feat: add wildcard token support for allowed extensions and access token CLI commands

Introduce WILDCARD_TOKENS set in attachments.py to treat "*", ".*", "*.*" as wildcards that fall back to ALLOWED_UPLOAD_TYPES. Add cmd_token_issue and cmd_token_list CLI commands for issuing and listing DevPlace access tokens. Register access_tokens table in SOFT_DELETE_TABLES and initialize its columns and indexes in init_db. Replace Form() with Depends(json_or_form(...)) in admin backup, container, notification, settings, and user routers to support both JSON and form data.
This commit is contained in:
2026-06-17 17:10:52 +00:00
parent 217210e02f
commit 9598a1b867
45 changed files with 436 additions and 284 deletions
+20
View File
@@ -58,6 +58,26 @@ def resolve_user(params: dict) -> Optional[dict]:
return user
def resolve_user_by_key(key: str) -> Optional[dict]:
"""Resolve a user from a DevRant token key alone (40-char hex).
Used by the main DevPlace auth chain so that DevRant tokens work as
Bearer / X-API-KEY credentials on every DevPlace endpoint.
"""
if not key:
return None
token = get_table("devrant_tokens").find_one(key=key, deleted_at=None)
if not token:
return None
expire = as_int(token.get("expire_time"))
if expire and expire < now_unix():
return None
user = get_table("users").find_one(uid=token.get("user_uid"))
if not user or not user.get("is_active", True):
return None
return user
def revoke_all(user_uid: str) -> None:
tokens = get_table("devrant_tokens")
stamp = datetime.now(timezone.utc).isoformat()