M1.5 backend: admin role + DB-backed settings, DB-URL-only install
- users.is_admin; first registered user becomes admin; registration gated by the allow_registration setting (first account always allowed). is_admin in /api/auth/* responses; require_admin guard (live DB check). - settings table + code registry (site_name, allow_registration, session_ttl_days) with typed defaults — empty table = all defaults (rule 26). get/set/validate service; GET /api/config (public) + GET/PATCH /api/settings (admin), live session-TTL apply with no restart (rule 25). - Cookie-signing secret now persisted in the DB (before_serving load-or-create), so sessions survive restarts with no volume. Config: DATABASE_URL is the only required env; SECRET_KEY + DATA_DIR are optional break-glass items. - Migration 0003; DB-free tests for settings validation + admin guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
@@ -0,0 +1,44 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from datetime import timedelta
|
||||
|
||||
from quart import Blueprint, current_app, jsonify, request
|
||||
|
||||
from .auth import require_admin
|
||||
from .db import session_scope
|
||||
from .settings import get_admin_settings, set_settings, validate_updates
|
||||
|
||||
bp = Blueprint("settings", __name__, url_prefix="/api/settings")
|
||||
|
||||
|
||||
@bp.get("")
|
||||
@require_admin
|
||||
async def list_settings():
|
||||
async with session_scope() as db:
|
||||
return jsonify({"settings": await get_admin_settings(db)})
|
||||
|
||||
|
||||
@bp.patch("")
|
||||
@require_admin
|
||||
async def update_settings():
|
||||
raw = await request.get_json(silent=True)
|
||||
data = raw if isinstance(raw, dict) else {}
|
||||
# Accept either {settings: {...}} or a bare {key: value} object.
|
||||
updates = data.get("settings") if isinstance(data.get("settings"), dict) else data
|
||||
if not isinstance(updates, dict):
|
||||
return jsonify({"error": "expected an object of settings"}), 400
|
||||
|
||||
clean, error = validate_updates(updates)
|
||||
if error is not None:
|
||||
return jsonify({"error": error}), 400
|
||||
|
||||
async with session_scope() as db:
|
||||
await set_settings(db, clean)
|
||||
await db.commit()
|
||||
result = await get_admin_settings(db)
|
||||
|
||||
# Apply the live-tunable knob without a restart (rule 25).
|
||||
if "session_ttl_days" in clean:
|
||||
current_app.config["PERMANENT_SESSION_LIFETIME"] = timedelta(days=int(clean["session_ttl_days"]))
|
||||
|
||||
return jsonify({"settings": result})
|
||||
Reference in New Issue
Block a user