github_backup.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371
  1. """API routes for GitHub profile backup."""
  2. import logging
  3. from fastapi import APIRouter, Depends, HTTPException, Query
  4. from sqlalchemy import delete, desc, select
  5. from sqlalchemy.ext.asyncio import AsyncSession
  6. from backend.app.core.auth import RequirePermissionIfAuthEnabled
  7. from backend.app.core.database import get_db
  8. from backend.app.core.permissions import Permission
  9. from backend.app.models.github_backup import GitHubBackupConfig, GitHubBackupLog
  10. from backend.app.models.user import User
  11. from backend.app.schemas.github_backup import (
  12. GitHubBackupConfigCreate,
  13. GitHubBackupConfigResponse,
  14. GitHubBackupConfigUpdate,
  15. GitHubBackupLogResponse,
  16. GitHubBackupStatus,
  17. GitHubBackupTriggerResponse,
  18. GitHubTestConnectionResponse,
  19. ProviderType,
  20. )
  21. from backend.app.services.github_backup import github_backup_service
  22. logger = logging.getLogger(__name__)
  23. router = APIRouter(prefix="/github-backup", tags=["github-backup"])
  24. def _config_to_response(config: GitHubBackupConfig) -> dict:
  25. """Convert config model to response dict."""
  26. return {
  27. "id": config.id,
  28. "repository_url": config.repository_url,
  29. "has_token": bool(config.access_token),
  30. "branch": config.branch,
  31. "provider": config.provider,
  32. "allow_insecure_http": config.allow_insecure_http,
  33. "schedule_enabled": config.schedule_enabled,
  34. "schedule_type": config.schedule_type,
  35. "backup_kprofiles": config.backup_kprofiles,
  36. "backup_cloud_profiles": config.backup_cloud_profiles,
  37. "backup_settings": config.backup_settings,
  38. "backup_spools": config.backup_spools,
  39. "backup_archives": config.backup_archives,
  40. "enabled": config.enabled,
  41. "last_backup_at": config.last_backup_at,
  42. "last_backup_status": config.last_backup_status,
  43. "last_backup_message": config.last_backup_message,
  44. "last_backup_commit_sha": config.last_backup_commit_sha,
  45. "next_scheduled_run": config.next_scheduled_run,
  46. "created_at": config.created_at,
  47. "updated_at": config.updated_at,
  48. }
  49. @router.get("/config", response_model=GitHubBackupConfigResponse | None)
  50. async def get_config(
  51. db: AsyncSession = Depends(get_db),
  52. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  53. ):
  54. """Get the current GitHub backup configuration."""
  55. result = await db.execute(select(GitHubBackupConfig).limit(1))
  56. config = result.scalar_one_or_none()
  57. if not config:
  58. return None
  59. return _config_to_response(config)
  60. @router.post("/config", response_model=GitHubBackupConfigResponse)
  61. async def save_config(
  62. config_data: GitHubBackupConfigCreate,
  63. db: AsyncSession = Depends(get_db),
  64. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  65. ):
  66. """Create or update GitHub backup configuration.
  67. Only one configuration is supported. If one exists, it will be updated.
  68. """
  69. # Check for existing config
  70. result = await db.execute(select(GitHubBackupConfig).limit(1))
  71. config = result.scalar_one_or_none()
  72. if config:
  73. # Update existing
  74. config.repository_url = config_data.repository_url
  75. config.access_token = config_data.access_token
  76. config.branch = config_data.branch
  77. config.provider = config_data.provider.value
  78. config.schedule_enabled = config_data.schedule_enabled
  79. config.schedule_type = config_data.schedule_type.value
  80. config.backup_kprofiles = config_data.backup_kprofiles
  81. config.backup_cloud_profiles = config_data.backup_cloud_profiles
  82. config.backup_settings = config_data.backup_settings
  83. config.backup_spools = config_data.backup_spools
  84. config.backup_archives = config_data.backup_archives
  85. config.allow_insecure_http = config_data.allow_insecure_http
  86. config.enabled = config_data.enabled
  87. # Calculate next scheduled run if enabled
  88. if config.schedule_enabled:
  89. config.next_scheduled_run = github_backup_service.calculate_next_run(config.schedule_type)
  90. else:
  91. config.next_scheduled_run = None
  92. logger.info("Updated GitHub backup config: %s", config.repository_url)
  93. else:
  94. # Create new
  95. config = GitHubBackupConfig(
  96. repository_url=config_data.repository_url,
  97. access_token=config_data.access_token,
  98. branch=config_data.branch,
  99. provider=config_data.provider.value,
  100. schedule_enabled=config_data.schedule_enabled,
  101. schedule_type=config_data.schedule_type.value,
  102. backup_kprofiles=config_data.backup_kprofiles,
  103. backup_cloud_profiles=config_data.backup_cloud_profiles,
  104. backup_settings=config_data.backup_settings,
  105. backup_spools=config_data.backup_spools,
  106. backup_archives=config_data.backup_archives,
  107. allow_insecure_http=config_data.allow_insecure_http,
  108. enabled=config_data.enabled,
  109. )
  110. if config.schedule_enabled:
  111. config.next_scheduled_run = github_backup_service.calculate_next_run(config.schedule_type)
  112. db.add(config)
  113. logger.info("Created GitHub backup config: %s", config.repository_url)
  114. await db.commit()
  115. await db.refresh(config)
  116. return _config_to_response(config)
  117. @router.patch("/config", response_model=GitHubBackupConfigResponse)
  118. async def update_config(
  119. update_data: GitHubBackupConfigUpdate,
  120. db: AsyncSession = Depends(get_db),
  121. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  122. ):
  123. """Partially update GitHub backup configuration."""
