Protect recipe API with bearer token
This commit is contained in:
@@ -25,6 +25,12 @@ def settings() -> tuple[str, dict]:
|
||||
return key, config
|
||||
|
||||
|
||||
def authorized() -> bool:
|
||||
expected = os.environ.get("RECIPE_API_TOKEN")
|
||||
authorization = request.headers.get("Authorization", "")
|
||||
return bool(expected and authorization == f"Bearer {expected}")
|
||||
|
||||
|
||||
@app.get("/health")
|
||||
def health():
|
||||
return jsonify(status="ok")
|
||||
@@ -32,6 +38,8 @@ def health():
|
||||
|
||||
@app.post("/recipe")
|
||||
def recipe():
|
||||
if not authorized():
|
||||
return jsonify(error="unauthorized"), 401
|
||||
image = request.files.get("image")
|
||||
prompt = request.form.get("prompt")
|
||||
if image is None or not prompt:
|
||||
|
||||
Reference in New Issue
Block a user