File size: 2,746 Bytes
18ade12
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
"""
Authentication dependencies for FastAPI routes.

Provides JWT token validation and user authentication.
For development, allows bypassing auth with a mock user.
"""

from fastapi import Depends, HTTPException, status
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials
from pydantic import BaseModel
from typing import Optional
import os

# Security scheme for JWT Bearer token
security = HTTPBearer(auto_error=False)

# Check if we're in development mode (skip auth for testing)
DEV_MODE = os.getenv("DEV_MODE", "true").lower() == "true"


class ValidatedUser(BaseModel):
    """Represents a validated user from JWT token."""
    sub: str  # User ID from JWT subject (Better Auth uses string IDs)
    email: Optional[str] = None
    name: Optional[str] = None


def get_validated_user(
    credentials: Optional[HTTPAuthorizationCredentials] = Depends(security),
) -> ValidatedUser:
    """
    Dependency to validate JWT token and extract user information.

    In development mode, returns a mock user if no token provided.
    In production, validates the JWT token from Better Auth.
    """
    if DEV_MODE and credentials is None:
        # Development mode: use mock user for testing
        return ValidatedUser(
            sub="dev-user-001",
            email="dev@example.com",
            name="Dev User"
        )

    if credentials is None:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Authentication required",
            headers={"WWW-Authenticate": "Bearer"},
        )

    token = credentials.credentials

    try:
        # In production, validate JWT token with Better Auth
        # For now, we'll use a simple validation
        # TODO: Integrate with Better Auth for JWT validation

        # Mock validation for development - accepts any token
        if DEV_MODE:
            return ValidatedUser(
                sub="dev-user-001",
                email="dev@example.com",
                name="Dev User"
            )
        else:
            # Production: Validate with Better Auth
            # This would typically call Better Auth's token validation endpoint
            raise HTTPException(
                status_code=status.HTTP_401_UNAUTHORIZED,
                detail="Token validation not implemented for production",
                headers={"WWW-Authenticate": "Bearer"},
            )
    except HTTPException:
        raise
    except Exception as e:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail=f"Invalid token: {str(e)}",
            headers={"WWW-Authenticate": "Bearer"},
        )


# Alias for backwards compatibility
get_current_user = get_validated_user