Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.

This commit is contained in:
2025-12-02 18:34:59 +00:00
parent 15916047fa
commit eedbd4aaa4
6 changed files with 14 additions and 17 deletions
+7 -1
View File
@@ -10,7 +10,7 @@ from fastapi import (
Request,
Response,
)
from fastapi.responses import JSONResponse
from fastapi.responses import FileResponse, JSONResponse
from fastapi.security import HTTPBearer
from passkey.util import frontend
@@ -36,6 +36,12 @@ app = FastAPI()
app.mount("/user", user.app)
@app.get("/restricted")
async def restricted_view():
"""Serve the restricted/authentication UI for iframe embedding."""
return FileResponse(frontend.file("restricted-api", "index.html"))
@app.exception_handler(HTTPException)
async def http_exception_handler(_request: Request, exc: HTTPException):
"""Ensure auth cookie is cleared on 401 responses (JSON responses only)."""