fix(cloud): reuse authenticated account for user info

This commit is contained in:
dadachann
2026-07-25 02:41:31 +08:00
parent 84440df47f
commit 64e772e32d
2 changed files with 23 additions and 12 deletions
@@ -222,20 +222,15 @@ class UserRouterGroup(group.RouterGroup):
except Exception:
raise
@self.route('/info', methods=['GET'], auth_type=group.AuthType.USER_TOKEN)
async def _(user_email: str) -> str:
"""Get current user information including account type"""
user_obj = await self.ap.user_service.get_user_by_email(user_email)
if user_obj is None:
return self.http_status(404, -1, 'User not found')
@self.route('/info', methods=['GET'], auth_type=group.AuthType.ACCOUNT_TOKEN)
async def _(account) -> str:
"""Get current Account information without re-querying under Workspace RLS."""
return self.success(
data={
'account_uuid': user_obj.uuid,
'user': user_obj.user,
'account_type': user_obj.account_type,
'has_password': bool(user_obj.password and user_obj.password.strip()),
'account_uuid': account.uuid,
'user': account.user,
'account_type': account.account_type,
'has_password': bool(account.password and account.password.strip()),
}
)
+16
View File
@@ -130,6 +130,22 @@ async def test_fresh_sqlite_login_returns_current_workspace_and_user_info(worksp
assert info['user'] == 'owner@example.com'
async def test_user_info_uses_the_account_resolved_from_the_token(workspace_api):
application, client, _, owner_token = workspace_api
account = await application.user_service.get_authenticated_account(owner_token)
application.user_service.get_authenticated_account = AsyncMock(return_value=account)
application.user_service.get_user_by_email = AsyncMock(return_value=None)
response = await client.get('/api/v1/user/info', headers=_auth(owner_token))
assert response.status_code == 200
info = (await response.get_json())['data']
assert info['account_uuid'] == account.uuid
assert info['user'] == account.user
application.user_service.get_user_by_email.assert_not_awaited()
async def test_authenticated_system_info_reads_workspace_wizard_metadata(workspace_api):
application, client, _, owner_token = workspace_api