Skip to content

Commit bdc5bc0

Browse files
committed
fix: login_required accepts ADMIN_API_KEY env var for clean programmatic auth
1 parent aba39e0 commit bdc5bc0

1 file changed

Lines changed: 8 additions & 5 deletions

File tree

‎admin_blueprint.py‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -117,19 +117,22 @@ def get_tier_rate_limit(tier):
117117
# AUTH
118118
# =============================================================================
119119

120+
ADMIN_API_KEY = os.getenv("ADMIN_API_KEY", "")
121+
120122
def login_required(f):
121123
"""Decorator to require login for admin routes.
122-
Accepts session auth OR X-Admin-Key header matching ADMIN_PASSWORD.
124+
Accepts session auth OR X-Admin-Key header matching ADMIN_PASSWORD or ADMIN_API_KEY.
123125
"""
124126
@functools.wraps(f)
125127
def decorated_function(*args, **kwargs):
126128
# API key auth for programmatic access (e.g., RunPod training pipeline)
127-
if request.headers.get('X-Admin-Key') and ADMIN_PASSWORD:
128-
if request.headers.get('X-Admin-Key') == ADMIN_PASSWORD:
129+
api_key = request.headers.get('X-Admin-Key', '')
130+
if api_key:
131+
if (ADMIN_PASSWORD and api_key == ADMIN_PASSWORD) or (ADMIN_API_KEY and api_key == ADMIN_API_KEY):
129132
return f(*args, **kwargs)
133+
return jsonify({"error": "Unauthorized"}), 401
130134
if not session.get('admin_logged_in'):
131-
# Return JSON 401 for API requests, redirect for browser
132-
if request.headers.get('Accept', '').startswith('application/json') or request.headers.get('X-Admin-Key'):
135+
if request.headers.get('Accept', '').startswith('application/json'):
133136
return jsonify({"error": "Unauthorized"}), 401
134137
return redirect(url_for('admin.login'))
135138
return f(*args, **kwargs)

0 commit comments

Comments
 (0)