Files
microsoft-365-service/app/credentials.py
T
JiriUhlirandClaude Fable 5.1 d80193da8b Hlavicky X-MS365-* jako obycejne hodnoty, GET /users/{user_id}/calendar
- credentials: sifrovani AES-GCM/HKDF odstraneno, tri hlavicky se berou
  tak, jak jsou; bez hlavicek se pouziji hodnoty z prostredi
- zrusena promenna MS365_CREDENTIAL_ENCODING_SECRET a zavislost cryptography
- novy endpoint GET /users/{user_id}/calendar (objekt kalendare schranky,
  id a name) pro read-only overeni pristupu pres e-mail schranky
- C# ukazka posila hodnoty primo, CredentialEncoder smazan
- README: sekce o hlavickach vcetne PowerShell ukazky, zaznam zmen
- .gitignore: bin/ a obj/, zaverzovane obj/ soubory ukazky odstraneny z gitu

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 12:49:25 +02:00

53 lines
1.7 KiB
Python

from typing import Annotated
from fastapi import Header, HTTPException, status
from .config import Settings, settings
async def get_request_settings(
tenant_id: Annotated[
str | None,
Header(
alias="X-MS365-Tenant-Id",
description="Microsoft Entra tenant id of the client (Directory / tenant ID).",
),
] = None,
client_id: Annotated[
str | None,
Header(
alias="X-MS365-Client-Id",
description="Application (client) ID of the CSBOT Entra app registration.",
),
] = None,
client_secret: Annotated[
str | None,
Header(
alias="X-MS365-Client-Secret",
description="Client secret VALUE of the CSBOT Entra app registration (not the secret id).",
),
] = None,
) -> Settings:
"""Per-request credentials. All three headers together, or none (then env values are used)."""
header_values = {
"X-MS365-Tenant-Id": tenant_id,
"X-MS365-Client-Id": client_id,
"X-MS365-Client-Secret": client_secret,
}
provided = {name: value for name, value in header_values.items() if value}
if not provided:
return settings
missing = [name for name, value in header_values.items() if not value]
if missing:
raise HTTPException(
status_code=status.HTTP_400_BAD_REQUEST,
detail={"message": "Incomplete Microsoft 365 credential headers.", "missing_headers": missing},
)
return settings.with_credentials(
tenant_id=provided["X-MS365-Tenant-Id"],
client_id=provided["X-MS365-Client-Id"],
client_secret=provided["X-MS365-Client-Secret"],
)