aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/config.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-09 04:39:34 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-09 04:39:34 +0200
commitfb91c4545c757711e1b5fd354ca4b311c89fd2c0 (patch)
treeeb1aee6cc0fb5fc020eed2763009dea5a32eb8ee /packages/meshbay-hub/src/meshbay_hub/config.py
parent77d76421829161df6b1ef628b4e6e051a2c3c2ee (diff)
downloadmeshbay-fb91c4545c757711e1b5fd354ca4b311c89fd2c0.tar.gz
feat(hub): add production hub — config, auth, API routers, tests
config.py: TOML + env var priority. auth.py: Argon2id passwords, JWT EdDSA with jti, refresh token hashed (blake3). Routers: hub (info/pubkey), users (register/login/refresh/pubkeys), nodes (announce/get), groups (create/gek-bundle/gek-retrieve). Rate limiting via slowapi. app.py factory with lifespan. All 40 tests pass (SQLite in-memory, no PostgreSQL required). Fix: remove tests/__init__.py to resolve namespace conflicts. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/config.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/config.py95
1 files changed, 95 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/config.py b/packages/meshbay-hub/src/meshbay_hub/config.py
new file mode 100644
index 0000000..297ace7
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/config.py
@@ -0,0 +1,95 @@
+"""
+MeshBay Hub configuration.
+
+Priority (highest first):
+ 1. Environment variables (MESHBAY_*)
+ 2. Config file (/etc/meshbay/hub.toml or --config)
+ 3. Built-in defaults
+
+Production config file example: /etc/meshbay/hub.toml
+"""
+
+import os
+from dataclasses import dataclass, field
+from pathlib import Path
+
+try:
+ import tomllib
+except ImportError:
+ import tomli as tomllib # type: ignore[no-redef]
+
+DEFAULT_CONFIG_PATHS = [
+ Path("/etc/meshbay/hub.toml"),
+ Path.home() / ".config" / "meshbay" / "hub.toml",
+]
+
+
+@dataclass
+class DatabaseConfig:
+ url: str = "sqlite+aiosqlite:///:memory:"
+
+
+@dataclass
+class ServerConfig:
+ host: str = "127.0.0.1"
+ port: int = 8000
+ workers: int = 1
+
+
+@dataclass
+class HubIdentityConfig:
+ id: str = "meshbay.org"
+ private_key_path: Path = field(default_factory=lambda:
+ Path.home() / ".config" / "meshbay" / "hub_private.pem")
+
+
+@dataclass
+class JWTConfig:
+ access_token_ttl: int = 3600 # 1 hour
+ refresh_token_ttl: int = 86400 * 30 # 30 days
+
+
+@dataclass
+class HubConfig:
+ db: DatabaseConfig = field(default_factory=DatabaseConfig)
+ server: ServerConfig = field(default_factory=ServerConfig)
+ identity: HubIdentityConfig = field(default_factory=HubIdentityConfig)
+ jwt: JWTConfig = field(default_factory=JWTConfig)
+
+
+def load_config(path: Path | None = None) -> HubConfig:
+ cfg = HubConfig()
+
+ # Find and load TOML
+ candidates = [path] if path else DEFAULT_CONFIG_PATHS
+ for p in candidates:
+ if p and p.exists():
+ raw = tomllib.loads(p.read_text())
+ if db := raw.get("database", {}):
+ cfg.db.url = db.get("url", cfg.db.url)
+ if srv := raw.get("server", {}):
+ cfg.server.host = srv.get("host", cfg.server.host)
+ cfg.server.port = srv.get("port", cfg.server.port)
+ cfg.server.workers = srv.get("workers", cfg.server.workers)
+ if idn := raw.get("hub", {}):
+ cfg.identity.id = idn.get("id", cfg.identity.id)
+ if kp := idn.get("private_key_path"):
+ cfg.identity.private_key_path = Path(kp).expanduser()
+ if jwt := raw.get("jwt", {}):
+ cfg.jwt.access_token_ttl = jwt.get("access_token_ttl", cfg.jwt.access_token_ttl)
+ cfg.jwt.refresh_token_ttl = jwt.get("refresh_token_ttl", cfg.jwt.refresh_token_ttl)
+ break
+
+ # Env var overrides
+ if url := os.environ.get("MESHBAY_DATABASE_URL"):
+ cfg.db.url = url
+ if host := os.environ.get("MESHBAY_HUB_HOST"):
+ cfg.server.host = host
+ if port := os.environ.get("MESHBAY_HUB_PORT"):
+ cfg.server.port = int(port)
+ if hub_id := os.environ.get("MESHBAY_HUB_ID"):
+ cfg.identity.id = hub_id
+ if kp := os.environ.get("MESHBAY_HUB_KEY"):
+ cfg.identity.private_key_path = Path(kp).expanduser()
+
+ return cfg