diff --git a/run.py b/run.py index b893c22..f88e65c 100644 --- a/run.py +++ b/run.py @@ -1,5 +1,5 @@ import uvicorn -from server.backend import endpoints # импортируем FastAPI экземпляр из файла app.py +from server.backend import endpoints# импортируем FastAPI экземпляр из файла app.py import asyncio from server.database import db if __name__ == "__main__": diff --git a/server/backend/endpoints.py b/server/backend/endpoints.py index bc7703b..c5e6faa 100644 --- a/server/backend/endpoints.py +++ b/server/backend/endpoints.py @@ -12,7 +12,6 @@ from datetime import datetime, timedelta import asyncio api = FastAPI() - from dotenv import load_dotenv #Работа с env для CORS import os load_dotenv() @@ -28,16 +27,6 @@ api.add_middleware( allow_headers=headers, ) -# @api.middleware("http") #Логирование заходов перед всеми endpoints / возможно не нужен, так как то же самое делает uvicorn -# async def log_requests(request: Request, call_next): -# ip = request.client.host #ip -# ua = request.headers.get("user-agent") #browser -# method = request.method #method -# url = str(request.url) #url -# print(f"[{method}] {url} from {ip} ({ua})") -# response = await call_next(request) -# return response - @api.get("/protected") #test async def protected(current_user: str = Depends(JWT.current_user)): return {"msg": f"Hello, {current_user}"} @@ -45,8 +34,8 @@ async def protected(current_user: str = Depends(JWT.current_user)): @api.get("/", response_model=list[pydentic.UserOut]) #список! async def get_all_rows(current_user: str = Depends(JWT.current_user)): users = await db.get_all_rows() - if not users: - raise HTTPException(status_code=404, detail="No users found") + if not user: + raise HTTPException(status_code=401, detail="The user isn't found") return users @api.get("/get_user_by_email/{email}", response_model=pydentic.UserOut) async def get_user_by_email(email:str, current_user: str = Depends(JWT.current_user)): @@ -54,24 +43,27 @@ async def get_user_by_email(email:str, current_user: str = Depends(JWT.current_u if user: return user else: - raise HTTPException(status_code=404, detail="The user isn't found") + raise HTTPException(status_code=401, detail="The user isn't found") @api.post("/user_create", response_model=pydentic.UserOut) async def create_user(row:pydentic.CreateUser): new_row = pydentic.CreateUser(email=row.email, description=row.description, activated = row.activated, password = row.password) - await db.create_user(new_row) + try: + await db.create_user(new_row) + except: + raise HTTPException(status_code=409, detail="User with this email already exists") return new_row @api.delete("/user_delete/{email}", response_model=pydentic.UserOut) async def delete_user(email:str,current_user: str = Depends(JWT.current_user)): user = await db.get_user_by_email(email) if not user: - raise HTTPException(status_code=404, detail="The user isn't found") + raise HTTPException(status_code=401, detail="The user isn't found") await db.delete_user(email) return user @api.put("/user_update/{email}", response_model=pydentic.UserOut) async def update_user(email:str, updated_row: pydentic.UserUpdate, current_user: str = Depends(JWT.current_user)): user = await db.get_user_by_email(email) if not user: - raise HTTPException(status_code=404, detail="The user isn't found") + raise HTTPException(status_code=401, detail="The user isn't found") changed = False if updated_row.email is not None and updated_row.email != user.email: user.email = updated_row.email @@ -92,7 +84,10 @@ async def update_user(email:str, updated_row: pydentic.UserUpdate, current_user: return user @api.post("/login") async def login_user(form_data: OAuth2PasswordRequestForm = Depends()): - creds = pydentic.UserLogin(email=form_data.username, password=form_data.password) + try: + creds = pydentic.UserLogin(email=form_data.username, password=form_data.password) + except: + raise HTTPException(status_code=422, detail="Email is not a valid email address") user = await db.login_user(creds) if not user: raise HTTPException(status_code=401, detail="The user isn't found") @@ -103,7 +98,6 @@ async def login_user(form_data: OAuth2PasswordRequestForm = Depends()): return {"access_token": access_token, "token_type": "bearer"} @api.post("/reset", response_model=pydentic.UserOut) async def reset_user(row:pydentic.UserReset): - user = await db.get_user_by_email(row.email) if not user: raise HTTPException(status_code=401, detail="The user isn't found") diff --git a/server/database/db.py b/server/database/db.py index 7f700bd..e8982c9 100644 --- a/server/database/db.py +++ b/server/database/db.py @@ -1,9 +1,11 @@ import asyncio +from datetime import datetime,timezone + #from sqlalchemy import create_engine #Не async from sqlalchemy.orm import DeclarativeBase, sessionmaker from sqlalchemy.ext.asyncio import AsyncSession, create_async_engine -from sqlalchemy import Column, Integer, String, Boolean, select +from sqlalchemy import Column, Integer, String, Boolean, select,func, DateTime from pathlib import Path db_folder = Path(__file__).parent / "DB" @@ -12,6 +14,7 @@ db_path = db_folder / "example.db" async_engine = create_async_engine(f"sqlite+aiosqlite:///{db_path}", echo=True) #sqlite+aiosqlite — тип БД + async-драйвер ///example.db — путь к файлу (три слэша, если путь относительный; четыре, если абсолютный #async_engine = create_async_engine( "postgresql+asyncpg://user:pass@host:5432/mydb", echo=True) #Можно указать Pgpool-II для psql или proxysql для mysql mariadb + from passlib.context import CryptContext #Hash password pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto") @@ -33,6 +36,9 @@ class User(Base): description = Column(String, nullable=False) activated = Column(Boolean, default=False) password = Column(String, nullable=False) + created_at = Column(DateTime(timezone=True), server_default=func.now()) + updated_at = Column(DateTime(timezone=True), onupdate=func.now()) + last_login = Column(DateTime(timezone=True)) async def init_db(): async with async_engine.begin() as conn: @@ -75,6 +81,8 @@ async def login_user(user_info): result = await session.execute(select(User).where(User.email == user_info.email)) user = result.scalar_one_or_none() if user and verify_password(user_info.password, user.password): + user.last_login=datetime.now(timezone.utc) + await session.commit() return user return None async def reset_user(user_info):