From edff9381275d90d7be5f078430554ae592a27f5d Mon Sep 17 00:00:00 2001 From: Max Nanis Date: Fri, 11 Sep 2026 11:27:58 -0700 Subject: Current jb flask testing state. --- jb/views/auth.py | 30 ++++++++++++++++++++---------- 1 file changed, 20 insertions(+), 10 deletions(-) (limited to 'jb/views') diff --git a/jb/views/auth.py b/jb/views/auth.py index 44fef10..bf39b51 100644 --- a/jb/views/auth.py +++ b/jb/views/auth.py @@ -2,7 +2,7 @@ from typing import Annotated from urllib.parse import urlencode from fastapi import APIRouter, Depends, HTTPException, Response, status -from fastapi.responses import HTMLResponse, RedirectResponse +from fastapi.responses import HTMLResponse, JSONResponse, RedirectResponse from jb.api.auth import ( SESSION_COOKIE_NAME, @@ -103,6 +103,12 @@ def link_amt_account(body: AmtAccountLink) -> dict[str, str]: """Link an AMT account and login.""" email = str(body.email) amt_worker_id = body.amt_worker_id + + # TODO! Prevent a user that's already transitioned their account, from being + # TODO! able to continuously create this special link token. + # TODO! Max Notes: this seems to be handled within the gr-api, and that + # TODO! can raise, the following line would / should fail if needed. + token = create_amt_account_link_token(email=email, amt_worker_id=amt_worker_id) if settings.debug: @@ -110,7 +116,7 @@ def link_amt_account(body: AmtAccountLink) -> dict[str, str]: return {"magic_link": f"{settings.base_url}auth/link-amt/?{query}"} send_amt_link_email(email=email, magic_token=token) - return {"detail": "Link sent. Check your inbox and follow the link to log in."} + return {} @auth_router.get("/link-amt/", response_class=HTMLResponse, include_in_schema=False) @@ -119,14 +125,18 @@ def link_amt_account_landing_page( token: str | None = None, ) -> HTMLResponse: """Serve the account-link SPA without consuming the one-time token.""" - if settings.debug: - if token is None: - raise HTTPException( - status_code=status.HTTP_400_BAD_REQUEST, - detail="token is required", - ) - response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER) - _exchange_amt_account_link(token, response, gr_api) + + # TODO! Try catch any of this, and if it fails, show the user a + # TODO! failed HTML page. As of now, it shows them a failed JSON response. + + if token is None: + raise HTTPException( + status_code=status.HTTP_400_BAD_REQUEST, + detail="token is required", + ) + _response = RedirectResponse(url="/", status_code=status.HTTP_303_SEE_OTHER) + _exchange_amt_account_link(token=token, response=_response, gr_api=gr_api) + return HTMLResponse( BASE_HTML, headers={ -- cgit v1.2.3