INNER CODE UNIT · Python
SidecarAuthMiddleware
mouseart2025/AI-Reader-V2 · backend/src/api/main.py:111
class SidecarAuthMiddleware:
"""V-01 修复:配置了 sidecar 令牌时,/api/* 与 /ws/* 一律要求鉴权。
背景:桌面端 sidecar 监听 loopback 随机端口,但 loopback 绑定与 CORS 都不是
认证手段——同机任意进程都能直接请求。Tauri 宿主每次启动生成随机令牌并经
环境变量传入(src.infra.config.SIDECAR_TOKEN);未配置(web 直跑/开发)全放行。
- HTTP:要求 ``Authorization: Bearer <token>``
- WebSocket(浏览器/WebView 无法自定义头):要求 ``?token=<token>``
- 豁免:``/api/health``(宿主健康检查,无敏感信息)与 OPTIONS(CORS 预检)
"""
def __init__(self, app):
self.app = app
async def __call__(self, scope, receive, send):
if scope["type"] not in ("http", "websocket"):
return await self.app(scope, receive, send)