commit fcd005b8624023547f28b7b28e59e6099bcfc7d4
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 20:24:07 2025 +1100
Openapi tightening
commit f93bd8f641d561052c7bd075bae321b4ff3b676d
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 19:03:52 2025 +1100
Removed refactor strategy doc
commit 0c5a61092f522be0c47cbbe86917c8a7e4e2d339
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 17:48:33 2025 +1100
mypy & ruff checks
commit 23d66d6b18984127e17c73c3063f6120385935e9
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 16:49:35 2025 +1100
Final removal of db.py files
commit f454aed1ca9783cc558cc203f29a7fe31b62a975
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:42:31 2025 +1100
Finalise restructure, remove db.py files
commit 7187f6dd89489521538791c6bdebb426514beb99
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:34:54 2025 +1100
commit 6fea227ae20d32b8eb1e7a4885006a620fcc7bb1
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:32:53 2025 +1100
commit 27415e7e02d89195ad514cb017a9dbbf84d7a5e4
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:31:10 2025 +1100
commit b773428033d855f9ad82005602e049c1a2e3c585
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:28:58 2025 +1100
commit 116592c95278d995f4c516e87f2cea43cf5b7735
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:25:21 2025 +1100
commit 03ec565faea088971968ee2f9bb83e2de16b21f3
Author: jableader <jacobdunk@gmail.com>
Date: Sun Oct 19 15:21:29 2025 +1100
Plan
109 lines
4 KiB
Python
109 lines
4 KiB
Python
from __future__ import annotations
|
|
|
|
from typing import Any
|
|
|
|
from fastapi import FastAPI
|
|
|
|
|
|
def extend_with_problem_and_cookie_auth(app: FastAPI) -> None:
|
|
"""Augment FastAPI's OpenAPI spec with RFC7807 responses and cookie auth.
|
|
|
|
This mutates the app's OpenAPI generation in-place while delegating to the
|
|
original generator for the base schema.
|
|
"""
|
|
original_openapi = app.openapi
|
|
|
|
def custom_openapi() -> dict[str, Any]:
|
|
spec = original_openapi()
|
|
components = spec.setdefault("components", {})
|
|
responses = components.setdefault("responses", {})
|
|
security_schemes = components.setdefault("securitySchemes", {})
|
|
|
|
# Standard ProblemDetails responses
|
|
responses.setdefault(
|
|
"Problem400",
|
|
{
|
|
"description": "Bad Request",
|
|
"content": {
|
|
"application/problem+json": {},
|
|
"application/json": {"schema": {"$ref": "#/components/schemas/ProblemDetails"}},
|
|
},
|
|
},
|
|
)
|
|
responses.setdefault(
|
|
"Problem404",
|
|
{
|
|
"description": "Not Found",
|
|
"content": {
|
|
"application/problem+json": {},
|
|
"application/json": {"schema": {"$ref": "#/components/schemas/ProblemDetails"}},
|
|
},
|
|
},
|
|
)
|
|
responses.setdefault(
|
|
"Problem422",
|
|
{
|
|
"description": "Validation Error",
|
|
"content": {
|
|
"application/problem+json": {"schema": {"$ref": "#/components/schemas/ProblemDetails"}},
|
|
"application/json": {"schema": {"$ref": "#/components/schemas/ProblemDetails"}},
|
|
},
|
|
},
|
|
)
|
|
|
|
# Cookie-based auth for documentation (does not enforce at runtime)
|
|
security_schemes.setdefault(
|
|
"cookieAuth",
|
|
{
|
|
"type": "apiKey",
|
|
"in": "cookie",
|
|
"name": "user_id",
|
|
"description": "Authentication via user_id cookie (session-style).",
|
|
},
|
|
)
|
|
|
|
# Normalize v1 responses and mark cookie security for known endpoints
|
|
paths = spec.get("paths", {})
|
|
protected_ops: set[str] = {
|
|
"parseRecipe",
|
|
"createRecipe",
|
|
"deleteRecipe",
|
|
"markMealConsumed",
|
|
"deleteMeal",
|
|
"purchaseIngredients",
|
|
"getMyShoppingList",
|
|
"syncMyShoppingList",
|
|
"requestMeal",
|
|
"unrequestMeal",
|
|
"refresh",
|
|
}
|
|
for path, ops in paths.items():
|
|
if not isinstance(path, str) or not path.startswith("/api/v1/"):
|
|
continue
|
|
if not isinstance(ops, dict):
|
|
continue
|
|
for _method, op in ops.items():
|
|
if not isinstance(op, dict):
|
|
continue
|
|
resp = op.get("responses")
|
|
if not isinstance(resp, dict):
|
|
continue
|
|
if "400" in resp:
|
|
resp["400"] = {"$ref": "#/components/responses/Problem400"}
|
|
if "404" in resp:
|
|
resp["404"] = {"$ref": "#/components/responses/Problem404"}
|
|
if "422" not in resp:
|
|
resp["422"] = {"$ref": "#/components/responses/Problem422"}
|
|
|
|
op_id = op.get("operationId")
|
|
if isinstance(op_id, str) and op_id in protected_ops:
|
|
security = op.setdefault("security", [])
|
|
if not any(isinstance(s, dict) and "cookieAuth" in s for s in security):
|
|
security.append({"cookieAuth": []})
|
|
|
|
# Keep endpoint-specific schemas driven by route declarations only (no forced overrides)
|
|
|
|
return spec
|
|
|
|
# Rebind app.openapi to our generator (FastAPI supports this pattern). Mypy needs a narrow ignore here.
|
|
app.openapi = custom_openapi # type: ignore[method-assign]
|