2026-05-21 20:33:31 +02:00
|
|
|
"""`@require_perm` Flask decorator (group-based RBAC)."""
|
|
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
|
|
|
|
from collections.abc import Callable
|
|
|
|
|
from functools import wraps
|
chore(backend): mypy strict clean + ruff format pass
Pre-merge sanity per devops checklist (ruff format --check, mypy --strict).
Type fixes:
- ORM models: `Mapped[dict]` → `Mapped[dict[str, Any]]` (audit, scenario, run,
report, ttp, detection.artifact_files_json). Equivalent on Pydantic DTOs
(TtpBase.params_schema_json, ScenarioStepBase.params_override_json).
- Rename `TtpRead.current_version` → `TtpRead.version` to mirror the ORM
column (which itself was renamed in D-009 cleanup).
- Flask blueprints: add `-> ResponseReturnValue` to every view, plus typed
UUID params on `_validate_step_consistency`.
- `templating/filters.py`: rewrite the conditional re2 import so mypy can
narrow the union (`ModuleType | None`); the runtime branch on `_re2 is not
None` removes the unused-ignore that was triggered by warn_unused_ignores.
- `pyproject.toml`: add `flask_login.*` and `pythonjsonlogger.*` to the
`[[tool.mypy.overrides]]` `ignore_missing_imports` list (both ship without
typed marker).
- Misc: drop stale `# type: ignore` comments (`app.py:36`,
`rbac/decorators.py:35`) flagged by `warn_unused_ignores`. Keep
`logging.JsonFormatter` ignore because the symbol exists at runtime but is
not re-exported through the typed surface.
Formatting:
- `ruff format` applied (15 files normalized; line-length unchanged at 100).
Verification on this commit:
- `ruff check` → All checks passed.
- `ruff format --check` → 68 files already formatted.
- `mypy --strict src` → Success: no issues found in 54 source files.
- `pytest tests/unit` → 49 passed.
2026-05-22 05:10:51 +02:00
|
|
|
from typing import ParamSpec, TypeVar
|
2026-05-21 20:33:31 +02:00
|
|
|
|
|
|
|
|
from flask import abort
|
|
|
|
|
from flask_login import current_user
|
|
|
|
|
|
|
|
|
|
from mimic.rbac.matrix import Permission
|
|
|
|
|
|
|
|
|
|
P = ParamSpec("P")
|
|
|
|
|
R = TypeVar("R")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def require_perm(perm: Permission) -> Callable[[Callable[P, R]], Callable[P, R]]:
|
|
|
|
|
"""Reject the request with 401/403 unless the user holds `perm`."""
|
|
|
|
|
|
|
|
|
|
def _decorate(view: Callable[P, R]) -> Callable[P, R]:
|
|
|
|
|
@wraps(view)
|
|
|
|
|
def _wrapped(*args: P.args, **kwargs: P.kwargs) -> R:
|
|
|
|
|
user = current_user
|
|
|
|
|
if not getattr(user, "is_authenticated", False):
|
|
|
|
|
abort(401)
|
|
|
|
|
permissions: frozenset[Permission] = getattr(user, "permissions", frozenset())
|
|
|
|
|
if perm not in permissions:
|
|
|
|
|
abort(403)
|
|
|
|
|
return view(*args, **kwargs)
|
|
|
|
|
|
chore(backend): mypy strict clean + ruff format pass
Pre-merge sanity per devops checklist (ruff format --check, mypy --strict).
Type fixes:
- ORM models: `Mapped[dict]` → `Mapped[dict[str, Any]]` (audit, scenario, run,
report, ttp, detection.artifact_files_json). Equivalent on Pydantic DTOs
(TtpBase.params_schema_json, ScenarioStepBase.params_override_json).
- Rename `TtpRead.current_version` → `TtpRead.version` to mirror the ORM
column (which itself was renamed in D-009 cleanup).
- Flask blueprints: add `-> ResponseReturnValue` to every view, plus typed
UUID params on `_validate_step_consistency`.
- `templating/filters.py`: rewrite the conditional re2 import so mypy can
narrow the union (`ModuleType | None`); the runtime branch on `_re2 is not
None` removes the unused-ignore that was triggered by warn_unused_ignores.
- `pyproject.toml`: add `flask_login.*` and `pythonjsonlogger.*` to the
`[[tool.mypy.overrides]]` `ignore_missing_imports` list (both ship without
typed marker).
- Misc: drop stale `# type: ignore` comments (`app.py:36`,
`rbac/decorators.py:35`) flagged by `warn_unused_ignores`. Keep
`logging.JsonFormatter` ignore because the symbol exists at runtime but is
not re-exported through the typed surface.
Formatting:
- `ruff format` applied (15 files normalized; line-length unchanged at 100).
Verification on this commit:
- `ruff check` → All checks passed.
- `ruff format --check` → 68 files already formatted.
- `mypy --strict src` → Success: no issues found in 54 source files.
- `pytest tests/unit` → 49 passed.
2026-05-22 05:10:51 +02:00
|
|
|
return _wrapped
|
2026-05-21 20:33:31 +02:00
|
|
|
|
|
|
|
|
return _decorate
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def user_has(perm: Permission, permissions: frozenset[Permission]) -> bool:
|
|
|
|
|
"""Pure helper, easier to unit-test than the decorator."""
|
|
|
|
|
return perm in permissions
|