2025-01-26 18:01:04 +03:00
|
|
|
|
from asyncio.log import logger
|
2025-07-02 22:30:21 +03:00
|
|
|
|
from enum import Enum
|
2025-01-26 18:01:04 +03:00
|
|
|
|
|
2025-07-02 22:30:21 +03:00
|
|
|
|
from ariadne import (
|
|
|
|
|
MutationType,
|
|
|
|
|
ObjectType,
|
|
|
|
|
QueryType,
|
|
|
|
|
SchemaBindable,
|
2025-07-25 09:27:55 +03:00
|
|
|
|
graphql,
|
2025-07-02 22:30:21 +03:00
|
|
|
|
load_schema_from_path,
|
2025-07-25 09:27:55 +03:00
|
|
|
|
make_executable_schema,
|
2025-07-02 22:30:21 +03:00
|
|
|
|
)
|
2025-07-25 09:27:55 +03:00
|
|
|
|
from starlette.requests import Request
|
|
|
|
|
from starlette.responses import JSONResponse, Response
|
2021-06-28 12:08:09 +03:00
|
|
|
|
|
2025-07-25 09:27:55 +03:00
|
|
|
|
from auth.middleware import CSRF_HEADER_NAME, CSRF_TOKEN_KEY
|
2025-02-10 18:04:08 +03:00
|
|
|
|
from services.db import create_table_if_not_exists, local_session
|
2025-01-26 18:01:04 +03:00
|
|
|
|
|
2025-07-02 22:30:21 +03:00
|
|
|
|
# Создаем основные типы
|
2023-10-06 12:51:07 +03:00
|
|
|
|
query = QueryType()
|
|
|
|
|
mutation = MutationType()
|
2025-04-26 11:45:16 +03:00
|
|
|
|
type_draft = ObjectType("Draft")
|
2025-06-30 21:25:26 +03:00
|
|
|
|
type_community = ObjectType("Community")
|
2025-06-30 21:46:53 +03:00
|
|
|
|
type_collection = ObjectType("Collection")
|
2025-07-02 22:30:21 +03:00
|
|
|
|
type_author = ObjectType("Author")
|
|
|
|
|
|
|
|
|
|
# Загружаем определения типов из файлов схемы
|
|
|
|
|
type_defs = load_schema_from_path("schema/")
|
|
|
|
|
|
|
|
|
|
# Список всех типов для схемы
|
|
|
|
|
resolvers: SchemaBindable | type[Enum] | list[SchemaBindable | type[Enum]] = [
|
|
|
|
|
query,
|
|
|
|
|
mutation,
|
|
|
|
|
type_draft,
|
|
|
|
|
type_community,
|
|
|
|
|
type_collection,
|
|
|
|
|
type_author,
|
|
|
|
|
]
|
2025-01-26 18:01:04 +03:00
|
|
|
|
|
|
|
|
|
|
2025-06-02 02:56:11 +03:00
|
|
|
|
def create_all_tables() -> None:
|
2025-02-10 18:04:08 +03:00
|
|
|
|
"""Create all database tables in the correct order."""
|
2025-05-29 12:37:39 +03:00
|
|
|
|
from auth.orm import Author, AuthorBookmark, AuthorFollower, AuthorRating
|
2025-07-01 00:01:20 +03:00
|
|
|
|
from orm import collection, community, draft, invite, notification, reaction, shout, topic
|
2025-02-10 18:04:08 +03:00
|
|
|
|
|
|
|
|
|
# Порядок важен - сначала таблицы без внешних ключей, затем зависимые таблицы
|
|
|
|
|
models_in_order = [
|
2025-02-11 12:24:02 +03:00
|
|
|
|
# user.User, # Базовая таблица auth
|
2025-05-16 09:23:48 +03:00
|
|
|
|
Author, # Базовая таблица
|
2025-02-10 18:04:08 +03:00
|
|
|
|
community.Community, # Базовая таблица
|
|
|
|
|
topic.Topic, # Базовая таблица
|
|
|
|
|
# Связи для базовых таблиц
|
2025-05-16 09:23:48 +03:00
|
|
|
|
AuthorFollower, # Зависит от Author
|
2025-02-10 18:04:08 +03:00
|
|
|
|
community.CommunityFollower, # Зависит от Community
|
|
|
|
|
topic.TopicFollower, # Зависит от Topic
|
|
|
|
|
# Черновики (теперь без зависимости от Shout)
|
|
|
|
|
draft.Draft, # Зависит только от Author
|
|
|
|
|
draft.DraftAuthor, # Зависит от Draft и Author
|
|
|
|
|
draft.DraftTopic, # Зависит от Draft и Topic
|
|
|
|
|
# Основные таблицы контента
|
|
|
|
|
shout.Shout, # Зависит от Author и Draft
|
|
|
|
|
shout.ShoutAuthor, # Зависит от Shout и Author
|
|
|
|
|
shout.ShoutTopic, # Зависит от Shout и Topic
|
|
|
|
|
# Реакции
|
|
|
|
|
reaction.Reaction, # Зависит от Author и Shout
|
|
|
|
|
shout.ShoutReactionsFollower, # Зависит от Shout и Reaction
|
|
|
|
|
# Дополнительные таблицы
|
2025-05-16 09:23:48 +03:00
|
|
|
|
AuthorRating, # Зависит от Author
|
|
|
|
|
AuthorBookmark, # Зависит от Author
|
2025-02-10 18:04:08 +03:00
