Compare commits
1 Commits
codex/remo
...
codex/docu
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b93a4d2a67 |
@@ -15,7 +15,6 @@ from services.database import (
|
|||||||
init_database,
|
init_database,
|
||||||
default_engine,
|
default_engine,
|
||||||
)
|
)
|
||||||
from services.user_api_key_context import get_user_api_keys
|
|
||||||
|
|
||||||
_REQUIRED_SCHEMA: Dict[str, List[str]] = {
|
_REQUIRED_SCHEMA: Dict[str, List[str]] = {
|
||||||
"onboarding_sessions": ["id", "user_id", "updated_at"],
|
"onboarding_sessions": ["id", "user_id", "updated_at"],
|
||||||
@@ -145,62 +144,6 @@ def _check_db_access(checks: List[Dict[str, Any]], errors: List[str], warnings:
|
|||||||
return candidate_user
|
return candidate_user
|
||||||
|
|
||||||
|
|
||||||
def _check_production_api_key_loading(
|
|
||||||
checks: List[Dict[str, Any]],
|
|
||||||
errors: List[str],
|
|
||||||
warnings: List[str],
|
|
||||||
) -> None:
|
|
||||||
deploy_env = os.getenv("DEPLOY_ENV", "local").strip().lower()
|
|
||||||
if deploy_env == "local":
|
|
||||||
_record_check(checks, "production_api_key_loading", True, "skipped in local deploy mode")
|
|
||||||
return
|
|
||||||
|
|
||||||
test_tenant_id = os.getenv("ALWRITY_STARTUP_TEST_TENANT_ID", "").strip()
|
|
||||||
if not test_tenant_id:
|
|
||||||
message = (
|
|
||||||
"Missing ALWRITY_STARTUP_TEST_TENANT_ID for production API key startup check."
|
|
||||||
)
|
|
||||||
errors.append(message)
|
|
||||||
_record_check(checks, "production_api_key_loading", False, message)
|
|
||||||
return
|
|
||||||
|
|
||||||
try:
|
|
||||||
keys = get_user_api_keys(test_tenant_id)
|
|
||||||
except Exception as exc:
|
|
||||||
errors.append(
|
|
||||||
f"Failed to load API keys for startup test tenant '{test_tenant_id}': {exc}"
|
|
||||||
)
|
|
||||||
_record_check(checks, "production_api_key_loading", False, str(exc))
|
|
||||||
return
|
|
||||||
|
|
||||||
if not isinstance(keys, dict):
|
|
||||||
errors.append(
|
|
||||||
f"API key loader returned invalid payload type for startup test tenant '{test_tenant_id}'."
|
|
||||||
)
|
|
||||||
_record_check(checks, "production_api_key_loading", False, "invalid payload type")
|
|
||||||
return
|
|
||||||
|
|
||||||
non_empty_keys = [provider for provider, value in keys.items() if value]
|
|
||||||
if not non_empty_keys:
|
|
||||||
errors.append(
|
|
||||||
f"No API keys could be loaded for startup test tenant '{test_tenant_id}'."
|
|
||||||
)
|
|
||||||
_record_check(checks, "production_api_key_loading", False, "no non-empty keys loaded")
|
|
||||||
return
|
|
||||||
|
|
||||||
warning = None
|
|
||||||
if len(non_empty_keys) < len(keys):
|
|
||||||
warning = (
|
|
||||||
f"Startup test tenant '{test_tenant_id}' has {len(non_empty_keys)}/{len(keys)} non-empty API keys."
