Structure webber into three independent subprojects: - webber-api/: FastAPI backend server with all agent code - webber-cli/: Standalone CLI client (renamed from cli/ to webber_cli/) - webber-sandbox/: Test project for functional testing Key changes: - Each subproject has its own .venv (Python 3.12+) - Added sandbox.sh for managing test project templates - Created sandbox-templates/ with calculator-cli and empty starter - Updated CI/CD for prefixed tags (api/v*, cli/v*) - Added comprehensive AGENTS.md with operational instructions - Added gitignore filtering to glob and grep tools - Created pyproject.toml for each subproject Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
1.1 KiB
1.1 KiB
Auth Domain
This domain handles API key management and authentication.
Structure
auth/
├── router.py # Auth routes
├── controller.py # Auth logic
└── schemas.py # Auth models
Authentication Flow
- Client sends
X-API-Keyheader - Middleware validates key (via
shared/auth.py) - User context set in
shared/context.py - Routes use
Depends(require_auth)for protected endpoints
Integration with Tatlock
API keys are validated against the tatlock-ui/core-api user management system.
# In shared/auth.py
async def validate_api_key(api_key: str) -> Optional[User]:
async with httpx.AsyncClient() as client:
response = await client.get(
f"{settings.tatlock_api_url}/auth/validate",
headers={"X-API-Key": api_key}
)
if response.status_code == 200:
return User(**response.json())
return None
TODO
- Implement tatlock API key validation
- Add API key generation endpoint
- Add rate limiting per API key
- Add usage tracking