from fastapi import APIRouter, Depends, HTTPException from sqlalchemy.orm import Session from app import models, schemas from app.auth import get_current_user from app.database import get_db router = APIRouter() def _owner_config(config_id: int, db: Session, user: models.User) -> models.Config: config = db.query(models.Config).filter( models.Config.id == config_id, models.Config.owner_id == user.id ).first() if not config: raise HTTPException(status_code=404, detail="Config not found") return config @router.get("/{config_id}/policies", response_model=list[schemas.PolicyOut]) def list_policies(config_id: int, db: Session = Depends(get_db), user: models.User = Depends(get_current_user)): _owner_config(config_id, db, user) return db.query(models.Policy).filter(models.Policy.config_id == config_id).order_by(models.Policy.position).all() @router.post("/{config_id}/policies", response_model=schemas.PolicyOut, status_code=201) def create_policy(config_id: int, body: schemas.PolicyCreate, db: Session = Depends(get_db), user: models.User = Depends(get_current_user)): _owner_config(config_id, db, user) policy = models.Policy(**body.model_dump(), config_id=config_id) db.add(policy) db.commit() db.refresh(policy) return policy @router.get("/{config_id}/policies/{policy_id}", response_model=schemas.PolicyOut) def get_policy(config_id: int, policy_id: int, db: Session = Depends(get_db), user: models.User = Depends(get_current_user)): _owner_config(config_id, db, user) policy = db.query(models.Policy).filter(models.Policy.id == policy_id, models.Policy.config_id == config_id).first() if not policy: raise HTTPException(status_code=404, detail="Policy not found") return policy @router.put("/{config_id}/policies/{policy_id}", response_model=schemas.PolicyOut) def update_policy(config_id: int, policy_id: int, body: schemas.PolicyUpdate, db: Session = Depends(get_db), user: models.User = Depends(get_current_user)): _owner_config(config_id, db, user) policy = db.query(models.Policy).filter(models.Policy.id == policy_id, models.Policy.config_id == config_id).first() if not policy: raise HTTPException(status_code=404, detail="Policy not found") for field, value in body.model_dump(exclude_none=True).items(): setattr(policy, field, value) db.commit() db.refresh(policy) return policy @router.delete("/{config_id}/policies/{policy_id}", status_code=204) def delete_policy(config_id: int, policy_id: int, db: Session = Depends(get_db), user: models.User = Depends(get_current_user)): _owner_config(config_id, db, user) policy = db.query(models.Policy).filter(models.Policy.id == policy_id, models.Policy.config_id == config_id).first() if not policy: raise HTTPException(status_code=404, detail="Policy not found") db.delete(policy) db.commit()