diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-08-11 11:50:08 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-08-11 11:50:08 +0200 |
| commit | c8f2de4025ea67b579e66cf608f08a8d35ee4a3c (patch) | |
| tree | ae1261441af3ca372ce0e89c0000c5c1616dfc8d /packages/meshbay-hub/src/meshbay_hub/api/deps.py | |
| parent | 441ef090055ff4f8c47e78826e0a992f45d918dc (diff) | |
| download | meshbay-c8f2de4025ea67b579e66cf608f08a8d35ee4a3c.tar.gz | |
feat(hub): Phase 10.1–10.4 — Site overlay + admin/moderation UI
- Site overlay: landing page, /about, /downloads (dark/light, responsive)
- User role column (user/moderator/admin) with config-based admin sync
- require_moderator dependency + admin API (8 endpoints: stats, users,
groups, audit logs)
- Admin SPA panel at #/admin with 5 tabs (stats, users, groups, logs,
blocklist) — visible only to moderators/admins
- SPA also served at /app/ for Caddy site overlay integration
- GET /v1/users/me returns current user role
- 15 new tests, 147 total passing
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/deps.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/deps.py | 13 |
1 files changed, 12 insertions, 1 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/deps.py b/packages/meshbay-hub/src/meshbay_hub/api/deps.py index 7a580ad..addba30 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/deps.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/deps.py @@ -52,10 +52,21 @@ async def get_current_user( return user +async def require_moderator( + current_user: User = Depends(get_current_user), +) -> User: + if current_user.role not in ("moderator", "admin") \ + and current_user.username not in _admin_usernames: + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, + detail="Moderator access required") + return current_user + + async def require_admin( current_user: User = Depends(get_current_user), ) -> User: - if current_user.username not in _admin_usernames: + if current_user.role != "admin" \ + and current_user.username not in _admin_usernames: raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail="Admin access required") return current_user |