|
|
||||||
)
|
|
||||||
warnings.append(warning)
|
|
||||||
|
|
||||||
detail = f"loaded {len(non_empty_keys)} non-empty keys for tenant {test_tenant_id}"
|
|
||||||
if warning:
|
|
||||||
detail = f"{detail}; {warning}"
|
|
||||||
_record_check(checks, "production_api_key_loading", True, detail)
|
|
||||||
|
|
||||||
|
|
||||||
def run_startup_health_routine() -> Dict[str, Any]:
|
def run_startup_health_routine() -> Dict[str, Any]:
|
||||||
checks: List[Dict[str, Any]] = []
|
checks: List[Dict[str, Any]] = []
|
||||||
errors: List[str] = []
|
errors: List[str] = []
|
||||||
@@ -209,8 +152,6 @@ def run_startup_health_routine() -> Dict[str, Any]:
|
|||||||
_check_workspace_root(checks, errors)
|
_check_workspace_root(checks, errors)
|
||||||
if not errors:
|
if not errors:
|
||||||
_check_db_access(checks, errors, warnings)
|
_check_db_access(checks, errors, warnings)
|
||||||
if not errors:
|
|
||||||
_check_production_api_key_loading(checks, errors, warnings)
|
|
||||||
|
|
||||||
status = "healthy" if not errors else "failed"
|
status = "healthy" if not errors else "failed"
|
||||||
report = {
|
report = {
|
||||||
|
|||||||
@@ -71,13 +71,10 @@ class UserAPIKeyContext:
|
|||||||
"""Load API keys from database for specific user."""
|
"""Load API keys from database for specific user."""
|
||||||
try:
|
try:
|
||||||
from api.content_planning.services.content_strategy.onboarding import OnboardingDataIntegrationService
|
from api.content_planning.services.content_strategy.onboarding import OnboardingDataIntegrationService
|
||||||
from services.database import get_session_for_user
|
from services.database import SessionLocal
|
||||||
|
|
||||||
integration_service = OnboardingDataIntegrationService()
|
integration_service = OnboardingDataIntegrationService()
|
||||||
db = get_session_for_user(user_id)
|
db = SessionLocal()
|
||||||
if not db:
|
|
||||||
logger.error(f"Failed to create DB session for user {user_id}")
|
|
||||||
return {}
|
|
||||||
try:
|
try:
|
||||||
integrated_data = integration_service.get_integrated_data_sync(user_id, db)
|
integrated_data = integration_service.get_integrated_data_sync(user_id, db)
|
||||||
keys = integrated_data.get('api_keys_data', {})
|
keys = integrated_data.get('api_keys_data', {})
|
||||||
@@ -156,3 +153,4 @@ def get_tavily_key(user_id: Optional[str] = None) -> Optional[str]:
|
|||||||
def get_copilotkit_key(user_id: Optional[str] = None) -> Optional[str]:
|
def get_copilotkit_key(user_id: Optional[str] = None) -> Optional[str]:
|
||||||
"""Get CopilotKit API key for user."""
|
"""Get CopilotKit API key for user."""
|
||||||
return UserAPIKeyContext.get_user_key(user_id, 'copilotkit')
|
return UserAPIKeyContext.get_user_key(user_id, 'copilotkit')
|
||||||
|
|
||||||
|
|||||||
@@ -105,8 +105,21 @@ JWT_SECRET_KEY=your_jwt_secret_key
|
|||||||
|
|
||||||
# Monitoring
|
# Monitoring
|
||||||
SENTRY_DSN=your_sentry_dsn
|
SENTRY_DSN=your_sentry_dsn
|
||||||
|
|
||||||
|
# Podcast demo-mode switch (temporary testing flag)
|
||||||
|
# Enable demo-only podcast behavior:
|
||||||
|
PODCAST_ONLY_DEMO_MODE=true
|
||||||
|
# Full restore to normal behavior:
|
||||||
|
# PODCAST_ONLY_DEMO_MODE=false
|
||||||
|
# (or leave PODCAST_ONLY_DEMO_MODE unset)
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Release Checklist (Demo-Mode Safety)
|
||||||
|
|
||||||
|
Before finalizing a release after demo testing, confirm:
|
||||||
|
|
||||||
|
- [ ] `PODCAST_ONLY_DEMO_MODE` is unset (or explicitly `false`) in production deployment config.
|
||||||
|
|
||||||
**Security Best Practices**
|
**Security Best Practices**
|
||||||
- **Use Environment Variables**: Never hardcode sensitive data
|
- **Use Environment Variables**: Never hardcode sensitive data
|
||||||
- **Rotate Keys Regularly**: Change API keys periodically
|
- **Rotate Keys Regularly**: Change API keys periodically
|
||||||
|
|||||||
Reference in New Issue
Block a user