Atualizar app/app.py
This commit is contained in:
+85
@@ -34,6 +34,19 @@ def notifications(ws):
|
|||||||
ws.send(json.dumps({"type": "pong", "payload": data}))
|
ws.send(json.dumps({"type": "pong", "payload": data}))
|
||||||
|
|
||||||
|
|
||||||
|
def admin_required(f):
|
||||||
|
@wraps(f)
|
||||||
|
def wrapper(*args, **kwargs):
|
||||||
|
db = SessionLocal()
|
||||||
|
email = session["user"]["email"]
|
||||||
|
u = db.query(User).filter_by(email=email).first()
|
||||||
|
db.close()
|
||||||
|
|
||||||
|
if not u or u.role != "admin":
|
||||||
|
return jsonify({"error": "Admin only"}), 403
|
||||||
|
|
||||||
|
return f(*args, **kwargs)
|
||||||
|
return wrapper
|
||||||
|
|
||||||
|
|
||||||
def require_capability(cap):
|
def require_capability(cap):
|
||||||
@@ -96,6 +109,78 @@ def oauth_callback():
|
|||||||
db.close()
|
db.close()
|
||||||
return redirect("/")
|
return redirect("/")
|
||||||
|
|
||||||
|
# ================
|
||||||
|
# ADMIN
|
||||||
|
# ================
|
||||||
|
|
||||||
|
@app.route("/admin/users")
|
||||||
|
@login_required
|
||||||
|
@admin_required
|
||||||
|
def admin_users():
|
||||||
|
db = SessionLocal()
|
||||||
|
users = db.query(User).all()
|
||||||
|
data = [{
|
||||||
|
"email": u.email,
|
||||||
|
"name": u.name,
|
||||||
|
"role": u.role,
|
||||||
|
"can_use_audio": u.can_use_audio,
|
||||||
|
"can_use_vision": u.can_use_vision,
|
||||||
|
"can_share": u.can_share,
|
||||||
|
"can_import_docs": u.can_import_docs,
|
||||||
|
"can_export_pdf": u.can_export_pdf,
|
||||||
|
"can_export_md": u.can_export_md,
|
||||||
|
} for u in users]
|
||||||
|
db.close()
|
||||||
|
return jsonify(data)
|
||||||
|
|
||||||
|
@app.route("/admin/update_acl/<email>", methods=["POST"])
|
||||||
|
@login_required
|
||||||
|
@admin_required
|
||||||
|
def update_acl(email):
|
||||||
|
db = SessionLocal()
|
||||||
|
u = db.query(User).filter_by(email=email).first()
|
||||||
|
if not u:
|
||||||
|
return jsonify({"error": "User not found"}), 404
|
||||||
|
|
||||||
|
data = request.json
|
||||||
|
for key, value in data.items():
|
||||||
|
if hasattr(u, key):
|
||||||
|
setattr(u, key, value)
|
||||||
|
|
||||||
|
db.commit()
|
||||||
|
db.close()
|
||||||
|
return jsonify({"status": "ok"})
|
||||||
|
|
||||||
|
|
||||||
|
@app.route("/admin/promote/<email>", methods=["POST"])
|
||||||
|
@login_required
|
||||||
|
@admin_required
|
||||||
|
def promote(email):
|
||||||
|
db = SessionLocal()
|
||||||
|
u = db.query(User).filter_by(email=email).first()
|
||||||
|
if not u:
|
||||||
|
return jsonify({"error": "User not found"}), 404
|
||||||
|
|
||||||
|
u.role = "admin"
|
||||||
|
db.commit()
|
||||||
|
db.close()
|
||||||
|
return jsonify({"status": "ok"})
|
||||||
|
|
||||||
|
@app.route("/admin/conversations/<email>")
|
||||||
|
@login_required
|
||||||
|
@admin_required
|
||||||
|
def admin_conversations(email):
|
||||||
|
db = SessionLocal()
|
||||||
|
convs = db.query(Conversation).filter_by(user_email=email).all()
|
||||||
|
data = [{"id": c.id, "title": c.title, "tags": c.tags} for c in convs]
|
||||||
|
db.close()
|
||||||
|
return jsonify(data)
|
||||||
|
|
||||||
|
|
||||||
|
# ================
|
||||||
|
# API
|
||||||
|
# ================
|
||||||
|
|
||||||
|
|
||||||
@app.route("/api/new_conversation", methods=["POST"])
|
@app.route("/api/new_conversation", methods=["POST"])
|
||||||
@login_required
|
@login_required
|
||||||
|
|||||||
Reference in New Issue
Block a user