Kairo-Jinkendo/backend/routers/config.py
Lars 53047b6c16
All checks were successful
Deploy Development / deploy (push) Successful in 38s
Test Suite / pytest-backend (push) Successful in 18s
Test Suite / lint-backend (push) Successful in 1s
Test Suite / compose-smoke (push) Has been skipped
Test Suite / k6 /api/health Baseline (push) Successful in 18s
Test Suite / playwright-smoke (push) Successful in 24s
AP0.4: Feature-, Prompt- und Config-Registry mit Single-Render und Entitlements-Features.
Migration 005, Registry-Sync, Placeholder-Validation, capability-geschuetzte API, Tests und Abschlussbericht v0.1.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-04 23:29:02 +02:00

62 lines
1.9 KiB
Python

"""Configuration registry API."""
from __future__ import annotations
from typing import Any
from capabilities import require_capability_ctx
from config_service import SECRET_VALUE_FORBIDDEN, list_configs, upsert_config
from fastapi import APIRouter, Depends, HTTPException
from pydantic import BaseModel, Field
from tenant_context import TenantContext
router = APIRouter(prefix="/api/config", tags=["config"])
class ConfigUpsertRequest(BaseModel):
config_key: str
scope: str = "global"
value: Any = None
value_type: str = "string"
description: str = ""
is_secret: bool = False
tenant_id: str | None = None
@router.get("")
def get_configs(
scope: str | None = None,
ctx: TenantContext = Depends(require_capability_ctx("kairo.config.registry.read")),
):
tenant_id = ctx.tenant_id if scope == "tenant" else None
if scope == "tenant" and not tenant_id:
raise HTTPException(status_code=400, detail="Aktiver Tenant erforderlich für tenant-scope")
return list_configs(scope=scope, tenant_id=tenant_id)
@router.post("")
def post_config(
body: ConfigUpsertRequest,
ctx: TenantContext = Depends(require_capability_ctx("kairo.config.registry.manage")),
):
tenant_id = body.tenant_id
if body.scope == "tenant":
tenant_id = tenant_id or ctx.tenant_id
if not tenant_id:
raise HTTPException(status_code=400, detail="tenant_id erforderlich")
try:
return upsert_config(
config_key=body.config_key,
scope=body.scope,
value=body.value,
value_type=body.value_type,
description=body.description,
is_secret=body.is_secret,
tenant_id=tenant_id,
user_id=ctx.user_id,
)
except ValueError as exc:
if str(exc) == SECRET_VALUE_FORBIDDEN:
raise HTTPException(status_code=400, detail=str(exc)) from exc
raise HTTPException(status_code=400, detail=str(exc)) from exc