M0: backend skeleton — Quart factory, async DB, auth, ACL spine, migrations
Foundation & Identity backend for ThoughtSync: - Quart app factory (create_app) with /api/health + SPA history-fallback - async SQLAlchemy 2.0 + asyncpg engine/session (lazy; boots without a DB) - native email+password auth via signed-cookie session (register/login/logout/me + login_required guard); bcrypt password hashing (72-byte safe) - multi-user sharing-ACL spine (rule 47): users, groups, group_members, and a polymorphic shares table + visible_to_user() SQL predicate (owner OR direct share OR group share) that M1's notes will scope through - Alembic async env (adapted from family pattern) + 0001 foundation migration - DB-free unit tests (app/health/auth-guard, password roundtrip, ACL compile) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
|
||||
from quart import Quart, jsonify, send_from_directory
|
||||
|
||||
from . import __version__
|
||||
from .auth import bp as auth_bp
|
||||
from .config import Config
|
||||
|
||||
STATIC_DIR = os.path.join(os.path.dirname(__file__), "static")
|
||||
|
||||
|
||||
def create_app() -> Quart:
|
||||
# static_folder=None: the SPA catch-all below owns static serving instead of
|
||||
# Quart's default /static handler.
|
||||
app = Quart(__name__, static_folder=None)
|
||||
app.secret_key = Config.secret_key()
|
||||
app.config["APP_VERSION"] = os.environ.get("APP_VERSION", __version__)
|
||||
|
||||
app.register_blueprint(auth_bp)
|
||||
|
||||
@app.get("/api/health")
|
||||
async def health():
|
||||
return jsonify({"status": "ok", "version": app.config["APP_VERSION"]})
|
||||
|
||||
# Serve the built Vue SPA (baked into static/ by the Docker build) with a
|
||||
# history-fallback to index.html. In dev the Vite server proxies /api here, so
|
||||
# a missing static/ dir is expected and simply 404s the frontend.
|
||||
@app.get("/", defaults={"path": ""})
|
||||
@app.get("/<path:path>")
|
||||
async def spa(path: str):
|
||||
if path.startswith("api/"):
|
||||
return jsonify({"error": "not found"}), 404
|
||||
candidate = os.path.join(STATIC_DIR, path)
|
||||
if path and os.path.isfile(candidate):
|
||||
return await send_from_directory(STATIC_DIR, path)
|
||||
index = os.path.join(STATIC_DIR, "index.html")
|
||||
if os.path.isfile(index):
|
||||
return await send_from_directory(STATIC_DIR, "index.html")
|
||||
return jsonify({"error": "frontend not built"}), 404
|
||||
|
||||
return app
|
||||
Reference in New Issue
Block a user