diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api')
13 files changed, 86 insertions, 67 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/admin.py b/packages/meshbay-hub/src/meshbay_hub/api/admin.py index 7ca1e68..b4b2f4f 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/admin.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/admin.py @@ -6,19 +6,18 @@ Separate from moderation.py (which handles public reporting and content blocklis """ import logging -from datetime import datetime, timezone from fastapi import APIRouter, Depends, HTTPException, Query from pydantic import BaseModel from sqlalchemy import func, select from sqlalchemy.ext.asyncio import AsyncSession -from meshbay_hub.auth import decrypt_email +from meshbay_hub import hub_settings from meshbay_hub.api.deps import require_admin, require_moderator, user_is_admin from meshbay_hub.api.revocation import get_connected_node_count, is_node_connected +from meshbay_hub.auth import decrypt_email from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import Group, GroupMember, IPLog, Node, User -from meshbay_hub import hub_settings log = logging.getLogger(__name__) @@ -318,7 +317,8 @@ async def admin_patch_user( if body.role not in ("user", "moderator", "admin"): raise HTTPException(status_code=422, detail="role must be user, moderator, or admin") user.role = body.role - log.info("User %s role changed to %s by %s", user.username, body.role, current_user.username) + log.info("User %s role changed to %s by %s", + user.username, body.role, current_user.username) await create_notification( db, user.id, "role_change", f"Your role has been changed to {body.role}", @@ -326,7 +326,9 @@ async def admin_patch_user( if body.status is not None: if body.status not in ("active", "suspended", "revoked"): - raise HTTPException(status_code=422, detail="status must be active, suspended, or revoked") + raise HTTPException( + status_code=422, + detail="status must be active, suspended, or revoked") user.status = body.status log.info("User %s status changed to %s by %s", user.username, body.status, current_user.username) @@ -484,7 +486,9 @@ async def admin_patch_group( if body.status is not None: if body.status not in ("active", "suspended", "revoked"): - raise HTTPException(status_code=422, detail="status must be active, suspended, or revoked") + raise HTTPException( + status_code=422, + detail="status must be active, suspended, or revoked") group.status = body.status log.info("Group %s status changed to %s by %s", group.name, body.status, current_user.username) diff --git a/packages/meshbay-hub/src/meshbay_hub/api/deps.py b/packages/meshbay-hub/src/meshbay_hub/api/deps.py index 907a481..501be9d 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/deps.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/deps.py @@ -8,8 +8,8 @@ JWT scope enforcement: """ from fastapi import Depends, Header, HTTPException, status -from sqlalchemy.ext.asyncio import AsyncSession from sqlalchemy import select +from sqlalchemy.ext.asyncio import AsyncSession from meshbay_hub.auth import decode_access_token from meshbay_hub.db.engine import get_db diff --git a/packages/meshbay-hub/src/meshbay_hub/api/federation.py b/packages/meshbay-hub/src/meshbay_hub/api/federation.py index 9e252c6..755639e 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/federation.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/federation.py @@ -23,18 +23,18 @@ Protocol version: MHP 0.1 import logging import time import uuid +from datetime import UTC import jwt -from fastapi import APIRouter, Depends, HTTPException, Header +from fastapi import APIRouter, Depends, Header, HTTPException +from meshbay_common import MHP_VERSION from pydantic import BaseModel from sqlalchemy import func, select from sqlalchemy.ext.asyncio import AsyncSession -from meshbay_common import MHP_VERSION from meshbay_hub import __version__, hub_settings from meshbay_hub.api.deps import require_admin -from meshbay_hub.auth import ( - hub_id, hub_private_key_pem, hub_public_key_pem) +from meshbay_hub.auth import hub_id, hub_private_key_pem, hub_public_key_pem from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import FederatedGroup, Group, HubPeer, User @@ -244,8 +244,8 @@ async def receive_directory( if len(body.groups) > MAX_FEDERATED_GROUPS_PER_PUSH: raise HTTPException(status_code=413, detail="Too many groups in one push") - from datetime import datetime, timezone - now = datetime.now(timezone.utc) + from datetime import datetime + now = datetime.now(UTC) have = await db.scalar( select(func.count()).select_from(FederatedGroup) .where(FederatedGroup.source_hub == sender)) or 0 diff --git a/packages/meshbay-hub/src/meshbay_hub/api/groups.py b/packages/meshbay-hub/src/meshbay_hub/api/groups.py index 72ba194..3a11345 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/groups.