aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/deps.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-09 04:39:34 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-09 04:39:34 +0200
commitfb91c4545c757711e1b5fd354ca4b311c89fd2c0 (patch)
treeeb1aee6cc0fb5fc020eed2763009dea5a32eb8ee /packages/meshbay-hub/src/meshbay_hub/api/deps.py
parent77d76421829161df6b1ef628b4e6e051a2c3c2ee (diff)
downloadmeshbay-fb91c4545c757711e1b5fd354ca4b311c89fd2c0.tar.gz
feat(hub): add production hub — config, auth, API routers, tests
config.py: TOML + env var priority. auth.py: Argon2id passwords, JWT EdDSA with jti, refresh token hashed (blake3). Routers: hub (info/pubkey), users (register/login/refresh/pubkeys), nodes (announce/get), groups (create/gek-bundle/gek-retrieve). Rate limiting via slowapi. app.py factory with lifespan. All 40 tests pass (SQLite in-memory, no PostgreSQL required). Fix: remove tests/__init__.py to resolve namespace conflicts. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/deps.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/deps.py47
1 files changed, 47 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/deps.py b/packages/meshbay-hub/src/meshbay_hub/api/deps.py
new file mode 100644
index 0000000..cb637f3
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/api/deps.py
@@ -0,0 +1,47 @@
+"""
+FastAPI shared dependencies — injected via Depends().
+"""
+
+from collections.abc import AsyncGenerator
+
+from fastapi import Depends, Header, HTTPException, status
+from sqlalchemy.ext.asyncio import AsyncSession
+from sqlalchemy import select
+
+from meshbay_hub.auth import decode_access_token
+from meshbay_hub.db.engine import get_db
+from meshbay_hub.db.models import User
+
+
+async def get_current_user(
+ authorization: str = Header(...),
+ db: AsyncSession = Depends(get_db),
+) -> User:
+ """
+ Verify the JWT bearer token and return the User from the database.
+ Node clients: verified locally with hub PK — no DB round-trip needed.
+ Hub API (web): must confirm user still exists and is active.
+ """
+ try:
+ scheme, token = authorization.split(None, 1)
+ if scheme.lower() != "bearer":
+ raise ValueError
+ payload = decode_access_token(token)
+ except Exception:
+ raise HTTPException(
+ status_code=status.HTTP_401_UNAUTHORIZED,
+ detail="Invalid or expired token",
+ headers={"WWW-Authenticate": "Bearer"},
+ )
+
+ result = await db.execute(
+ select(User).where(User.id == payload["sub"]))
+ user = result.scalar_one_or_none()
+
+ if user is None:
+ raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED,
+ detail="User not found")
+ if user.status != "active":
+ raise HTTPException(status_code=status.HTTP_403_FORBIDDEN,
+ detail=f"Account {user.status}")
+ return user