Send admin token via X-Admin-Token header (not URL path)
This commit is contained in:
1 parent
6d3f6f7c86
commit
30ca7cbcf3
1 file changed
+4
-4
+4
-4
@@ -58,7 +58,7 @@ def is_admin(request: Request) -> bool:
|
||||
|
||||
async def portal_get(path: str) -> dict:
|
||||
async with httpx.AsyncClient(timeout=20.0) as client:
|
||||
r = await client.get(f"{PORTAL_BASE}{path}")
|
||||
r = await client.get(f"{PORTAL_BASE}{path}", headers={"X-Admin-Token": ADMIN_TOKEN})
|
||||
if r.status_code != 200:
|
||||
raise HTTPException(502, f"Portal error {r.status_code}")
|
||||
return r.json()
|
||||
@@ -66,7 +66,7 @@ async def portal_get(path: str) -> dict:
|
||||
|
||||
async def portal_post(path: str, payload: dict) -> dict:
|
||||
async with httpx.AsyncClient(timeout=20.0) as client:
|
||||
r = await client.post(f"{PORTAL_BASE}{path}", json=payload)
|
||||
r = await client.post(f"{PORTAL_BASE}{path}", json=payload, headers={"X-Admin-Token": ADMIN_TOKEN})
|
||||
if r.status_code not in (200, 201):
|
||||
try:
|
||||
detail = r.json().get("detail", r.text)
|
||||
@@ -95,7 +95,7 @@ async def index(request: Request):
|
||||
async def api_overview(request: Request):
|
||||
if not is_admin(request):
|
||||
return JSONResponse({"error": "forbidden"}, status_code=403)
|
||||
return await portal_get(f"/admin/overview/{ADMIN_TOKEN}")
|
||||
return await portal_get("/admin/overview")
|
||||
|
||||
|
||||
@app.post("/api/set-balance")
|
||||
@@ -114,7 +114,7 @@ async def api_set_balance(request: Request):
|
||||
else:
|
||||
return JSONResponse({"error": "Provide 'balance' or 'add'"}, status_code=400)
|
||||
try:
|
||||
return await portal_post(f"/admin/set-balance/{ADMIN_TOKEN}", payload)
|
||||
return await portal_post("/admin/set-balance", payload)
|
||||
except HTTPException as e:
|
||||
return JSONResponse({"error": e.detail}, status_code=e.status_code)
|
||||
|
||||
|
||||
Reference in new issue
Block a user