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/groups.py @@ -1,22 +1,27 @@ """Group endpoints — /v1/groups/*""" import re +from datetime import UTC, datetime from fastapi import APIRouter, Depends, HTTPException, Query, Request from pydantic import BaseModel -from datetime import datetime, timezone from sqlalchemy import func, or_, select, update from sqlalchemy.exc import IntegrityError from sqlalchemy.ext.asyncio import AsyncSession from meshbay_hub import hub_settings, mail -from meshbay_hub.auth import decrypt_email from meshbay_hub.api.deps import get_current_user, require_user_scope from meshbay_hub.api.middleware import limiter from meshbay_hub.api.netutil import client_ip +from meshbay_hub.auth import decrypt_email from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import ( - FederatedGroup, Group, GroupMember, IPLog, SwarmSource, User, + FederatedGroup, + Group, + GroupMember, + IPLog, + SwarmSource, + User, ) router = APIRouter(prefix="/v1/groups", tags=["groups"]) @@ -97,7 +102,7 @@ async def touch_group_activity( await db.execute( update(Group) .where(Group.id == group_id) - .values(last_activity_at=datetime.now(timezone.utc))) + .values(last_activity_at=datetime.now(UTC))) await db.commit() return {"ok": True} @@ -261,9 +266,9 @@ async def swarm_register( detail="endpoint must be '<webrtc|quic>:<port>' — a port on the " "registering node, not an address") - from datetime import datetime, timezone + from datetime import datetime existing = await db.get(SwarmSource, (body.content_hash, current_user.id)) - now = datetime.now(timezone.utc) + now = datetime.now(UTC) if existing: existing.endpoint = body.endpoint existing.last_seen = now @@ -297,8 +302,8 @@ async def swarm_sources( Authenticated (H7): an open endpoint lets anyone probe whether a given file exists anywhere in the network and which node holds it. """ - from datetime import datetime, timezone, timedelta - cutoff = datetime.now(timezone.utc) - timedelta(minutes=30) + from datetime import datetime, timedelta + cutoff = datetime.now(UTC) - timedelta(minutes=30) result = await db.execute( select(SwarmSource) .where( diff --git a/packages/meshbay-hub/src/meshbay_hub/api/hub.py b/packages/meshbay-hub/src/meshbay_hub/api/hub.py index 94e9b3c..cab60c8 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/hub.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/hub.py @@ -1,9 +1,9 @@ """Hub info endpoints — /v1/hub/*""" from fastapi import APIRouter, Depends +from meshbay_common import MHP_VERSION, MNP_VERSION from sqlalchemy.ext.asyncio import AsyncSession -from meshbay_common import MNP_VERSION, MHP_VERSION from meshbay_hub import __version__, hub_settings from meshbay_hub.api import federation from meshbay_hub.auth import hub_public_key_pem diff --git a/packages/meshbay-hub/src/meshbay_hub/api/moderation.py b/packages/meshbay-hub/src/meshbay_hub/api/moderation.py index ee10cbc..35c688c 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/moderation.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/moderation.py @@ -23,7 +23,6 @@ Node integration: """ import logging -from datetime import datetime, timezone from fastapi import APIRouter, Depends, HTTPException, Query, Request from pydantic import BaseModel diff --git a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py index 83b60f2..7478173 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py @@ -1,20 +1,20 @@ """Node endpoints — /v1/nodes/*""" -from datetime import datetime, timezone import base64 import time +from datetime import UTC, datetime -from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey from cryptography.exceptions import InvalidSignature +from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey from fastapi import APIRouter, Depends, HTTPException, Request from pydantic import BaseModel from sqlalchemy import func, select from sqlalchemy.ext.asyncio import AsyncSession -from meshbay_hub.auth import issue_access_token from meshbay_hub.api.deps import get_current_user from meshbay_hub.api.middleware import limiter from meshbay_hub.api.netutil import client_ip +from meshbay_hub.auth import issue_access_token from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import