|
| 1 | +import jwt |
| 2 | + |
| 3 | +from fastapi.security import ( |
| 4 | + OAuth2PasswordBearer, |
| 5 | + OAuth2PasswordRequestForm, |
| 6 | + APIKeyHeader, |
| 7 | + APIKeyQuery, |
| 8 | +) |
| 9 | +from pydantic import BaseModel |
| 10 | +from datetime import timedelta, datetime, timezone |
| 11 | +from .config import env_vars |
| 12 | +from typing import Annotated |
| 13 | +from fastapi import Depends, HTTPException, status |
| 14 | + |
| 15 | + |
| 16 | +oauth2_scheme = OAuth2PasswordBearer( |
| 17 | + tokenUrl="token", |
| 18 | +) |
| 19 | + |
| 20 | + |
| 21 | +class Token(BaseModel): |
| 22 | + access_token: str |
| 23 | + token_type: str |
| 24 | + |
| 25 | + |
| 26 | +class TokenData(BaseModel): |
| 27 | + username: str | None = None |
| 28 | + |
| 29 | + |
| 30 | +def check_creds(username: str, password: str): |
| 31 | + if username == env_vars["USERNAME"] and password == env_vars["PASSWORD"]: |
| 32 | + return True |
| 33 | + raise HTTPException( |
| 34 | + status_code=status.HTTP_401_UNAUTHORIZED, |
| 35 | + detail="Creds for worker job not correct", |
| 36 | + ) |
| 37 | + |
| 38 | + |
| 39 | +def create_access_token(data: dict, expires_delta: timedelta | None = None): |
| 40 | + to_encode = data.copy() |
| 41 | + if expires_delta: |
| 42 | + expire = datetime.now(timezone.utc) + expires_delta |
| 43 | + else: |
| 44 | + expire = datetime.now(timezone.utc) + timedelta( |
| 45 | + minutes=env_vars["ACCESS_TOKEN_EXPIRE_MINUTES"] |
| 46 | + ) |
| 47 | + to_encode.update({"exp": expire}) |
| 48 | + encoded_jwt = jwt.encode( |
| 49 | + to_encode, env_vars["SECRET_KEY"], algorithm=env_vars["ALGORITHM"] |
| 50 | + ) |
| 51 | + return encoded_jwt |
| 52 | + |
| 53 | + |
| 54 | +async def get_current_username( |
| 55 | + token: Annotated[str, Depends(oauth2_scheme)], |
| 56 | +) -> str: |
| 57 | + credentials_exception = HTTPException( |
| 58 | + status_code=status.HTTP_401_UNAUTHORIZED, |
| 59 | + detail="Could not validate credentials", |
| 60 | + headers={"WWW-Authenticate": "Bearer"}, |
| 61 | + ) |
| 62 | + username = "" |
| 63 | + try: |
| 64 | + payload = jwt.decode( |
| 65 | + token, env_vars["SECRET_KEY"], algorithms=env_vars["ALGORITHM"] |
| 66 | + ) |
| 67 | + username = payload.get("sub") |
| 68 | + if username is None: |
| 69 | + raise credentials_exception |
| 70 | + token_data = TokenData(username=username) |
| 71 | + except InvalidTokenError: |
| 72 | + raise credentials_exception |
| 73 | + if token_data.username != env_vars["USERNAME"]: |
| 74 | + raise credentials_exception |
| 75 | + return username |
0 commit comments