Send admin token via X-Admin-Token header (not URL path)
This commit is contained in:
1 parent
6d3f6f7c86
commit
30ca7cbcf3
1 file changed
+4
-4
+4
-4
@@ -58,7 +58,7 @@ def is_admin(request: Request) -> bool:
|
|||||||
|
|
||||||
async def portal_get(path: str) -> dict:
|
async def portal_get(path: str) -> dict:
|
||||||
async with httpx.AsyncClient(timeout=20.0) as client:
|
async with httpx.AsyncClient(timeout=20.0) as client:
|
||||||
r = await client.get(f"{PORTAL_BASE}{path}")
|
r = await client.get(f"{PORTAL_BASE}{path}", headers={"X-Admin-Token": ADMIN_TOKEN})
|
||||||
if r.status_code != 200:
|
if r.status_code != 200:
|
||||||
raise HTTPException(502, f"Portal error {r.status_code}")
|
raise HTTPException(502, f"Portal error {r.status_code}")
|
||||||
return r.json()
|
return r.json()
|
||||||
@@ -66,7 +66,7 @@ async def portal_get(path: str) -> dict:
|
|||||||
|
|
||||||
async def portal_post(path: str, payload: dict) -> dict:
|
async def portal_post(path: str, payload: dict) -> dict:
|
||||||
async with httpx.AsyncClient(timeout=20.0) as client:
|
async with httpx.AsyncClient(timeout=20.0) as client:
|
||||||
r = await client.post(f"{PORTAL_BASE}{path}", json=payload)
|
r = await client.post(f"{PORTAL_BASE}{path}", json=payload, headers={"X-Admin-Token": ADMIN_TOKEN})
|
||||||
if r.status_code not in (200, 201):
|
if r.status_code not in (200, 201):
|
||||||
try:
|
try:
|
||||||
detail = r.json().get("detail", r.text)
|
detail = r.json().get("detail", r.text)
|
||||||
@@ -95,7 +95,7 @@ async def index(request: Request):
|
|||||||
async def api_overview(request: Request):
|
async def api_overview(request: Request):
|
||||||
if not is_admin(request):
|
if not is_admin(request):
|
||||||
return JSONResponse({"error": "forbidden"}, status_code=403)
|
return JSONResponse({"error": "forbidden"}, status_code=403)
|
||||||
return await portal_get(f"/admin/overview/{ADMIN_TOKEN}")
|
return await portal_get("/admin/overview")
|
||||||
|
|
||||||
|
|
||||||
@app.post("/api/set-balance")
|
@app.post("/api/set-balance")
|
||||||
@@ -114,7 +114,7 @@ async def api_set_balance(request: Request):
|
|||||||
else:
|
else:
|
||||||
return JSONResponse({"error": "Provide 'balance' or 'add'"}, status_code=400)
|
return JSONResponse({"error": "Provide 'balance' or 'add'"}, status_code=400)
|
||||||
try:
|
try:
|
||||||
return await portal_post(f"/admin/set-balance/{ADMIN_TOKEN}", payload)
|
return await portal_post("/admin/set-balance", payload)
|
||||||
except HTTPException as e:
|
except HTTPException as e:
|
||||||
return JSONResponse({"error": e.detail}, status_code=e.status_code)
|
return JSONResponse({"error": e.detail}, status_code=e.status_code)
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user