50 lines
2.3 KiB
Python
50 lines
2.3 KiB
Python
from fastapi import APIRouter, HTTPException, Depends
|
|
from sqlmodel import Session, select
|
|
from typing import List
|
|
|
|
from ..model.models import UserResponse, UserCreate, UserDB, UserUpdate
|
|
from ..services.database import engine, get_session, add_and_refresh
|
|
from ..services.auth import get_password_hash, get_current_user, auth_is_admin
|
|
|
|
user_router = APIRouter(tags=["Users"])
|
|
|
|
@user_router.post("/users/", response_model=UserResponse)
|
|
def create_user(*, db: Session = Depends(get_session), user: UserCreate, admin: bool = Depends(auth_is_admin)):
|
|
print("creating user with data ", user)
|
|
hashed_password = {"passwordhash": get_password_hash(user.password)}
|
|
db_user = UserDB.model_validate(user, update=hashed_password)
|
|
return add_and_refresh(db, db_user)
|
|
|
|
@user_router.get("/users/", response_model=List[UserResponse])
|
|
def read_users(*, db: Session = Depends(get_session), admin: bool = Depends(auth_is_admin)):
|
|
users = db.exec(select(UserDB)).all()
|
|
return users
|
|
|
|
@user_router.get("/users/{user_id}", response_model=UserResponse)
|
|
def read_user(*, db: Session = Depends(get_session), user_id: int, admin: bool = Depends(auth_is_admin)):
|
|
db_user = db.get(UserDB, user_id)
|
|
if db_user is None:
|
|
raise HTTPException(status_code=404, detail="User not found")
|
|
return db_user
|
|
|
|
@user_router.patch("/users/{user_id}", response_model=UserResponse)
|
|
def update_user(*, db: Session = Depends(get_session), user_id: int, user: UserUpdate, admin: bool = Depends(auth_is_admin)):
|
|
db_user = db.get(UserDB, user_id)
|
|
if db_user is None:
|
|
raise HTTPException(status_code=404, detail="User not found")
|
|
user_data = user.model_dump(exclude_unset=True)
|
|
hashed_password = {}
|
|
if "password" in user_data:
|
|
password = user_data["password"]
|
|
hashed_password = {"passwordhash": get_password_hash(password)}
|
|
db_user.sqlmodel_update(user_data, update=hashed_password)
|
|
return add_and_refresh(db, db_user)
|
|
|
|
@user_router.delete("/users/{user_id}")
|
|
def delete_user(*, db: Session = Depends(get_session), user_id: int, admin: bool = Depends(auth_is_admin)):
|
|
db_user = db.get(UserDB, user_id)
|
|
if db_user is None:
|
|
raise HTTPException(status_code=404, detail="User not found")
|
|
db.delete(db_user)
|
|
db.commit()
|
|
return {"message": "User deleted successfully"} |