Phase 1 (Foundation): - Project restructure (presenton-main → backend/ + frontend/) - Database schema (8 new models, Alembic config, seed script) - Auth (Azure AD SSO + dev bypass, JWT sessions, AuthMiddleware) - RBAC (access_service, rbac_middleware, admin routers) - Audit logging (fire-and-forget, AuditMiddleware, admin router) - i18n (react-i18next with 5 namespace files) Phase 2 (Admin Panel & Client Management): - Admin panel shell (sidebar layout, role guard, 12 pages) - Redux admin slice with 18 async thunks - User management (role changes, deactivation) - Client management (CRUD, brand config, team management) - Brand config editor (colors, fonts, logos, voice rules) - Master deck upload & parser (PPTX → HTML → React pipeline) - Audit log viewer with filters and CSV/JSON export Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
36 lines
1.3 KiB
Python
36 lines
1.3 KiB
Python
from fastapi import Request, HTTPException, Depends
|
|
from models.sql.user import UserModel
|
|
|
|
|
|
def get_current_user(request: Request) -> UserModel:
|
|
"""FastAPI dependency: extract authenticated user from request state."""
|
|
user = getattr(request.state, "user", None)
|
|
if not user:
|
|
raise HTTPException(status_code=401, detail="Not authenticated")
|
|
return user
|
|
|
|
|
|
def require_role(*roles: str):
|
|
"""FastAPI dependency factory: require user has one of the specified roles."""
|
|
def dependency(request: Request) -> UserModel:
|
|
user = get_current_user(request)
|
|
if user.role not in roles:
|
|
raise HTTPException(status_code=403, detail="Insufficient permissions")
|
|
return user
|
|
return Depends(dependency)
|
|
|
|
|
|
def require_super_admin(request: Request) -> UserModel:
|
|
"""FastAPI dependency: require super_admin role."""
|
|
user = get_current_user(request)
|
|
if user.role != "super_admin":
|
|
raise HTTPException(status_code=403, detail="Super admin access required")
|
|
return user
|
|
|
|
|
|
def require_client_admin(request: Request) -> UserModel:
|
|
"""FastAPI dependency: require client_admin or super_admin role."""
|
|
user = get_current_user(request)
|
|
if user.role not in ("super_admin", "client_admin"):
|
|
raise HTTPException(status_code=403, detail="Admin access required")
|
|
return user
|