""" API Dependencies — Shared dependency injection for all routes. """ import secrets from fastapi import Header, HTTPException, Request from config import get_settings from core.gateway import AIPSTNGateway def get_gateway(request: Request) -> AIPSTNGateway: """Get the gateway instance from app state.""" gateway = getattr(request.app.state, "gateway", None) if gateway is None: raise HTTPException(status_code=503, detail="Gateway not initialized") return gateway def get_routing_service(request: Request): """Get the routing service from app state.""" routing = getattr(request.app.state, "routing_service", None) if routing is None: raise HTTPException(status_code=503, detail="Routing service not ready") return routing def require_token(authorization: str | None = Header(default=None)) -> None: """ Enforce the static bearer token (API_TOKEN) on REST routes. An empty configured token disables auth; startup refuses that combination unless the server is bound to loopback. """ token = get_settings().api_token.get_secret_value() if not token: return supplied = "" if authorization and authorization.lower().startswith("bearer "): supplied = authorization[7:] if not secrets.compare_digest(supplied, token): raise HTTPException( status_code=401, detail="Missing or invalid bearer token", headers={"WWW-Authenticate": "Bearer"}, )