- auth.py/auth_routes.py: Login Flow v2 (verified against real NC source/docs) - no OAuth2 client registration needed, backend polls server-side so no CORS issues. Sessions are hashed-token cookies; NC app passwords encrypted at rest (Fernet). Every /api/* route guarded by a blueprint-wide before_request, not per-route decorators, so future routes are protected by default. - receipts/groups scoped per owner_nc_user_id; cross-user access 404s. - nc_client/cospend_client take (username, app_password) per call instead of one shared global credential - each user's uploads/shares/ bills now happen as themselves. - Frontend: LoginGate component drives the login flow (open NC login in a new tab, poll our backend, done). - Merged the old separate review step into the split screen, redesigned with Tailwind (was unstyled/broken), default-excluded-per-item splitting with one-click "include everyone" fixed, DD.MM.YYYY date field, receipt-icon branding. - Dropped LLM bounding-box highlighting - unreliable on real receipts, plain photo upload instead. - Only mention who a bill is split with in its title when there's more than one bill off the same receipt to disambiguate.
37 lines
1.1 KiB
Python
37 lines
1.1 KiB
Python
import os
|
|
|
|
from flask import Flask
|
|
from flask_cors import CORS
|
|
|
|
from .config import Config
|
|
from .db import init_db
|
|
|
|
|
|
def create_app() -> Flask:
|
|
app = Flask(__name__, instance_relative_config=True)
|
|
app.config.from_object(Config)
|
|
|
|
os.makedirs(app.instance_path, exist_ok=True)
|
|
os.makedirs(Config.UPLOAD_DIR, exist_ok=True)
|
|
|
|
# Frontend runs on a different origin (vite dev server) during
|
|
# development; lock this down to that origin in production. Auth now
|
|
# relies on a session cookie, so credentials must be allowed - and with
|
|
# supports_credentials, the origin allowlist can't be "*", it has to be
|
|
# this one explicit origin (flask-cors enforces that).
|
|
CORS(
|
|
app,
|
|
resources={r"/api/*": {"origins": Config.CORS_ORIGIN}, r"/auth/*": {"origins": Config.CORS_ORIGIN}},
|
|
supports_credentials=True,
|
|
)
|
|
|
|
init_db(Config.DATABASE_PATH)
|
|
|
|
from .auth_routes import bp as auth_bp
|
|
from .routes import bp as api_bp
|
|
|
|
app.register_blueprint(api_bp, url_prefix="/api")
|
|
app.register_blueprint(auth_bp, url_prefix="/auth")
|
|
|
|
return app
|