72b6879f4b
- Refactored max_bot from nested packages to flat module structure - Q2: Extended BotUser model (patronymic, email, org, address, vcf_raw, contact_hash, phone_verified, email_verified, last_interaction, total_conversations, total_tickets) - Q2: VCF parser (FN, N, TEL, EMAIL, ORG, ADR), upsert on re-contact, NLP history context (_get_user_history_context -> YandexGPT) - Q1: Broadcast preview modal with 10s confirmation timer - Q3: CSS var(--white)->var(--bg-card), var(--text)->var(--text-primary) - Q4: bot_settings showNotification(), editable max_bot_id - Q5: Webhook secret passthrough via X-Max-Bot-Api-Secret - Masking sensitive keys, dialog_cleared handler, migrate via _add_column_if_not_exists() - Rate limit (asyncio.sleep 0.5 per 10), dead code removed, conv.intent context in contact.py - Portal pages: bot_consent, bot_kb (edit), bot_settings, bot_test, bot_tickets, portal_settings - Tests: 21/21 passing, added test_yandex_gpt.py, test_email_sender.py - Deploy: deploy_full.sh, schema.sql, seed_knowledge_base.sql
17 lines
581 B
Python
17 lines
581 B
Python
from fastapi import Request, Depends, HTTPException
|
|
from fastapi.responses import RedirectResponse
|
|
|
|
|
|
def get_current_user(request: Request) -> dict | None:
|
|
return request.session.get("user")
|
|
|
|
|
|
def require_role(*roles: str):
|
|
def dependency(request: Request, user: dict = Depends(get_current_user)):
|
|
if not user:
|
|
return RedirectResponse(url="/service/login", status_code=302)
|
|
if roles and user["role"] not in roles:
|
|
raise HTTPException(status_code=403, detail="Доступ запрещён")
|
|
return user
|
|
return dependency
|