Files
light-heart-labs--dreamserver/ods/extensions/services/dashboard-api/security.py
T
wehub-resource-sync 9e8f1bbeed
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:31:33 +08:00

39 lines
1.4 KiB
Python

"""API key authentication for ODS Dashboard API."""
import logging
import os
import secrets
from pathlib import Path
from fastapi import HTTPException, Security
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials
logger = logging.getLogger(__name__)
DASHBOARD_API_KEY = os.environ.get("DASHBOARD_API_KEY")
if not DASHBOARD_API_KEY:
DASHBOARD_API_KEY = secrets.token_urlsafe(32)
key_file = Path("/data/dashboard-api-key.txt")
key_file.parent.mkdir(parents=True, exist_ok=True)
key_file.write_text(DASHBOARD_API_KEY)
key_file.chmod(0o600)
logger.warning(
"DASHBOARD_API_KEY not set. Generated temporary key and wrote to %s (mode 0600). "
"Set DASHBOARD_API_KEY in your .env file for production.", key_file
)
security_scheme = HTTPBearer(auto_error=False)
async def verify_api_key(credentials: HTTPAuthorizationCredentials = Security(security_scheme)):
"""Verify API key for protected endpoints."""
if not credentials:
raise HTTPException(
status_code=401,
detail="Authentication required. Provide Bearer token in Authorization header.",
headers={"WWW-Authenticate": "Bearer"}
)
if not secrets.compare_digest(credentials.credentials, DASHBOARD_API_KEY):
raise HTTPException(status_code=403, detail="Invalid API key.")
return credentials.credentials