This commit is contained in:
Timothy Jaeryang Baek
2026-02-10 15:41:11 -06:00
parent a73cdf4288
commit e3a8257690
6 changed files with 181 additions and 0 deletions
+46
View File
@@ -481,6 +481,52 @@ async def update_model_by_id(
return model
############################
# UpdateModelAccessById
############################
class ModelAccessGrantsForm(BaseModel):
id: str
access_grants: list[dict]
@router.post("/model/access/update", response_model=Optional[ModelModel])
async def update_model_access_by_id(
form_data: ModelAccessGrantsForm,
user=Depends(get_verified_user),
db: Session = Depends(get_session),
):
model = Models.get_model_by_id(form_data.id, db=db)
if not model:
raise HTTPException(
status_code=status.HTTP_404_NOT_FOUND,
detail=ERROR_MESSAGES.NOT_FOUND,
)
if (
model.user_id != user.id
and not AccessGrants.has_access(
user_id=user.id,
resource_type="model",
resource_id=model.id,
permission="write",
db=db,
)
and user.role != "admin"
):
raise HTTPException(
status_code=status.HTTP_400_BAD_REQUEST,
detail=ERROR_MESSAGES.ACCESS_PROHIBITED,
)
AccessGrants.set_access_grants(
"model", form_data.id, form_data.access_grants, db=db
)
return Models.get_model_by_id(form_data.id, db=db)
############################
# DeleteModelById
############################
+46
View File
@@ -510,6 +510,52 @@ async def update_tools_by_id(
)
############################
# UpdateToolAccessById
############################
class ToolAccessGrantsForm(BaseModel):
access_grants: list[dict]
@router.post("/id/{id}/access/update", response_model=Optional[ToolModel])
async def update_tool_access_by_id(
id: str,
form_data: ToolAccessGrantsForm,
user=Depends(get_verified_user),
db: Session = Depends(get_session),
):
tools = Tools.get_tool_by_id(id, db=db)
if not tools:
raise HTTPException(
status_code=status.HTTP_404_NOT_FOUND,
detail=ERROR_MESSAGES.NOT_FOUND,
)
if (
tools.user_id != user.id
and not AccessGrants.has_access(
user_id=user.id,
resource_type="tool",
resource_id=tools.id,
permission="write",
db=db,
)
and user.role != "admin"
):
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=ERROR_MESSAGES.UNAUTHORIZED,
)
AccessGrants.set_access_grants(
"tool", id, form_data.access_grants, db=db
)
return Tools.get_tool_by_id(id, db=db)
############################
# DeleteToolsById
############################