mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-07-26 06:16:09 +00:00
fix(cloud): reuse authenticated account for user info
This commit is contained in:
@@ -222,20 +222,15 @@ class UserRouterGroup(group.RouterGroup):
|
|||||||
except Exception:
|
except Exception:
|
||||||
raise
|
raise
|
||||||
|
|
||||||
@self.route('/info', methods=['GET'], auth_type=group.AuthType.USER_TOKEN)
|
@self.route('/info', methods=['GET'], auth_type=group.AuthType.ACCOUNT_TOKEN)
|
||||||
async def _(user_email: str) -> str:
|
async def _(account) -> str:
|
||||||
"""Get current user information including account type"""
|
"""Get current Account information without re-querying under Workspace RLS."""
|
||||||
user_obj = await self.ap.user_service.get_user_by_email(user_email)
|
|
||||||
|
|
||||||
if user_obj is None:
|
|
||||||
return self.http_status(404, -1, 'User not found')
|
|
||||||
|
|
||||||
return self.success(
|
return self.success(
|
||||||
data={
|
data={
|
||||||
'account_uuid': user_obj.uuid,
|
'account_uuid': account.uuid,
|
||||||
'user': user_obj.user,
|
'user': account.user,
|
||||||
'account_type': user_obj.account_type,
|
'account_type': account.account_type,
|
||||||
'has_password': bool(user_obj.password and user_obj.password.strip()),
|
'has_password': bool(account.password and account.password.strip()),
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -130,6 +130,22 @@ async def test_fresh_sqlite_login_returns_current_workspace_and_user_info(worksp
|
|||||||
assert info['user'] == 'owner@example.com'
|
assert info['user'] == 'owner@example.com'
|
||||||
|
|
||||||
|
|
||||||
|
async def test_user_info_uses_the_account_resolved_from_the_token(workspace_api):
|
||||||
|
application, client, _, owner_token = workspace_api
|
||||||
|
account = await application.user_service.get_authenticated_account(owner_token)
|
||||||
|
|
||||||
|
application.user_service.get_authenticated_account = AsyncMock(return_value=account)
|
||||||
|
application.user_service.get_user_by_email = AsyncMock(return_value=None)
|
||||||
|
|
||||||
|
response = await client.get('/api/v1/user/info', headers=_auth(owner_token))
|
||||||
|
|
||||||
|
assert response.status_code == 200
|
||||||
|
info = (await response.get_json())['data']
|
||||||
|
assert info['account_uuid'] == account.uuid
|
||||||
|
assert info['user'] == account.user
|
||||||
|
application.user_service.get_user_by_email.assert_not_awaited()
|
||||||
|
|
||||||
|
|
||||||
async def test_authenticated_system_info_reads_workspace_wizard_metadata(workspace_api):
|
async def test_authenticated_system_info_reads_workspace_wizard_metadata(workspace_api):
|
||||||
application, client, _, owner_token = workspace_api
|
application, client, _, owner_token = workspace_api
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user