Spaces:
Runtime error
Runtime error
File size: 2,746 Bytes
18ade12 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 | """
Authentication dependencies for FastAPI routes.
Provides JWT token validation and user authentication.
For development, allows bypassing auth with a mock user.
"""
from fastapi import Depends, HTTPException, status
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials
from pydantic import BaseModel
from typing import Optional
import os
# Security scheme for JWT Bearer token
security = HTTPBearer(auto_error=False)
# Check if we're in development mode (skip auth for testing)
DEV_MODE = os.getenv("DEV_MODE", "true").lower() == "true"
class ValidatedUser(BaseModel):
"""Represents a validated user from JWT token."""
sub: str # User ID from JWT subject (Better Auth uses string IDs)
email: Optional[str] = None
name: Optional[str] = None
def get_validated_user(
credentials: Optional[HTTPAuthorizationCredentials] = Depends(security),
) -> ValidatedUser:
"""
Dependency to validate JWT token and extract user information.
In development mode, returns a mock user if no token provided.
In production, validates the JWT token from Better Auth.
"""
if DEV_MODE and credentials is None:
# Development mode: use mock user for testing
return ValidatedUser(
sub="dev-user-001",
email="dev@example.com",
name="Dev User"
)
if credentials is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Authentication required",
headers={"WWW-Authenticate": "Bearer"},
)
token = credentials.credentials
try:
# In production, validate JWT token with Better Auth
# For now, we'll use a simple validation
# TODO: Integrate with Better Auth for JWT validation
# Mock validation for development - accepts any token
if DEV_MODE:
return ValidatedUser(
sub="dev-user-001",
email="dev@example.com",
name="Dev User"
)
else:
# Production: Validate with Better Auth
# This would typically call Better Auth's token validation endpoint
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Token validation not implemented for production",
headers={"WWW-Authenticate": "Bearer"},
)
except HTTPException:
raise
except Exception as e:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=f"Invalid token: {str(e)}",
headers={"WWW-Authenticate": "Bearer"},
)
# Alias for backwards compatibility
get_current_user = get_validated_user
|