Files
url_shortening_service/site/links/auth.py
T
westfarn 433308d615
Deploy Beta / unit-tests (push) Successful in 4s
Deploy Beta / docker (push) Successful in 10s
Deploy Beta / deploy-beta (push) Successful in 1m3s
Serve /api/ on piha.lc / beta.piha.li (#8)
## Summary
- Serve `/api/` on `piha.lc` / `beta.piha.li` (Bearer still required).
- Drop `shortener.aimloperations.com` / `shortener-beta.aimloperations.com` from env examples and caller docs.
- `/admin/` stays 404 on the public host.

Closes #7.

## Test plan
- [ ] `POST https://beta.piha.li/api/links/` with valid Bearer → 201
- [ ] Same without Bearer → 401
- [ ] `GET https://beta.piha.li/<code>` still 302
- [ ] `/admin/` on beta.piha.li → 404
- [ ] Unit tests: `cd site && uv run python manage.py test`

Reviewed-on: #8
2026-08-30 17:27:40 -07:00

65 lines
2.1 KiB
Python

"""Bearer token auth for /api/. The lock that keeps minting closed on the public host."""
from __future__ import annotations
import hmac
from collections.abc import Callable
from functools import wraps
from django.conf import settings
from django.http import HttpRequest, JsonResponse
from django.views.decorators.csrf import csrf_exempt
def parse_bearer(request: HttpRequest) -> str | None:
header = request.META.get("HTTP_AUTHORIZATION") or ""
if not header.startswith("Bearer "):
return None
token = header[7:].strip()
return token or None
def authenticate_token(raw_token: str | None) -> str | None:
"""Return the configured token name, or None if no match.
Accepts either ``name:secret`` (as callers send) or the bare secret.
Always compares against every configured token (constant-time).
"""
configured = list(getattr(settings, "SHORTENER_API_TOKENS", []) or [])
if not configured or not raw_token:
return None
matched_name: str | None = None
for name, secret in configured:
full = f"{name}:{secret}"
if hmac.compare_digest(raw_token, full) or hmac.compare_digest(raw_token, secret):
matched_name = name
# Keep looping so compare_digest runs for every token.
return matched_name
def token_name_for_request(request: HttpRequest) -> str | None:
return authenticate_token(parse_bearer(request))
def require_bearer(view: Callable) -> Callable:
"""Decorator: 503 if no tokens configured, 401 if missing/wrong Bearer."""
@csrf_exempt
@wraps(view)
def wrapper(request, *args, **kwargs):
configured = list(getattr(settings, "SHORTENER_API_TOKENS", []) or [])
if not configured:
return JsonResponse({"detail": "Service unavailable"}, status=503)
name = token_name_for_request(request)
if not name:
response = JsonResponse({"detail": "Unauthorized"}, status=401)
response["WWW-Authenticate"] = "Bearer"
return response
request.token_name = name
return view(request, *args, **kwargs)
return wrapper