Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 7 additions & 15 deletions app/app.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,17 +5,14 @@
from fastapi.middleware.cors import CORSMiddleware
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials
from .schema import (
LoginSchema,
SignUpSchema,
MenuSchema,
AddStaffSchema,
UpdateStaffEmailSchema,
UpdateMenuItemSchema,
MenuScanResponse
)
from .auth import (
auth_signup_users,
auth_login_users,
authenticate_student,

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
verify_staff_access
)
from .staff import (
Expand All @@ -37,7 +34,6 @@

app.add_middleware(
CORSMiddleware,

allow_origins=[
"http://localhost:5000",
"http://127.0.0.1:5000",
Expand All @@ -57,17 +53,13 @@
"environment": os.getenv("ENV", "development")
}

@app.post('/auth/verify-staff', tags=["verify"])
async def verify_staff(credentials: HTTPAuthorizationCredentials = Security(security)):
@app.post('/auth/verify-staff', tags=["auth"])
async def verify_staff_endpoint(credentials: HTTPAuthorizationCredentials = Security(security)):

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Missing function or method docstring Warning

Missing function or method docstring

Check warning

Code scanning / Pylint (reported by Codacy)

Missing function docstring Warning

Missing function docstring
return await verify_staff_access(credentials.credentials)

@app.post('/signup/users', tags=["user"])
async def signup_users(user_data: SignUpSchema):
return await auth_signup_users(user_data)

@app.post('/login/users', tags=["user"])
async def login_users(user_data: LoginSchema):
return await auth_login_users(user_data)
@app.post('/auth/verify-student', tags=["auth"])
async def verify_student_endpoint(credentials: HTTPAuthorizationCredentials = Security(security)):

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Missing function or method docstring Warning

Missing function or method docstring

Check warning

Code scanning / Pylint (reported by Codacy)

Missing function docstring Warning

Missing function docstring
return await authenticate_student(credentials.credentials)

@app.get("/user/menu", tags=["user"])
async def get_student_menu_endpoint(
Expand Down Expand Up @@ -146,4 +138,4 @@
return await delete_menu_item(
item_id,
credentials.credentials
)
)

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Final newline missing Warning

Final newline missing

Check warning

Code scanning / Pylint (reported by Codacy)

Final newline missing Warning

Final newline missing
107 changes: 45 additions & 62 deletions app/auth.py
Original file line number Diff line number Diff line change
@@ -1,21 +1,21 @@
# app/auth.py

import os, requests
from .schema import LoginSchema, SignUpSchema
import os

Check warning on line 3 in app/auth.py

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

app/auth.py#L3

'os' imported but unused (F401)

Check notice

Code scanning / Pylint (reported by Codacy)

Unused import os Note

Unused import os

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Unused import os Note

Unused import os

Check warning

Code scanning / Prospector (reported by Codacy)

Unused import os (unused-import) Warning

Unused import os (unused-import)
from fastapi.responses import JSONResponse
from starlette import status
from firebase_admin import auth, firestore
from .firebase_init import db

FIREBASE_API_KEY = os.getenv("FIREBASE_API_KEY")

def _create_response(status_code: int, message: str, **kwargs):
content = {"message": message}
content.update(kwargs)
return JSONResponse(status_code=status_code, content=content)


def _get_college_by_domain(email: str):
try:
if not email: return None, None

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

More than one statement on a single line Warning

More than one statement on a single line

Check warning

Code scanning / Pylint (reported by Codacy)

More than one statement on a single line Warning

More than one statement on a single line

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 (bad-indentation) Warning

Bad indentation. Found 2 spaces, expected 4 (bad-indentation)

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
domain = email.split("@")[-1]
query = (
db.collection("colleges")
Expand All @@ -30,79 +30,63 @@
print(f"College lookup error: {e}")
return None, None

def _validate_passwords(password: str, confirm_password: str):
if password != confirm_password:
return False, "Passwords do not match"
return True, ""

async def auth_signup_users(user_data: SignUpSchema):
email = user_data.email
password = user_data.password
confirm_password = user_data.confirm_password

valid, msg = _validate_passwords(password, confirm_password)
if not valid:
return _create_response(status.HTTP_400_BAD_REQUEST, msg)

college_id, college_data = _get_college_by_domain(email)
if not college_id:
return _create_response(
status.HTTP_400_BAD_REQUEST,
"Your college domain is not registered with GreenPlate.",
)
async def authenticate_student(token: str):

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Missing function or method docstring Warning

Missing function or method docstring

Check warning

Code scanning / Pylint (reported by Codacy)

Missing function docstring Warning

Missing function docstring

try:
user = auth.create_user(email=email, password=password)
db.collection("users").document(user.uid).set(
{
"email": email,
"college_id": college_id,
"college_name": college_data.get("name"),
"role": "student",
"created_at": firestore.SERVER_TIMESTAMP,
}
)
return _create_response(
status.HTTP_201_CREATED, "User created successfully", uid=user.uid
)
except Exception as e:
return _create_response(status.HTTP_500_INTERNAL_SERVER_ERROR, str(e))

try:

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
decoded = auth.verify_id_token(token)

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12
except Exception:

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Catching too general exception Exception Note

Catching too general exception Exception

Check notice

Code scanning / Pylint (reported by Codacy)

Catching too general exception Exception Note

Catching too general exception Exception

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
return _create_response(status.HTTP_401_UNAUTHORIZED, "Invalid or expired token")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 (bad-indentation) Warning

