feat(backend): Update models and endpoints configuration
- Enhanced ticket and comment models with proper relationships - Updated client_profile model for better data handling - Improved auth endpoint with better error handling - Updated main app configuration and imports - Added new dependencies to requirements.txt - Enhanced tickets endpoint with attachment support
This commit is contained in:
@@ -8,6 +8,7 @@ from fastapi import APIRouter, HTTPException, status, Depends
|
||||
from fastapi.security import OAuth2PasswordBearer, OAuth2PasswordRequestForm
|
||||
from sqlalchemy.ext.asyncio import AsyncSession
|
||||
from sqlalchemy import select
|
||||
from sqlalchemy.orm import selectinload
|
||||
from pydantic import BaseModel, EmailStr
|
||||
from typing import Optional
|
||||
import structlog
|
||||
@@ -257,41 +258,49 @@ async def get_current_user(
|
||||
detail="Invalid token"
|
||||
)
|
||||
|
||||
# TODO: Fetch actual user from database
|
||||
user_id = payload.get("sub")
|
||||
if not user_id:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid token payload"
|
||||
)
|
||||
|
||||
# Fetch actual user from database
|
||||
query = select(User).where(User.id == user_id).options(
|
||||
selectinload(User.tenant)
|
||||
)
|
||||
result = await db.execute(query)
|
||||
user = result.scalar_one_or_none()
|
||||
|
||||
if not user:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_404_NOT_FOUND,
|
||||
detail="User not found"
|
||||
)
|
||||
|
||||
if not user.is_active:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="User account is disabled"
|
||||
)
|
||||
|
||||
return {
|
||||
"id": payload["sub"],
|
||||
"email": payload["email"],
|
||||
"role": payload["role"],
|
||||
"tenant_id": payload["tenant_id"]
|
||||
"id": str(user.id),
|
||||
"email": user.email,
|
||||
"first_name": user.first_name,
|
||||
"last_name": user.last_name,
|
||||
"role": user.role.value if hasattr(user.role, 'value') else user.role,
|
||||
"tenant_id": str(user.tenant_id),
|
||||
"tenant_name": user.tenant.name if user.tenant else None,
|
||||
"is_active": user.is_active,
|
||||
"is_two_factor_enabled": user.totp_secret is not None,
|
||||
"last_login": user.last_login.isoformat() if user.last_login else None,
|
||||
"created_at": user.created_at.isoformat()
|
||||
}
|
||||
|
||||
|
||||
# ===================================
|
||||
# DEPENDENCIES
|
||||
# ===================================
|
||||
|
||||
async def get_current_active_user(token: str = Depends(oauth2_scheme)):
|
||||
"""
|
||||
Dependency to get current active user from token.
|
||||
|
||||
Args:
|
||||
token: Access token
|
||||
|
||||
Returns:
|
||||
Current user data
|
||||
|
||||
Raises:
|
||||
HTTPException: If token is invalid or user is inactive
|
||||
"""
|
||||
payload = security.verify_token(token)
|
||||
if not payload:
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid token",
|
||||
headers={"WWW-Authenticate": "Bearer"},
|
||||
)
|
||||
|
||||
# TODO: Verify user exists and is active
|
||||
|
||||
return payload
|
||||
# Dependencies are imported from app.api.deps to avoid duplication
|
||||
# Use get_current_user and get_current_active_superuser from deps.py
|
||||
Reference in New Issue
Block a user