feat: harden data access and simplify user management

This commit is contained in:
xuelong committed 2026-08-25 21:02:30 -07:00
1 parent 3dd5731751
commit adb780bc82
51 files changed
+3239 -2121

No files matched your search

+11 -11
View File
@@ -5,7 +5,7 @@ from typing import Any
from fastapi import APIRouter, File, HTTPException, Query, Request, Response, UploadFile
from app.auth import AdminUser, CurrentUser, DataOperatorUser
from app.auth import AdminUser, CurrentUser, DataViewerUser
from app.data_platform.mysql_service import (
IDENTIFIER_PATTERN,
MAX_CSV_BYTES,
@@ -37,7 +37,7 @@ router = APIRouter(prefix="/data-platform")
@router.get("/databases")
async def databases(_user: DataOperatorUser):
async def databases(_user: DataViewerUser):
return await list_databases()
@@ -93,7 +93,7 @@ async def remove_database(project_id: str, body: dict[str, Any], user: CurrentUs
@router.get("/databases/{project_id}/tables")
async def tables(project_id: str, _user: DataOperatorUser):
async def tables(project_id: str, _user: DataViewerUser):
return await list_tables(project_id)
@@ -126,7 +126,7 @@ async def security_audit_logs(
@router.get("/databases/{project_id}/tables/{table_code}/inspection")
async def table_inspection(project_id: str, table_code: str, _user: DataOperatorUser):
async def table_inspection(project_id: str, table_code: str, _user: DataViewerUser):
return await inspect_table(project_id, table_code)
@@ -259,7 +259,7 @@ async def remove_table(
async def records(
project_id: str,
table_code: str,
_user: DataOperatorUser,
_user: DataViewerUser,
page: int = Query(default=1, ge=1),
page_size: int = Query(default=50, ge=1, le=5000),
search: str | None = None,
@@ -293,7 +293,7 @@ async def _read_csv_upload(file: UploadFile) -> tuple[bytes, str]:
async def preview_records_import(
project_id: str,
table_code: str,
user: DataOperatorUser,
user: AdminUser,
file: UploadFile = File(...),
):
content, file_name = await _read_csv_upload(file)
@@ -304,7 +304,7 @@ async def preview_records_import(
async def import_records(
project_id: str,
table_code: str,
user: DataOperatorUser,
user: AdminUser,
file: UploadFile = File(...),
):
content, file_name = await _read_csv_upload(file)
@@ -321,7 +321,7 @@ async def import_records(
async def export_records(
project_id: str,
table_code: str,
_user: DataOperatorUser,
_user: DataViewerUser,
search: str | None = None,
):
content, filename, total = await export_csv_records(
@@ -344,7 +344,7 @@ async def add_record(
project_id: str,
table_code: str,
body: dict[str, Any],
user: DataOperatorUser,
user: AdminUser,
):
return await create_record(project_id, table_code, body, user["username"])
@@ -355,7 +355,7 @@ async def edit_record(
table_code: str,
record_id: str,
body: dict[str, Any],
user: DataOperatorUser,
user: AdminUser,
):
return await update_record(project_id, table_code, record_id, body, user["username"])
@@ -365,6 +365,6 @@ async def remove_record(
project_id: str,
table_code: str,
record_id: str,
user: DataOperatorUser,
user: AdminUser,
):
return await delete_record(project_id, table_code, record_id, user["username"])