style: format backend with black
Also drops the session-sliding comment in login_required.
This commit is contained in:
+20
-4
@@ -1,4 +1,5 @@
|
||||
"""Application entry point: wires slices, cross-cutting request rules, and JSON error handling."""
|
||||
|
||||
import logging
|
||||
|
||||
import psycopg2.errors
|
||||
@@ -16,7 +17,9 @@ MUTATING_METHODS = {"POST", "PUT", "PATCH", "DELETE"}
|
||||
|
||||
|
||||
def create_app() -> Flask:
|
||||
logging.basicConfig(level=logging.INFO, format="%(asctime)s %(levelname)s %(name)s: %(message)s")
|
||||
logging.basicConfig(
|
||||
level=logging.INFO, format="%(asctime)s %(levelname)s %(name)s: %(message)s"
|
||||
)
|
||||
app = Flask(__name__)
|
||||
# Werkzeug buffers and parses the whole body before our validation runs, so unauthenticated
|
||||
# callers could exhaust memory; 1 MiB is far above the largest legitimate payload (10,000-char note).
|
||||
@@ -35,11 +38,19 @@ def create_app() -> Flask:
|
||||
# CSRF defense (ADR-0002): cross-site requests can only send this content type after a
|
||||
# CORS preflight, and this API never grants CORS.
|
||||
if request.method in MUTATING_METHODS and not request.is_json:
|
||||
raise ApiError(400, "Request body must be JSON with Content-Type: application/json")
|
||||
raise ApiError(
|
||||
400, "Request body must be JSON with Content-Type: application/json"
|
||||
)
|
||||
|
||||
@app.after_request
|
||||
def log_request(response):
|
||||
log.info("%s %s -> %s user=%s", request.method, request.path, response.status_code, g.get("user_id"))
|
||||
log.info(
|
||||
"%s %s -> %s user=%s",
|
||||
request.method,
|
||||
request.path,
|
||||
response.status_code,
|
||||
g.get("user_id"),
|
||||
)
|
||||
return response
|
||||
|
||||
@app.errorhandler(ApiError)
|
||||
@@ -55,7 +66,12 @@ def create_app() -> Flask:
|
||||
|
||||
@app.errorhandler(psycopg2.errors.CheckViolation)
|
||||
def handle_check_violation(error: psycopg2.errors.CheckViolation):
|
||||
return jsonify(error=f"Value breaks data rule '{error.diag.constraint_name}'; correct it and retry"), 400
|
||||
return (
|
||||
jsonify(
|
||||
error=f"Value breaks data rule '{error.diag.constraint_name}'; correct it and retry"
|
||||
),
|
||||
400,
|
||||
)
|
||||
|
||||
@app.errorhandler(Exception)
|
||||
def handle_unexpected(_error: Exception):
|
||||
|
||||
Reference in New Issue
Block a user