Files
gh-christianlouis-leagueledger/app/auth/middleware.py
T
Christian Krakau-Louis 6306abf6d9 Add comprehensive documentation for LeagueLedger
- Created architecture overview in development/architecture.md
- Added installation guide in getting-started/installation.md
- Developed user guide with detailed instructions in user-guide/overview.md, user-guide/teams.md, user-guide/qr-codes.md
- Implemented social login setup documentation in social_login_setup.md
- Updated index.md to include links to new documentation sections
- Configured mkdocs.yml for site structure and theme
- Added requirements.txt for documentation dependencies
2025-04-15 12:32:03 +02:00

74 lines
2.7 KiB
Python

from starlette.authentication import (
AuthCredentials, AuthenticationBackend, UnauthenticatedUser
)
from sqlalchemy.orm import Session
from ..db import SessionLocal
from ..models import User
class SessionAuthBackend(AuthenticationBackend):
"""
Authentication backend that uses session data to authenticate users.
This maintains compatibility with the existing session-based authentication
while providing the structure of Starlette's authentication system.
"""
async def authenticate(self, request):
"""
Authenticate the user from the session.
Args:
request: The FastAPI/Starlette request object.
Returns:
Tuple of (AuthCredentials, User) if authenticated,
or None if not authenticated.
"""
# Check for user_id in session
user_id = request.session.get("user_id")
if not user_id:
# Return None to indicate no authentication
return None
# Get database connection
db = SessionLocal()
try:
# Fetch user from database
user = db.query(User).filter(User.id == user_id).first()
# If user exists, set credentials and return user
if user:
# Base credentials for all authenticated users
scopes = ["authenticated"]
# Add admin scope if user is admin
if user.is_admin:
scopes.append("admin")
# Add verified scope if user is verified
if user.is_verified:
scopes.append("verified")
# Add OAuth provider scope if it exists
# This allows policies to be set based on authentication source
oauth_provider = request.session.get("oauth_provider")
if oauth_provider:
scopes.append(f"oauth:{oauth_provider}")
# Return credentials and user
return AuthCredentials(scopes), user
finally:
db.close()
# If we get here, user not found but session exists
# Clear session on next request (handled in middleware)
return None
def on_auth_error(request, exc):
"""Handle authentication errors by redirecting to login"""
from fastapi.responses import RedirectResponse
# Build the redirect URL with the original requested path as 'next'
login_url = f"/auth/login?next={request.url.path}"
# Return redirect response
return RedirectResponse(url=login_url, status_code=303)