From 30ca7cbcf37f2448d87f4002ebfaed37d9ca6c4a Mon Sep 17 00:00:00 2001 From: inference-bot Date: Mon, 14 Sep 2026 18:06:02 -0600 Subject: [PATCH] Send admin token via X-Admin-Token header (not URL path) --- app/main.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/app/main.py b/app/main.py index 93adf82..ec5004f 100644 --- a/app/main.py +++ b/app/main.py @@ -58,7 +58,7 @@ def is_admin(request: Request) -> bool: async def portal_get(path: str) -> dict: async with httpx.AsyncClient(timeout=20.0) as client: - r = await client.get(f"{PORTAL_BASE}{path}") + r = await client.get(f"{PORTAL_BASE}{path}", headers={"X-Admin-Token": ADMIN_TOKEN}) if r.status_code != 200: raise HTTPException(502, f"Portal error {r.status_code}") return r.json() @@ -66,7 +66,7 @@ async def portal_get(path: str) -> dict: async def portal_post(path: str, payload: dict) -> dict: async with httpx.AsyncClient(timeout=20.0) as client: - r = await client.post(f"{PORTAL_BASE}{path}", json=payload) + r = await client.post(f"{PORTAL_BASE}{path}", json=payload, headers={"X-Admin-Token": ADMIN_TOKEN}) if r.status_code not in (200, 201): try: detail = r.json().get("detail", r.text) @@ -95,7 +95,7 @@ async def index(request: Request): async def api_overview(request: Request): if not is_admin(request): return JSONResponse({"error": "forbidden"}, status_code=403) - return await portal_get(f"/admin/overview/{ADMIN_TOKEN}") + return await portal_get("/admin/overview") @app.post("/api/set-balance") @@ -114,7 +114,7 @@ async def api_set_balance(request: Request): else: return JSONResponse({"error": "Provide 'balance' or 'add'"}, status_code=400) try: - return await portal_post(f"/admin/set-balance/{ADMIN_TOKEN}", payload) + return await portal_post("/admin/set-balance", payload) except HTTPException as e: return JSONResponse({"error": e.detail}, status_code=e.status_code)