  124. result = await db.execute(select(GitHubBackupConfig).limit(1))
  125. config = result.scalar_one_or_none()
  126. if not config:
  127. raise HTTPException(status_code=404, detail="No configuration found")
  128. update_dict = update_data.model_dump(exclude_unset=True)
  129. # Validate HTTP URL restriction when the URL policy is being changed. This avoids blocking unrelated autosaves
  130. # for legacy configs that already contain an HTTP URL.
  131. if "repository_url" in update_dict or "allow_insecure_http" in update_dict:
  132. url_to_check = update_dict.get("repository_url", config.repository_url)
  133. effective_allow_http = update_dict.get("allow_insecure_http", config.allow_insecure_http)
  134. if url_to_check and url_to_check.startswith("http://") and not effective_allow_http:
  135. raise HTTPException(
  136. status_code=422,
  137. detail="This URL uses HTTP instead of HTTPS. Enable 'Allow insecure HTTP' if your instance does not use TLS.",
  138. )
  139. for key, value in update_dict.items():
  140. if key in ("schedule_type", "provider") and value is not None:
  141. setattr(config, key, value.value)
  142. else:
  143. setattr(config, key, value)
  144. # Recalculate next scheduled run if schedule settings changed
  145. if "schedule_enabled" in update_dict or "schedule_type" in update_dict:
  146. if config.schedule_enabled:
  147. config.next_scheduled_run = github_backup_service.calculate_next_run(config.schedule_type)
  148. else:
  149. config.next_scheduled_run = None
  150. await db.commit()
  151. await db.refresh(config)
  152. logger.info("Updated GitHub backup config: %s", config.repository_url)
  153. return _config_to_response(config)
  154. @router.delete("/config")
  155. async def delete_config(
  156. db: AsyncSession = Depends(get_db),
  157. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  158. ):
  159. """Delete the GitHub backup configuration and all logs."""
  160. result = await db.execute(select(GitHubBackupConfig).limit(1))
  161. config = result.scalar_one_or_none()
  162. if not config:
  163. raise HTTPException(status_code=404, detail="No configuration found")
  164. await db.delete(config)
  165. await db.commit()
  166. logger.info("Deleted GitHub backup config")
  167. return {"message": "Configuration deleted"}
  168. @router.post("/test", response_model=GitHubTestConnectionResponse)
  169. async def test_connection(
  170. repo_url: str = Query(..., description="Repository URL"),
  171. token: str = Query(..., description="Personal Access Token"),
  172. provider: ProviderType = Query(default=ProviderType.GITHUB, description="Git provider key"),
  173. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  174. ):
  175. """Test Git provider connection with provided credentials."""
  176. result = await github_backup_service.test_connection(repo_url, token, provider=provider)
  177. return GitHubTestConnectionResponse(**result)
  178. @router.post("/test-stored", response_model=GitHubTestConnectionResponse)
  179. async def test_stored_connection(
  180. db: AsyncSession = Depends(get_db),
  181. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  182. ):
  183. """Test GitHub connection using stored configuration."""
  184. result = await db.execute(select(GitHubBackupConfig).limit(1))
  185. config = result.scalar_one_or_none()
  186. if not config:
  187. raise HTTPException(status_code=404, detail="No configuration found")
  188. if not config.access_token:
  189. raise HTTPException(status_code=400, detail="No access token configured")
  190. test_result = await github_backup_service.test_connection(
  191. config.repository_url,
  192. config.access_token,
  193. provider=config.provider,
  194. )
  195. return GitHubTestConnectionResponse(**test_result)
  196. @router.post("/run", response_model=GitHubBackupTriggerResponse)
  197. async def trigger_backup(
  198. db: AsyncSession = Depends(get_db),
  199. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  200. ):
  201. """Manually trigger a backup."""