Bad indentation. Found 6 spaces, expected 12 (bad-indentation)

async def auth_login_users(user_data: LoginSchema):
email = user_data.email
password = user_data.password
uid = decoded["uid"]

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
email = decoded.get("email")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)

college_id, _ = _get_college_by_domain(email)
if not college_id:
return _create_response(
status.HTTP_400_BAD_REQUEST,
"Your college domain is not registered.",
)
if not email:

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
return _create_response(status.HTTP_400_BAD_REQUEST, "Invalid token: Email required.")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 (bad-indentation) Warning

Bad indentation. Found 6 spaces, expected 12 (bad-indentation)

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
try:
request_url = f"https://identitytoolkit.googleapis.com/v1/accounts:signInWithPassword?key={FIREBASE_API_KEY}"
payload = {
"email": email,
"password": password,
"returnSecureToken": True
}
response = requests.post(request_url, json=payload)
response_data = response.json()
user_doc_ref = db.collection("users").document(uid)

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
user_doc = user_doc_ref.get()

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)

if response.status_code == 200:
if user_doc.exists:

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
return _create_response(
status.HTTP_200_OK,
"Login successful",

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
idToken=response_data["idToken"],
role="student",

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
college_id=user_doc.to_dict().get("college_id")

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
)

college_id, college_data = _get_college_by_domain(email)

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
if not college_id:

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
try:
auth.delete_user(uid)

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 Note

Bad indentation. Found 8 spaces, expected 16

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 Note

Bad indentation. Found 8 spaces, expected 16

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 (bad-indentation) Warning

Bad indentation. Found 8 spaces, expected 16 (bad-indentation)
except:

Check warning on line 64 in app/auth.py

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

app/auth.py#L64

No exception type(s) specified

Check warning on line 64 in app/auth.py

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

app/auth.py#L64

Try, Except, Pass detected.

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

No exception type(s) specified Note

No exception type(s) specified

Check notice

Code scanning / Pylint (reported by Codacy)

No exception type(s) specified Note

No exception type(s) specified

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check notice

Code scanning / Bandit (reported by Codacy)

Try, Except, Pass detected. Note

Try, Except, Pass detected.

Check warning

Code scanning / Prospector (reported by Codacy)

No exception type(s) specified (bare-except) Warning

No exception type(s) specified (bare-except)

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 (bad-indentation) Warning

Bad indentation. Found 6 spaces, expected 12 (bad-indentation)
pass

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 Note

Bad indentation. Found 8 spaces, expected 16

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 Note

Bad indentation. Found 8 spaces, expected 16

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 8 spaces, expected 16 (bad-indentation) Warning

Bad indentation. Found 8 spaces, expected 16 (bad-indentation)
return _create_response(
status.HTTP_403_FORBIDDEN,
"Your college domain is not registered with GreenPlate.",
)
else:
error_msg = response_data.get("error", {}).get("message", "Login failed")
return _create_response(status.HTTP_401_UNAUTHORIZED, error_msg)

user_doc_ref.set({

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
"email": email,
"college_id": college_id,
"college_name": college_data.get("name"),
"role": "student",
"created_at": firestore.SERVER_TIMESTAMP,
})

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

return _create_response(
status.HTTP_201_CREATED,

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
"User registered and logged in",

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
role="student",

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
college_id=college_id

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 6 spaces, expected 12 Note

Bad indentation. Found 6 spaces, expected 12
)

except Exception as e:
return _create_response(status.HTTP_500_INTERNAL_SERVER_ERROR, str(e))


async def verify_staff_access(token: str):
try:
decoded = auth.verify_id_token(token)
Expand All @@ -121,18 +105,18 @@
"Verified",
role=data.get("role"),
stall_id=data.get("stall_id"),
college_id=data.get("college_id")

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
)

Check notice

Code scanning / Pylint (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

college_id, _ = _get_college_by_domain(email)

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
if not college_id:
return _create_response(status.HTTP_403_FORBIDDEN, "Domain not registered.")

stalls_query = (
db.collection("colleges")
.document(college_id)
.collection("stalls")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
.where("email", "==", email)
.limit(1)
.stream()
Expand All @@ -142,9 +126,8 @@
for doc in stalls_query:
found_stall = doc
break

Check warning

Code scanning / Prospector (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 (bad-indentation) Warning

Bad indentation. Found 4 spaces, expected 8 (bad-indentation)
if found_stall:

new_staff_data = {
"email": email,
"stall_id": found_stall.id,
Expand All @@ -163,10 +146,10 @@
college_id=college_id
)

return _create_response(

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
status.HTTP_403_FORBIDDEN,
"Access Denied. You are not a registered staff member or manager for this college."
)

Check warning

Code scanning / Pylint (reported by Codacy)

Wrong hanging indentation (add 2 spaces). Warning

Wrong hanging indentation (add 2 spaces).
except Exception as e:
return _create_response(status.HTTP_401_UNAUTHORIZED, str(e))
9 changes: 0 additions & 9 deletions app/schema.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,6 @@
from pydantic import BaseModel, Field
from typing import List, Optional

class SignUpSchema(BaseModel):
email: str
password: str
confirm_password: str

class AddStaffSchema(BaseModel):
email: str

Expand All @@ -17,10 +12,6 @@ class StaffAuthResponse(BaseModel):
stall_id: str
college_id: str

class LoginSchema(BaseModel):
email: str
password: str

class UpdateStaffEmailSchema(BaseModel):
new_email: str

Expand Down
Loading