Files
webber/webber-api/src/domains/auth/README.md
T
jpmschweitzerandClaude Opus 4.5 3b58fa4f8b
Build and Push API / release (push) Successful in 3s
Build and Push API / build (push) Successful in 2m27s
refactor: reorganize into monorepo with separate subprojects
Structure webber into three independent subprojects:
- webber-api/: FastAPI backend server with all agent code
- webber-cli/: Standalone CLI client (renamed from cli/ to webber_cli/)
- webber-sandbox/: Test project for functional testing

Key changes:
- Each subproject has its own .venv (Python 3.12+)
- Added sandbox.sh for managing test project templates
- Created sandbox-templates/ with calculator-cli and empty starter
- Updated CI/CD for prefixed tags (api/v*, cli/v*)
- Added comprehensive AGENTS.md with operational instructions
- Added gitignore filtering to glob and grep tools
- Created pyproject.toml for each subproject

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-10 10:37:47 +01:00

1.1 KiB

Auth Domain

This domain handles API key management and authentication.

Structure

auth/
├── router.py        # Auth routes
├── controller.py    # Auth logic
└── schemas.py       # Auth models

Authentication Flow

  1. Client sends X-API-Key header
  2. Middleware validates key (via shared/auth.py)
  3. User context set in shared/context.py
  4. Routes use Depends(require_auth) for protected endpoints

Integration with Tatlock

API keys are validated against the tatlock-ui/core-api user management system.

# In shared/auth.py
async def validate_api_key(api_key: str) -> Optional[User]:
    async with httpx.AsyncClient() as client:
        response = await client.get(
            f"{settings.tatlock_api_url}/auth/validate",
            headers={"X-API-Key": api_key}
        )
        if response.status_code == 200:
            return User(**response.json())
    return None

TODO

  • Implement tatlock API key validation
  • Add API key generation endpoint
  • Add rate limiting per API key
  • Add usage tracking