mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 18:46:54 +00:00
The backend import package is now docsgpt, the name it will carry on PyPI; application was far too generic to install into anyone's site-packages. git mv plus a mechanical rewrite of every import, dotted string and path reference: 734 Python files, the compose files, Dockerfile, workflows, docs, setup scripts, devcontainer, k8s manifests, vscode config, pytest and coverage config, .gitignore. Behaviour is unchanged. Kept for one release: - A top-level application package whose meta-path finder resolves application.x.y to the already-imported docsgpt.x.y object, so old imports and entry points (celery -A application.app.celery, uvicorn application.asgi:asgi_app) keep working with a FutureWarning. - Celery registers every application.* task name as an alias of its docsgpt.* task on start-up, so messages queued by the previous release still run. The redbeat key prefix moves to redbeat:docsgpt:v2: so schedule entries the previous release wrote are left unread instead of firing twice. The backend image builds from the repository root (docker build -f docsgpt/Dockerfile .) so it can ship the alias package; a root .dockerignore allow-lists docsgpt/ and application/ and keeps caches, local data, .env files, the sample index files and the Dockerfile out. Compose and the image workflows point at the new context.
42 lines
1.5 KiB
Python
42 lines
1.5 KiB
Python
from jose import jwt
|
|
from jose.exceptions import ExpiredSignatureError
|
|
|
|
from docsgpt.core.settings import settings
|
|
|
|
|
|
def handle_auth(request, data={}):
|
|
if settings.AUTH_TYPE in ["simple_jwt", "session_jwt", "oidc"]:
|
|
jwt_token = request.headers.get("Authorization")
|
|
if not jwt_token:
|
|
return None
|
|
|
|
jwt_token = jwt_token.replace("Bearer ", "")
|
|
|
|
is_oidc = settings.AUTH_TYPE == "oidc"
|
|
try:
|
|
decoded_token = jwt.decode(
|
|
jwt_token,
|
|
settings.JWT_SECRET_KEY,
|
|
algorithms=["HS256"],
|
|
# oidc sessions are minted with an exp at the login callback and
|
|
# must carry one: require_exp rejects any exp-less HS256 token
|
|
# signed with JWT_SECRET_KEY (e.g. a legacy simple_jwt/session_jwt
|
|
# token), which would otherwise authenticate forever and be
|
|
# unrevocable. simple_jwt/session_jwt never carried an exp, so the
|
|
# requirement is scoped to oidc.
|
|
options={"verify_exp": is_oidc, "require_exp": is_oidc},
|
|
)
|
|
return decoded_token
|
|
except ExpiredSignatureError:
|
|
return {
|
|
"message": "Authentication error: token expired",
|
|
"error": "token_expired",
|
|
}
|
|
except Exception:
|
|
return {
|
|
"message": "Authentication error: invalid token",
|
|
"error": "invalid_token",
|
|
}
|
|
else:
|
|
return {"sub": "local"}
|