_api)
+
return HTMLResponse(
BASE_HTML,
headers={