Files
DocsGPT/docsgpt/auth.py
T
Alex 574f96341e refactor: rename the application package to docsgpt
The backend import package is now docsgpt, the name it will carry on PyPI;
application was far too generic to install into anyone's site-packages.
git mv plus a mechanical rewrite of every import, dotted string and path
reference: 734 Python files, the compose files, Dockerfile, workflows, docs,
setup scripts, devcontainer, k8s manifests, vscode config, pytest and coverage
config, .gitignore. Behaviour is unchanged.

Kept for one release:
- A top-level application package whose meta-path finder resolves
  application.x.y to the already-imported docsgpt.x.y object, so old imports
  and entry points (celery -A application.app.celery,
  uvicorn application.asgi:asgi_app) keep working with a FutureWarning.
- Celery registers every application.* task name as an alias of its
  docsgpt.* task on start-up, so messages queued by the previous release still
  run. The redbeat key prefix moves to redbeat:docsgpt:v2: so schedule entries
  the previous release wrote are left unread instead of firing twice.

The backend image builds from the repository root (docker build -f
docsgpt/Dockerfile .) so it can ship the alias package; a root .dockerignore
allow-lists docsgpt/ and application/ and keeps caches, local data, .env
files, the sample index files and the Dockerfile out. Compose and the image
workflows point at the new context.
2026-09-07 10:20:43 +01:00

42 lines
1.5 KiB
Python

from jose import jwt
from jose.exceptions import ExpiredSignatureError
from docsgpt.core.settings import settings
def handle_auth(request, data={}):
if settings.AUTH_TYPE in ["simple_jwt", "session_jwt", "oidc"]:
jwt_token = request.headers.get("Authorization")
if not jwt_token:
return None
jwt_token = jwt_token.replace("Bearer ", "")
is_oidc = settings.AUTH_TYPE == "oidc"
try:
decoded_token = jwt.decode(
jwt_token,
settings.JWT_SECRET_KEY,
algorithms=["HS256"],
# oidc sessions are minted with an exp at the login callback and
# must carry one: require_exp rejects any exp-less HS256 token
# signed with JWT_SECRET_KEY (e.g. a legacy simple_jwt/session_jwt
# token), which would otherwise authenticate forever and be
# unrevocable. simple_jwt/session_jwt never carried an exp, so the
# requirement is scoped to oidc.
options={"verify_exp": is_oidc, "require_exp": is_oidc},
)
return decoded_token
except ExpiredSignatureError:
return {
"message": "Authentication error: token expired",
"error": "token_expired",
}
except Exception:
return {
"message": "Authentication error: invalid token",
"error": "invalid_token",
}
else:
return {"sub": "local"}