P1 auth, CORS, and SQL filtering
This commit is contained in:
+19
-2
@@ -1,19 +1,35 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
|
||||
from fastapi import FastAPI
|
||||
from fastapi.middleware.cors import CORSMiddleware
|
||||
|
||||
from backend.database import init_db
|
||||
from backend.routers.admin import router as admin_router
|
||||
from backend.routers.analyze import router as analyze_router
|
||||
from backend.routers.auth import router as auth_router
|
||||
from backend.routers.cases import router as cases_router
|
||||
from backend.routers.health import router as health_router
|
||||
from backend.routers.stats import router as stats_router
|
||||
|
||||
|
||||
def _parse_origins(value: str) -> list[str]:
|
||||
origins = [origin.strip() for origin in value.split(',') if origin.strip()]
|
||||
return origins or ['http://localhost:3000', 'http://127.0.0.1:3000']
|
||||
|
||||
|
||||
cors_origins = _parse_origins(os.getenv('CORS_ORIGINS', 'http://localhost:3000,http://127.0.0.1:3000'))
|
||||
allow_credentials = os.getenv('CORS_ALLOW_CREDENTIALS', 'true').strip().lower() in {'1', 'true', 'yes', 'on'}
|
||||
if '*' in cors_origins:
|
||||
allow_credentials = False
|
||||
|
||||
app = FastAPI(title='Vector API', version='0.1.0')
|
||||
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=['*'],
|
||||
allow_credentials=True,
|
||||
allow_origins=cors_origins,
|
||||
allow_credentials=allow_credentials,
|
||||
allow_methods=['*'],
|
||||
allow_headers=['*'],
|
||||
)
|
||||
@@ -25,6 +41,7 @@ def startup() -> None:
|
||||
|
||||
|
||||
app.include_router(health_router)
|
||||
app.include_router(auth_router)
|
||||
app.include_router(analyze_router)
|
||||
app.include_router(cases_router)
|
||||
app.include_router(stats_router)
|
||||
|
||||
Reference in New Issue
Block a user