catalog.py 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596
  1. from fastapi import APIRouter, Depends, HTTPException
  2. from typing import List
  3. import db
  4. import schemas
  5. import auth_utils
  6. router = APIRouter(tags=["catalog"])
  7. @router.get("/materials", response_model=List[schemas.MaterialBase])
  8. async def get_materials():
  9. return db.execute_query("SELECT * FROM materials WHERE is_active = TRUE")
  10. @router.get("/services", response_model=List[schemas.ServiceBase])
  11. async def get_services():
  12. return db.execute_query("SELECT id, name_key, description_key, tech_type, is_active FROM services WHERE is_active = TRUE")
  13. @router.get("/admin/materials")
  14. async def admin_get_materials(token: str = Depends(auth_utils.oauth2_scheme)):
  15. payload = auth_utils.decode_token(token)
  16. if not payload or payload.get("role") != 'admin':
  17. raise HTTPException(status_code=403, detail="Admin role required")
  18. return db.execute_query("SELECT * FROM materials ORDER BY id DESC")
  19. @router.post("/admin/materials")
  20. async def admin_create_material(data: schemas.MaterialCreate, token: str = Depends(auth_utils.oauth2_scheme)):
  21. payload = auth_utils.decode_token(token)
  22. if not payload or payload.get("role") != 'admin':
  23. raise HTTPException(status_code=403, detail="Admin role required")
  24. query = "INSERT INTO materials (name_en, name_ru, name_me, desc_en, desc_ru, desc_me, price_per_cm3, is_active) VALUES (%s, %s, %s, %s, %s, %s, %s, %s)"
  25. params = (data.name_en, data.name_ru, data.name_me, data.desc_en, data.desc_ru, data.desc_me, data.price_per_cm3, data.is_active)
  26. mat_id = db.execute_commit(query, params)
  27. return {"id": mat_id}
  28. @router.patch("/admin/materials/{mat_id}")
  29. async def admin_update_material(mat_id: int, data: schemas.MaterialUpdate, token: str = Depends(auth_utils.oauth2_scheme)):
  30. payload = auth_utils.decode_token(token)
  31. if not payload or payload.get("role") != 'admin':
  32. raise HTTPException(status_code=403, detail="Admin role required")
  33. update_fields = []
  34. params = []
  35. for field, value in data.dict(exclude_unset=True).items():
  36. update_fields.append(f"{field} = %s")
  37. params.append(value)
  38. if update_fields:
  39. query = f"UPDATE materials SET {', '.join(update_fields)} WHERE id = %s"
  40. params.append(mat_id)
  41. db.execute_commit(query, tuple(params))
  42. return {"id": mat_id}
  43. @router.delete("/admin/materials/{mat_id}")
  44. async def admin_delete_material(mat_id: int, token: str = Depends(auth_utils.oauth2_scheme)):
  45. payload = auth_utils.decode_token(token)
  46. if not payload or payload.get("role") != 'admin':
  47. raise HTTPException(status_code=403, detail="Admin role required")
  48. db.execute_commit("DELETE FROM materials WHERE id = %s", (mat_id,))
  49. return {"id": mat_id, "status": "deleted"}
  50. @router.get("/admin/services")
  51. async def admin_get_services(token: str = Depends(auth_utils.oauth2_scheme)):
  52. payload = auth_utils.decode_token(token)
  53. if not payload or payload.get("role") != 'admin':
  54. raise HTTPException(status_code=403, detail="Admin role required")
  55. return db.execute_query("SELECT * FROM services ORDER BY id DESC")
  56. @router.post("/admin/services")
  57. async def admin_create_service(data: schemas.ServiceCreate, token: str = Depends(auth_utils.oauth2_scheme)):
  58. payload = auth_utils.decode_token(token)
  59. if not payload or payload.get("role") != 'admin':
  60. raise HTTPException(status_code=403, detail="Admin role required")
  61. query = "INSERT INTO services (name_key, description_key, tech_type, is_active) VALUES (%s, %s, %s, %s)"
  62. srv_id = db.execute_commit(query, (data.name_key, data.description_key, data.tech_type, data.is_active))
  63. return {"id": srv_id}
  64. @router.patch("/admin/services/{srv_id}")
  65. async def admin_update_service(srv_id: int, data: schemas.ServiceUpdate, token: str = Depends(auth_utils.oauth2_scheme)):
  66. payload = auth_utils.decode_token(token)
  67. if not payload or payload.get("role") != 'admin':
  68. raise HTTPException(status_code=403, detail="Admin role required")
  69. update_fields = []
  70. params = []
  71. for field, value in data.dict(exclude_unset=True).items():
  72. update_fields.append(f"{field} = %s")
  73. params.append(value)
  74. if update_fields:
  75. query = f"UPDATE services SET {', '.join(update_fields)} WHERE id = %s"
  76. params.append(srv_id)
  77. db.execute_commit(query, tuple(params))
  78. return {"id": srv_id}
  79. @router.delete("/admin/services/{srv_id}")
  80. async def admin_delete_service(srv_id: int, token: str = Depends(auth_utils.oauth2_scheme)):
  81. payload = auth_utils.decode_token(token)
  82. if not payload or payload.get("role") != 'admin':
  83. raise HTTPException(status_code=403, detail="Admin role required")
  84. db.execute_commit("DELETE FROM services WHERE id = %s", (srv_id,))
  85. return {"id": srv_id, "status": "deleted"}