GroupMember, IPLog, Node, User @@ -156,7 +156,7 @@ async def announce_node( if node is not None: node.endpoint_hint = body.endpoint_hint node.observed_ip = seen_from - node.last_seen = datetime.now(timezone.utc) + node.last_seen = datetime.now(UTC) db.add(IPLog(user_id=current_user.id, event="node_announce", ip_address=seen_from, detail=body.endpoint_hint)) await db.commit() @@ -182,7 +182,7 @@ async def announce_node( pk_node=body.pk_node, endpoint_hint=body.endpoint_hint, observed_ip=seen_from, - last_seen=datetime.now(timezone.utc), + last_seen=datetime.now(UTC), ) db.add(node) db.add(IPLog( diff --git a/packages/meshbay-hub/src/meshbay_hub/api/notifications.py b/packages/meshbay-hub/src/meshbay_hub/api/notifications.py index b5783ab..d96ec18 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/notifications.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/notifications.py @@ -19,9 +19,9 @@ migration for no gain, and `unread_only` stays because it is what an older interface asks for and it still answers correctly — every row is unread. """ -from fastapi import APIRouter, Depends, HTTPException, Query -from datetime import datetime, timezone +from datetime import UTC, datetime +from fastapi import APIRouter, Depends, HTTPException, Query from sqlalchemy import delete, func, select from sqlalchemy.ext.asyncio import AsyncSession @@ -182,7 +182,7 @@ async def create_notification( existing.detail = detail existing.link = link existing.read = False - existing.created_at = datetime.now(timezone.utc) + existing.created_at = datetime.now(UTC) await db.flush() return existing diff --git a/packages/meshbay-hub/src/meshbay_hub/api/relay.py b/packages/meshbay-hub/src/meshbay_hub/api/relay.py index 08d935b..7bb3f66 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/relay.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/relay.py @@ -102,7 +102,8 @@ async def relay_register( approved = _relays.get(body.relay_id) if not approved or approved.get("pk") != body.pk_relay: raise HTTPException(status_code=403, - detail="Relay not approved — ask hub admin to run POST /v1/relays/approve") + detail="Relay not approved — ask the hub admin to " + "run POST /v1/relays/approve") if body.timestamp is None or not body.signature: raise HTTPException( diff --git a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py index 1f1f5c5..f8cae8a 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py @@ -26,23 +26,21 @@ and close active connections for that user. """ import asyncio -import base64 import json import logging import time import uuid -from datetime import datetime, timezone -from typing import Any +from datetime import UTC, datetime +import jwt from fastapi import APIRouter, Depends, HTTPException, Request, WebSocket, WebSocketDisconnect +from meshbay_common.background import spawn from pydantic import BaseModel from sqlalchemy import select, update from sqlalchemy.ext.asyncio import AsyncSession -import jwt -from meshbay_common.background import spawn -from meshbay_hub.auth import hub_public_key_pem, decode_access_token from meshbay_hub.api.deps import get_current_user, require_admin +from meshbay_hub.auth import decode_access_token from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import Group, GroupMember, IPLog, Node, User @@ -143,7 +141,7 @@ async def _mark_hosted(group_ids: list[str]) -> None: await db.execute( update(Group) .where(Group.id.in_(group_ids), Group.hosted_at.is_(None)) - .values(hosted_at=datetime.now(timezone.utc))) + .values(hosted_at=datetime.now(UTC))) await db.commit() except Exception as e: # A group that stays unhosted in the table is visible to its owner and @@ -169,7 +167,7 @@ async def broadcast_revocation(token: str) -> int: def _sign_revocation(target: str, target_id: str, reason: str) -> str: """Issue a signed revocation token (JWT EdDSA).""" - from meshbay_hub.auth import _hub_sk_pem, _hub_id + from meshbay_hub.auth import _hub_id, _hub_sk_pem now = int(time.time()) payload = { "type": "revocation", @@ -208,9 +206,9 @@ async def _handle_chat_notify(group_id: str, sender_name: str, sender_user_id: s (node_id or "?")