INNER CODE UNIT · Python
_check_admin_token
SPThole/CoexistAI · app.py:195
def _check_admin_token(token: str = None):
# token supplied via header X-Admin-Token or env ADMIN_TOKEN
# FastAPI dependency will pass header automatically when named 'x_admin_token'
env_token = os.environ.get('ADMIN_TOKEN')
if env_token is None:
# no admin token configured; disallow by default to avoid accidental exposure
raise HTTPException(status_code=403, detail='Admin actions disabled (no ADMIN_TOKEN set)')
if token != env_token:
raise HTTPException(status_code=401, detail='Invalid admin token')
return True
@app.post('/admin/reload-config')
async def admin_reload_config(request: Request):
"""Reload model config from the configured JSON file. Protected by ADMIN_TOKEN env var.
Send header 'X-Admin-Token: <token>' to authenticate. Returns the reloaded config on success.
"""
token = request.headers.get('X-Admin-Token')