Updated backend

This commit is contained in:
sriram
2026-08-12 16:37:28 +05:30
parent eb3567df62
commit ac8cfacbc9
21 changed files with 1496 additions and 155 deletions

View File

@@ -12,13 +12,19 @@ documentation (`docs/`). This file is just a fast local reference.
## Quick start
### One-click (Windows)
### One command (from the project root)
Double-click **`start_backend.bat`**. It picks up `venv\Scripts\python.exe`
if present (else falls back to system `python`), starts/creates the
`catalog_rag_postgres` Docker container from `docker-compose.yml`,
launches Ollama in the background if it's installed but not running,
seeds sample data if needed, then starts uvicorn on port 8000.
```bash
python run_project.py --backend-only
```
Picks up `backend/venv` if present (else the current interpreter) and starts
uvicorn with autoreload on port 8000. Drop `--backend-only` to run the React
frontend alongside it; `--help` lists the port and reload flags.
It does **not** start Postgres or Ollama for you - it reports them via
`/api/health` and warns if either is unreachable. Bring those up first
(see Manual below, and "Pulling the local LLM").
### Manual
@@ -30,6 +36,10 @@ pip install -r requirements.txt
cp .env.example .env # then edit DB_PASSWORD etc.
# Auth is required: the app will not start without AUTH_SECRET_KEY and the two
# password hashes. This prints them, plus the sign-in passwords (shown once).
python scripts/make_auth_secrets.py
# Option A: already have a Postgres+pgvector catalog from the old project?
# Just point .env at it (DB_HOST/DB_PORT/DB_NAME/DB_USER/DB_PASSWORD) - done.
# Option B: starting fresh locally?
@@ -42,6 +52,23 @@ uvicorn app.main:app --reload --port 8000
Then open http://localhost:8000/docs for interactive API docs, or run the
frontend (`../frontend/README.md`) to use the React UI.
## Authentication
Reads are public; the 18 write/compute endpoints require a credential, enforced
by a dependency on each route (`app/api/deps.py`). Sign in for a bearer token:
```bash
curl -X POST localhost:8000/api/auth/login \
-H 'Content-Type: application/json' \
-d '{"username":"admin","password":"<from make_auth_secrets.py>"}'
```
Send it as `Authorization: Bearer <token>`, or use an `X-API-Key` from the
`API_KEYS` setting for server-to-server callers. `admin` passes every
permission check; `user` holds the product/store/inventory permissions.
`AUTH_ENABLED=false` disables all of it for local work — never in a deployment.
See the Authentication section of `../DEPLOYMENT.md` for the full endpoint map.
## Pulling the local LLM (one-time)
```bash