forked from retoor/devplacepy
feat: add wildcard token support for allowed extensions and access token CLI commands
Introduce WILDCARD_TOKENS set in attachments.py to treat "*", ".*", "*.*" as wildcards that fall back to ALLOWED_UPLOAD_TYPES. Add cmd_token_issue and cmd_token_list CLI commands for issuing and listing DevPlace access tokens. Register access_tokens table in SOFT_DELETE_TABLES and initialize its columns and indexes in init_db. Replace Form() with Depends(json_or_form(...)) in admin backup, container, notification, settings, and user routers to support both JSON and form data.
This commit is contained in:
@@ -58,6 +58,26 @@ def resolve_user(params: dict) -> Optional[dict]:
|
||||
return user
|
||||
|
||||
|
||||
def resolve_user_by_key(key: str) -> Optional[dict]:
|
||||
"""Resolve a user from a DevRant token key alone (40-char hex).
|
||||
|
||||
Used by the main DevPlace auth chain so that DevRant tokens work as
|
||||
Bearer / X-API-KEY credentials on every DevPlace endpoint.
|
||||
"""
|
||||
if not key:
|
||||
return None
|
||||
token = get_table("devrant_tokens").find_one(key=key, deleted_at=None)
|
||||
if not token:
|
||||
return None
|
||||
expire = as_int(token.get("expire_time"))
|
||||
if expire and expire < now_unix():
|
||||
return None
|
||||
user = get_table("users").find_one(uid=token.get("user_uid"))
|
||||
if not user or not user.get("is_active", True):
|
||||
return None
|
||||
return user
|
||||
|
||||
|
||||
def revoke_all(user_uid: str) -> None:
|
||||
tokens = get_table("devrant_tokens")
|
||||
stamp = datetime.now(timezone.utc).isoformat()
|
||||
|
||||
Reference in New Issue
Block a user