INNER CODE UNIT · Python
APIKeyMiddleware
sunithvs/devb.io · api/main.py:33
class APIKeyMiddleware(BaseHTTPMiddleware):
"""Middleware for API key authentication"""
EXCLUDED_PATHS = {"/docs", "/redoc", "/openapi.json"}
async def dispatch(self, request: Request, call_next):
if request.url.path in self.EXCLUDED_PATHS or Settings.DEBUG:
return await call_next(request)
api_key = request.headers.get("X-API-Key")
if not api_key:
return JSONResponse(
status_code=401,
content={"detail": "API Key header is missing"}
)
if api_key not in Settings.API_KEYS:
return JSONResponse(
status_code=403,