9e8f1bbeed
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
39 lines
1.4 KiB
Python
39 lines
1.4 KiB
Python
"""API key authentication for ODS Dashboard API."""
|
|
|
|
import logging
|
|
import os
|
|
import secrets
|
|
from pathlib import Path
|
|
|
|
from fastapi import HTTPException, Security
|
|
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
DASHBOARD_API_KEY = os.environ.get("DASHBOARD_API_KEY")
|
|
if not DASHBOARD_API_KEY:
|
|
DASHBOARD_API_KEY = secrets.token_urlsafe(32)
|
|
key_file = Path("/data/dashboard-api-key.txt")
|
|
key_file.parent.mkdir(parents=True, exist_ok=True)
|
|
key_file.write_text(DASHBOARD_API_KEY)
|
|
key_file.chmod(0o600)
|
|
logger.warning(
|
|
"DASHBOARD_API_KEY not set. Generated temporary key and wrote to %s (mode 0600). "
|
|
"Set DASHBOARD_API_KEY in your .env file for production.", key_file
|
|
)
|
|
|
|
security_scheme = HTTPBearer(auto_error=False)
|
|
|
|
|
|
async def verify_api_key(credentials: HTTPAuthorizationCredentials = Security(security_scheme)):
|
|
"""Verify API key for protected endpoints."""
|
|
if not credentials:
|
|
raise HTTPException(
|
|
status_code=401,
|
|
detail="Authentication required. Provide Bearer token in Authorization header.",
|
|
headers={"WWW-Authenticate": "Bearer"}
|
|
)
|
|
if not secrets.compare_digest(credentials.credentials, DASHBOARD_API_KEY):
|
|
raise HTTPException(status_code=403, detail="Invalid API key.")
|
|
return credentials.credentials
|