cleanup in _common

This commit is contained in:
Jörn-Michael Miehe 2022-03-29 00:13:38 +00:00
parent d3ed11fce4
commit 8a0058f7f0
3 changed files with 11 additions and 14 deletions

View file

@ -85,19 +85,16 @@ async def get_current_user_if_exists(
return current_user return current_user
async def get_current_user_if_admin( async def current_user_is_admin(
current_user: User = Depends(get_current_user_if_exists), current_user: User = Depends(get_current_user_if_exists),
) -> User: ) -> User:
""" """
Get the currently logged-in user if it is an admin. Fail if the currently logged-in user is not an admin.
""" """
# fail if not requested by an admin
if not current_user.can(UserCapabilityType.admin): if not current_user.can(UserCapabilityType.admin):
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN) raise HTTPException(status_code=status.HTTP_403_FORBIDDEN)
return current_user
async def get_user_by_name( async def get_user_by_name(
user_name: str, user_name: str,

View file

@ -8,7 +8,7 @@ from sqlmodel import select
from ..config import Config from ..config import Config
from ..db import Connection, User, UserCapabilityType, UserCreate from ..db import Connection, User, UserCapabilityType, UserCreate
from ._common import Responses, get_current_user_if_admin from ._common import Responses, current_user_is_admin
router = APIRouter(prefix="/admin", tags=["admin"]) router = APIRouter(prefix="/admin", tags=["admin"])
@ -79,7 +79,7 @@ async def create_initial_admin(
) )
async def set_config( async def set_config(
config: Config, config: Config,
_: User = Depends(get_current_user_if_admin), _: User = Depends(current_user_is_admin),
): ):
""" """
PUT ./config: Edit `kiwi-vpn` main config. PUT ./config: Edit `kiwi-vpn` main config.

View file

@ -8,8 +8,8 @@ from pydantic import BaseModel
from ..config import Config from ..config import Config
from ..db import User, UserCapabilityType, UserCreate, UserRead from ..db import User, UserCapabilityType, UserCreate, UserRead
from ._common import (Responses, get_current_user, get_current_user_if_admin, from ._common import (Responses, current_user_is_admin,
get_user_by_name) get_current_user_if_exists, get_user_by_name)
router = APIRouter(prefix="/user", tags=["user"]) router = APIRouter(prefix="/user", tags=["user"])
@ -59,7 +59,7 @@ async def login(
@router.get("/current", response_model=UserRead) @router.get("/current", response_model=UserRead)
async def get_current_user( async def get_current_user(
current_user: User | None = Depends(get_current_user), current_user: User = Depends(get_current_user_if_exists),
): ):
""" """
GET ./current: Respond with the currently logged-in user. GET ./current: Respond with the currently logged-in user.
@ -81,7 +81,7 @@ async def get_current_user(
) )
async def add_user( async def add_user(
user: UserCreate, user: UserCreate,
_: User = Depends(get_current_user_if_admin), _: User = Depends(current_user_is_admin),
) -> User: ) -> User:
""" """
POST ./: Create a new user in the database. POST ./: Create a new user in the database.
@ -113,7 +113,7 @@ async def add_user(
response_model=User, response_model=User,
) )
async def remove_user( async def remove_user(
_: User = Depends(get_current_user_if_admin), _: User = Depends(current_user_is_admin),
user: User = Depends(get_user_by_name), user: User = Depends(get_user_by_name),
): ):
""" """
@ -135,7 +135,7 @@ async def remove_user(
) )
async def extend_capabilities( async def extend_capabilities(
capabilities: list[UserCapabilityType], capabilities: list[UserCapabilityType],
_: User = Depends(get_current_user_if_admin), _: User = Depends(current_user_is_admin),
user: User = Depends(get_user_by_name), user: User = Depends(get_user_by_name),
): ):
""" """
@ -158,7 +158,7 @@ async def extend_capabilities(
) )
async def remove_capabilities( async def remove_capabilities(
capabilities: list[UserCapabilityType], capabilities: list[UserCapabilityType],
_: User = Depends(get_current_user_if_admin), _: User = Depends(current_user_is_admin),
user: User = Depends(get_user_by_name), user: User = Depends(get_user_by_name),
): ):
""" """