INNER CODE UNIT · Python

SidecarAuthMiddleware

mouseart2025/AI-Reader-V2 · backend/src/api/main.py:111

class SidecarAuthMiddleware:
    """V-01 修复:配置了 sidecar 令牌时,/api/* 与 /ws/* 一律要求鉴权。

    背景:桌面端 sidecar 监听 loopback 随机端口,但 loopback 绑定与 CORS 都不是
    认证手段——同机任意进程都能直接请求。Tauri 宿主每次启动生成随机令牌并经
    环境变量传入(src.infra.config.SIDECAR_TOKEN);未配置(web 直跑/开发)全放行。

    - HTTP:要求 ``Authorization: Bearer <token>``
    - WebSocket(浏览器/WebView 无法自定义头):要求 ``?token=<token>``
    - 豁免:``/api/health``(宿主健康检查,无敏感信息)与 OPTIONS(CORS 预检)
    """

    def __init__(self, app):
        self.app = app

    async def __call__(self, scope, receive, send):
        if scope["type"] not in ("http", "websocket"):
            return await self.app(scope, receive, send)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…