[:8]) return try: - from meshbay_hub.db.engine import get_session_factory - from meshbay_hub.db.models import GroupMember, Group from meshbay_hub.api.notifications import create_notification + from meshbay_hub.db.engine import get_session_factory + from meshbay_hub.db.models import Group, GroupMember async with get_session_factory()() as db: group = await db.get(Group, group_id) @@ -478,7 +476,7 @@ async def notify_incoming( try: await asyncio.wait_for(event.wait(), timeout=5.0) - except asyncio.TimeoutError: + except TimeoutError: raise HTTPException(status_code=504, detail="Node did not respond in time") finally: _punch_events.pop(node_id, None) diff --git a/packages/meshbay-hub/src/meshbay_hub/api/signaling.py b/packages/meshbay-hub/src/meshbay_hub/api/signaling.py index bc03b45..8a10822 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/signaling.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/signaling.py @@ -25,8 +25,8 @@ from sqlalchemy.ext.asyncio import AsyncSession from meshbay_hub import hub_settings from meshbay_hub.api.deps import get_current_user from meshbay_hub.api.middleware import limiter -from meshbay_hub.db.engine import get_db from meshbay_hub.api.netutil import client_ip +from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import Group, GroupMember, IPLog, User log = logging.getLogger(__name__) @@ -167,7 +167,7 @@ async def webrtc_offer( try: answer = await asyncio.wait_for(answer_future, timeout=15.0) - except asyncio.TimeoutError: + except TimeoutError: raise HTTPException( status_code=504, detail="Node did not respond with WebRTC answer") diff --git a/packages/meshbay-hub/src/meshbay_hub/api/users.py b/packages/meshbay-hub/src/meshbay_hub/api/users.py index 0394f53..2666e86 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/users.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/users.py @@ -6,7 +6,7 @@ import re import secrets import time import uuid -from datetime import datetime, timedelta, timezone +from datetime import UTC, datetime, timedelta from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey from fastapi import APIRouter, Depends, HTTPException, Request @@ -33,8 +33,17 @@ from meshbay_hub.auth import ( from meshbay_hub.config import HubConfig from meshbay_hub.db.engine import get_db from meshbay_hub.db.models import ( - EmailVerification, Group, GroupMember, IPLog, Node, Notification, - RefreshToken, SwarmSource, User, UserDevice, UserPreference, + EmailVerification, + Group, + GroupMember, + IPLog, + Node, + Notification, + RefreshToken, + SwarmSource, + User, + UserDevice, + UserPreference, ) log = logging.getLogger(__name__) @@ -61,7 +70,7 @@ async def _refresh_expiry(db: AsyncSession, family_id: str | None = None) -> dat renewals of a tab that is being used. """ limits = await hub_settings.session_limits(db) - now = datetime.now(timezone.utc) + now = datetime.now(UTC) idle = max(limits["refresh_idle_hours"] * 3600, _ttl() + 3600) started = now if family_id is not None: @@ -69,7 +78,7 @@ async def _refresh_expiry(db: AsyncSession, family_id: str | None = None) -> dat select(func.min(RefreshToken.created_at)) .where(RefreshToken.family_id == family_id)) if first is not None: - started = first if first.tzinfo else first.replace(tzinfo=timezone.utc) + started = first if first.tzinfo else first.replace(tzinfo=UTC) return min(now + timedelta(seconds=idle), started + timedelta(hours=limits["max_hours"])) @@ -193,7 +202,7 @@ async def register( EmailVerification.user_id == found.id, EmailVerification.purpose == "registration", EmailVerification.created_at - > datetime.now(timezone.utc) + > datetime.now(UTC) - timedelta(seconds=resend_cooldown), )) if not recent.first(): @@ -270,7 +279,7 @@ async def _create_and_send_verification( code=code, purpose="registration", user_id=user.id, - expires_at=datetime.now(timezone.utc) + timedelta(seconds=VERIFICATION_TTL), + expires_at=datetime.now(UTC) + timedelta(seconds=VERIFICATION_TTL), )) await db.flush() await mail.send_off_loop( @@ -292,7 +301,7 @@ async def verify_email( ): """Verify a registration email with the code received by mail.""" eh = hash_email_blind(body.email) - now = datetime.now(timezone.utc) + now = datetime.now(UTC) result = await db.execute( select(EmailVerification).where( @@ -306,7 +315,7 @@ async def verify_email( raise HTTPException(status_code=404, detail="No pending verification for this email") - if verif.expires_at.replace(tzinfo=timezone.utc) < now: + if verif.expires_at.replace(tzinfo=UTC) < now: raise HTTPException(status_code=410, detail="Verification code expired") if verif.attempts >= VERIFICATION_MAX_ATTEMPTS: @@ -603,7 +612,7 @@ async def device_auth( await db.commit() raise HTTPException(status_code=401, detail="Invalid signature") - matched.last_seen = datetime.now(timezone.utc) + matched.last_seen = datetime.now(UTC) memberships = await db.execute( select(GroupMember.group_id).where(GroupMember.user_id == user.id)) @@ -650,7 +659,7 @@ async def token_refresh( await db.commit() raise HTTPException(status_code=401, detail="Token reuse detected — family revoked") - if rt.expires_at.replace(tzinfo=timezone.utc) < datetime.now(timezone.utc): + if rt.expires_at.replace(tzinfo=UTC) < datetime.now(UTC): raise HTTPException(status_code=401, detail="Expired refresh token") user = await db.get(User, rt.user_id) @@ -659,7 +668,7 @@ async def token_refresh( # The family's first sign-in was longer ago than any session may last. expires_at = await _refresh_expiry(db, rt.family_id) - if expires_at <= datetime.now(timezone.utc): + if expires_at <= datetime.now(UTC): await db.execute( update(RefreshToken) .where(RefreshToken.family_id == rt.family_id) @@ -779,7 +788,7 @@ async def update_profile( cooldown = await hub_settings.get_int( db, "mail.email_change_cooldown", hub_settings.mail_default("email_change_cooldown")) - since = datetime.now(timezone.utc) - timedelta(seconds=cooldown) + since = datetime.now(UTC) - timedelta(seconds=cooldown) recent = await db.execute( select(IPLog).where( IPLog.user_id == current_user.id, @@ -820,7 +829,7 @@ async def update_profile( code=code, purpose="email_change", user_id=current_user.id, - expires_at=datetime.now(timezone.utc) + timedelta(seconds=VERIFICATION_TTL), + expires_at=datetime.now(UTC) + timedelta(seconds=VERIFICATION_TTL), )) db.add(IPLog(user_id=current_user.id, event="email_change_request", ip_address=client_ip(request))) @@ -860,7 +869,7 @@ async def verify_email_change( db: AsyncSession = Depends(get_db), ): """Confirm an email change with the code sent to the new address.""" - now = datetime.now(timezone.utc) + now = datetime.now(UTC) result = await db.execute( select(EmailVerification).where( @@ -874,7 +883,7 @@ async def verify_email_change( raise HTTPException(status_code=404, detail="No pending email change") - if verif.expires_at.replace(tzinfo=timezone.utc) < now: + if verif.expires_at.replace(tzinfo=UTC) < now: raise HTTPException(status_code=410, detail="Verification code expired") if verif.attempts >= VERIFICATION_MAX_ATTEMPTS: @@ -1090,7 +1099,7 @@ async def password_reset_request( EmailVerification.user_id == user.id, EmailVerification.purpose == "password_reset", EmailVerification.created_at - > datetime.now(timezone.utc) - timedelta(seconds=reset_cooldown), + > datetime.now(UTC) - timedelta(seconds=reset_cooldown), )) if recent.first(): return {"status": "sent_if_exists"} @@ -1110,7 +1119,7 @@ async def password_reset_request( code=code, purpose="password_reset", user_id=user.id, - expires_at=datetime.now(timezone.utc) + expires_at=datetime.now(UTC) + timedelta(seconds=PASSWORD_RESET_TTL), )) db.add(IPLog(user_id=user.id, event="password_reset_request", @@ -1141,7 +1150,7 @@ async def password_reset( request: Request, db: AsyncSession = Depends(get_db), ): - now = datetime.now(timezone.utc) + now = datetime.now(UTC) result = await db.execute(select(User).where(User.username == body.username)) user = result.scalar_one_or_none() if not user: @@ -1157,7 +1166,7 @@ async def password_reset( if not verif: raise HTTPException(status_code=404, detail="No pending reset for this account") - if verif.expires_at.replace(tzinfo=timezone.utc) < now: + if verif.expires_at.replace(tzinfo=UTC) < now: raise HTTPException(status_code=410, detail="Reset code expired") if verif.attempts >= VERIFICATION_MAX_ATTEMPTS: raise HTTPException(status_code=429, detail="Too many attempts") @@ -1303,7 +1312,9 @@ async def register_node_key( if len(raw) != 32: raise ValueError except Exception: - raise HTTPException(status_code=400, detail="Invalid Ed25519 public key (need 32 bytes base64)") + raise HTTPException( + status_code=400, + detail="Invalid Ed25519 public key (need 32 bytes base64)") current_user.pk_node_ed25519 = body.pk_node_ed25519 await db.commit() diff --git a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py index 3e23961..054d04a 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py @@ -168,7 +168,8 @@ _HTML = """\ though it had scrolled away. This asks for the keyboard to resize the layout viewport instead, so what is pinned stays where it is looked at. Ignored by browsers that do not know it. --> - <meta name="viewport" content="width=device-width, initial-scale=1, interactive-widget=resizes-content"> + <meta name="viewport" + content="width=device-width, initial-scale=1, interactive-widget=resizes-content"> <title>MeshBay</title> <link rel="stylesheet" href="/a/{v}/style.css"> </head> |