diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/deps.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/deps.py | 47 |
1 files changed, 47 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/deps.py b/packages/meshbay-hub/src/meshbay_hub/api/deps.py new file mode 100644 index 0000000..cb637f3 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/api/deps.py @@ -0,0 +1,47 @@ +""" +FastAPI shared dependencies — injected via Depends(). +""" + +from collections.abc import AsyncGenerator + +from fastapi import Depends, Header, HTTPException, status +from sqlalchemy.ext.asyncio import AsyncSession +from sqlalchemy import select + +from meshbay_hub.auth import decode_access_token +from meshbay_hub.db.engine import get_db +from meshbay_hub.db.models import User + + +async def get_current_user( + authorization: str = Header(...), + db: AsyncSession = Depends(get_db), +) -> User: + """ + Verify the JWT bearer token and return the User from the database. + Node clients: verified locally with hub PK — no DB round-trip needed. + Hub API (web): must confirm user still exists and is active. + """ + try: + scheme, token = authorization.split(None, 1) + if scheme.lower() != "bearer": + raise ValueError + payload = decode_access_token(token) + except Exception: + raise HTTPException( + status_code=status.HTTP_401_UNAUTHORIZED, + detail="Invalid or expired token", + headers={"WWW-Authenticate": "Bearer"}, + ) + + result = await db.execute( + select(User).where(User.id == payload["sub"])) + user = result.scalar_one_or_none() + + if user is None: + raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, + detail="User not found") + if user.status != "active": + raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, + detail=f"Account {user.status}") + return user |