feat: harden data access and simplify user management
This commit is contained in:
1 parent
3dd5731751
commit
adb780bc82
51 files changed
+3239
-2121
No files matched your search
+11
-11
@@ -5,7 +5,7 @@ from typing import Any
|
||||
|
||||
from fastapi import APIRouter, File, HTTPException, Query, Request, Response, UploadFile
|
||||
|
||||
from app.auth import AdminUser, CurrentUser, DataOperatorUser
|
||||
from app.auth import AdminUser, CurrentUser, DataViewerUser
|
||||
from app.data_platform.mysql_service import (
|
||||
IDENTIFIER_PATTERN,
|
||||
MAX_CSV_BYTES,
|
||||
@@ -37,7 +37,7 @@ router = APIRouter(prefix="/data-platform")
|
||||
|
||||
|
||||
@router.get("/databases")
|
||||
async def databases(_user: DataOperatorUser):
|
||||
async def databases(_user: DataViewerUser):
|
||||
return await list_databases()
|
||||
|
||||
|
||||
@@ -93,7 +93,7 @@ async def remove_database(project_id: str, body: dict[str, Any], user: CurrentUs
|
||||
|
||||
|
||||
@router.get("/databases/{project_id}/tables")
|
||||
async def tables(project_id: str, _user: DataOperatorUser):
|
||||
async def tables(project_id: str, _user: DataViewerUser):
|
||||
return await list_tables(project_id)
|
||||
|
||||
|
||||
@@ -126,7 +126,7 @@ async def security_audit_logs(
|
||||
|
||||
|
||||
@router.get("/databases/{project_id}/tables/{table_code}/inspection")
|
||||
async def table_inspection(project_id: str, table_code: str, _user: DataOperatorUser):
|
||||
async def table_inspection(project_id: str, table_code: str, _user: DataViewerUser):
|
||||
return await inspect_table(project_id, table_code)
|
||||
|
||||
|
||||
@@ -259,7 +259,7 @@ async def remove_table(
|
||||
async def records(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
_user: DataOperatorUser,
|
||||
_user: DataViewerUser,
|
||||
page: int = Query(default=1, ge=1),
|
||||
page_size: int = Query(default=50, ge=1, le=5000),
|
||||
search: str | None = None,
|
||||
@@ -293,7 +293,7 @@ async def _read_csv_upload(file: UploadFile) -> tuple[bytes, str]:
|
||||
async def preview_records_import(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
user: DataOperatorUser,
|
||||
user: AdminUser,
|
||||
file: UploadFile = File(...),
|
||||
):
|
||||
content, file_name = await _read_csv_upload(file)
|
||||
@@ -304,7 +304,7 @@ async def preview_records_import(
|
||||
async def import_records(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
user: DataOperatorUser,
|
||||
user: AdminUser,
|
||||
file: UploadFile = File(...),
|
||||
):
|
||||
content, file_name = await _read_csv_upload(file)
|
||||
@@ -321,7 +321,7 @@ async def import_records(
|
||||
async def export_records(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
_user: DataOperatorUser,
|
||||
_user: DataViewerUser,
|
||||
search: str | None = None,
|
||||
):
|
||||
content, filename, total = await export_csv_records(
|
||||
@@ -344,7 +344,7 @@ async def add_record(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
body: dict[str, Any],
|
||||
user: DataOperatorUser,
|
||||
user: AdminUser,
|
||||
):
|
||||
return await create_record(project_id, table_code, body, user["username"])
|
||||
|
||||
@@ -355,7 +355,7 @@ async def edit_record(
|
||||
table_code: str,
|
||||
record_id: str,
|
||||
body: dict[str, Any],
|
||||
user: DataOperatorUser,
|
||||
user: AdminUser,
|
||||
):
|
||||
return await update_record(project_id, table_code, record_id, body, user["username"])
|
||||
|
||||
@@ -365,6 +365,6 @@ async def remove_record(
|
||||
project_id: str,
|
||||
table_code: str,
|
||||
record_id: str,
|
||||
user: DataOperatorUser,
|
||||
user: AdminUser,
|
||||
):
|
||||
return await delete_record(project_id, table_code, record_id, user["username"])
|
||||
Reference in new issue
Block a user