|
|
|
|
notification.Notification, # Зависит от Author
|
|
|
|
|
notification.NotificationSeen, # Зависит от Notification
|
2025-06-30 21:46:53 +03:00
|
|
|
|
collection.Collection, # Зависит от Author
|
|
|
|
|
collection.ShoutCollection, # Зависит от Collection и Shout
|
2025-07-01 00:01:20 +03:00
|
|
|
|
invite.Invite, # Зависит от Author и Shout
|
2025-02-10 18:04:08 +03:00
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
with local_session() as session:
|
|
|
|
|
for model in models_in_order:
|
|
|
|
|
try:
|
|
|
|
|
create_table_if_not_exists(session.get_bind(), model)
|
2025-02-11 12:00:35 +03:00
|
|
|
|
# logger.info(f"Created or verified table: {model.__tablename__}")
|
2025-02-10 18:04:08 +03:00
|
|
|
|
except Exception as e:
|
2025-06-02 02:56:11 +03:00
|
|
|
|
table_name = getattr(model, "__tablename__", str(model))
|
|
|
|
|
logger.error(f"Error creating table {table_name}: {e}")
|
2025-02-11 12:00:35 +03:00
|
|
|
|
raise
|
2025-07-25 09:27:55 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
async def graphql_handler(request: Request) -> Response:
|
|
|
|
|
"""
|
|
|
|
|
Обработчик GraphQL запросов с проверкой CSRF токена
|
|
|
|
|
"""
|
|
|
|
|
try:
|
|
|
|
|
# Проверяем CSRF токен для всех мутаций
|
|
|
|
|
data = await request.json()
|
|
|
|
|
op_name = data.get("operationName", "").lower()
|
|
|
|
|
|
|
|
|
|
# Проверяем CSRF только для мутаций
|
|
|
|
|
if op_name and (op_name.endswith("mutation") or op_name in ["login", "refreshtoken"]):
|
|
|
|
|
# Получаем токен из заголовка
|
|
|
|
|
request_csrf_token = request.headers.get(CSRF_HEADER_NAME)
|
|
|
|
|
|
|
|
|
|
# Получаем токен из куки
|
|
|
|
|
cookie_csrf_token = request.cookies.get(CSRF_TOKEN_KEY)
|
|
|
|
|
|
|
|
|
|
# Строгая проверка токена
|
|
|
|
|
if not request_csrf_token or not cookie_csrf_token:
|
|
|
|
|
# Возвращаем ошибку как часть GraphQL-ответа
|
|
|
|
|
return JSONResponse(
|
|
|
|
|
{
|
|
|
|
|
"data": None,
|
|
|
|
|
"errors": [{"message": "CSRF токен отсутствует", "extensions": {"code": "CSRF_TOKEN_MISSING"}}],
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
if request_csrf_token != cookie_csrf_token:
|
|
|
|
|
# Возвращаем ошибку как часть GraphQL-ответа
|
|
|
|
|
return JSONResponse(
|
|
|
|
|
{
|
|
|
|
|
"data": None,
|
|
|
|
|
"errors": [
|
|
|
|
|
{"message": "Недопустимый CSRF токен", "extensions": {"code": "CSRF_TOKEN_INVALID"}}
|
|
|
|
|
],
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
# Существующая логика обработки GraphQL запроса
|
|
|
|
|
schema = get_schema()
|
|
|
|
|
result = await graphql(
|
|
|
|
|
schema,
|
|
|
|
|
data.get("query"),
|
|
|
|
|
variable_values=data.get("variables"),
|
|
|
|
|
operation_name=data.get("operationName"),
|
|
|
|
|
context_value={"request": request},
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
# Обработка ошибок GraphQL
|
|
|
|
|
if result.errors:
|
|
|
|
|
return JSONResponse(
|
|
|
|
|
{
|
|
|
|
|
"data": result.data,
|
|
|
|
|
"errors": [{"message": str(error), "locations": error.locations} for error in result.errors],
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
return JSONResponse({"data": result.data})
|
|
|
|
|
|
|
|
|
|
except Exception as e:
|
|
|
|
|
logger.error(f"GraphQL handler error: {e}")
|
|
|
|
|
return JSONResponse(
|
|
|
|
|
{
|
|
|
|
|
"data": None,
|
|
|
|
|
"errors": [{"message": "Внутренняя ошибка сервера", "extensions": {"code": "INTERNAL_SERVER_ERROR"}}],
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def get_schema():
|
|
|
|
|
"""
|
|
|
|
|
Создает и возвращает GraphQL схему
|
|
|
|
|
"""
|
|
|
|
|
return make_executable_schema(type_defs, resolvers)
|