15a9ed9435
get_current_owner_id() only checked the session for authenticated users. When the mobile app sends Authorization: Bearer <token>, there is no session cookie, so the Depends(_get_owner_id) dependency raised HTTP 401 before the @require_login wrapper could resolve the Bearer token. The function now checks three sources in order: 1. Session user dict (existing behavior) 2. request.state.api_token_user (cached by require_login or prior call) 3. Direct Bearer token resolution via _resolve_bearer_user (new) Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>