  202. result = await db.execute(select(GitHubBackupConfig).limit(1))
  203. config = result.scalar_one_or_none()
  204. if not config:
  205. raise HTTPException(status_code=404, detail="No configuration found. Configure backup first.")
  206. if not config.enabled:
  207. raise HTTPException(status_code=400, detail="Backup is disabled")
  208. backup_result = await github_backup_service.run_backup(config.id, trigger="manual")
  209. return GitHubBackupTriggerResponse(**backup_result)
  210. @router.get("/status", response_model=GitHubBackupStatus)
  211. async def get_status(
  212. db: AsyncSession = Depends(get_db),
  213. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  214. ):
  215. """Get current backup status."""
  216. result = await db.execute(select(GitHubBackupConfig).limit(1))
  217. config = result.scalar_one_or_none()
  218. if not config:
  219. return GitHubBackupStatus(
  220. configured=False,
  221. enabled=False,
  222. is_running=False,
  223. progress=None,
  224. last_backup_at=None,
  225. last_backup_status=None,
  226. next_scheduled_run=None,
  227. )
  228. return GitHubBackupStatus(
  229. configured=True,
  230. enabled=config.enabled,
  231. is_running=github_backup_service.is_running,
  232. progress=github_backup_service.progress,
  233. last_backup_at=config.last_backup_at,
  234. last_backup_status=config.last_backup_status,
  235. next_scheduled_run=config.next_scheduled_run,
  236. )
  237. @router.get("/logs", response_model=list[GitHubBackupLogResponse])
  238. async def get_logs(
  239. limit: int = Query(default=50, ge=1, le=200),
  240. offset: int = Query(default=0, ge=0),
  241. db: AsyncSession = Depends(get_db),
  242. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  243. ):
  244. """Get backup logs."""
  245. result = await db.execute(select(GitHubBackupConfig).limit(1))
  246. config = result.scalar_one_or_none()
  247. if not config:
  248. return []
  249. logs_result = await db.execute(
  250. select(GitHubBackupLog)
  251. .where(GitHubBackupLog.config_id == config.id)
  252. .order_by(desc(GitHubBackupLog.started_at))
  253. .offset(offset)
  254. .limit(limit)
  255. )
  256. logs = logs_result.scalars().all()
  257. return [
  258. GitHubBackupLogResponse(
  259. id=log.id,
  260. config_id=log.config_id,
  261. started_at=log.started_at,
  262. completed_at=log.completed_at,
  263. status=log.status,
  264. trigger=log.trigger,
  265. commit_sha=log.commit_sha,
  266. files_changed=log.files_changed,
  267. error_message=log.error_message,
  268. )
  269. for log in logs
  270. ]
  271. @router.delete("/logs")
  272. async def clear_logs(
  273. keep_last: int = Query(default=10, ge=0, le=100, description="Number of recent logs to keep"),
  274. db: AsyncSession = Depends(get_db),
  275. _: User | None = RequirePermissionIfAuthEnabled(Permission.GITHUB_BACKUP),
  276. ):
  277. """Clear backup logs, optionally keeping the most recent entries."""
  278. result = await db.execute(select(GitHubBackupConfig).limit(1))
  279. config = result.scalar_one_or_none()
  280. if not config:
  281. return {"deleted": 0, "message": "No configuration found"}
  282. if keep_last > 0:
  283. # Get IDs to keep
  284. keep_result = await db.execute(
  285. select(GitHubBackupLog.id)
  286. .where(GitHubBackupLog.config_id == config.id)
  287. .order_by(desc(GitHubBackupLog.started_at))
  288. .limit(keep_last)
  289. )
  290. keep_ids = [row[0] for row in keep_result.fetchall()]
  291. if keep_ids:
  292. delete_result = await db.execute(
  293. delete(GitHubBackupLog).where(
  294. GitHubBackupLog.config_id == config.id, GitHubBackupLog.id.not_in(keep_ids)
  295. )
  296. )
  297. else:
  298. delete_result = await db.execute(delete(GitHubBackupLog).where(GitHubBackupLog.config_id == config.id))
  299. else:
  300. delete_result = await db.execute(delete(GitHubBackupLog).where(GitHubBackupLog.config_id == config.id))
  301. await db.commit()
  302. deleted_count = delete_result.rowcount
  303. logger.info("Deleted %s GitHub backup logs (kept %s)", deleted_count, keep_last)
  304. return {"deleted": deleted_count, "message": f"Deleted {deleted_count} logs"}