Updated backend
This commit is contained in:
39
README.md
39
README.md
@@ -12,13 +12,19 @@ documentation (`docs/`). This file is just a fast local reference.
|
||||
|
||||
## Quick start
|
||||
|
||||
### One-click (Windows)
|
||||
### One command (from the project root)
|
||||
|
||||
Double-click **`start_backend.bat`**. It picks up `venv\Scripts\python.exe`
|
||||
if present (else falls back to system `python`), starts/creates the
|
||||
`catalog_rag_postgres` Docker container from `docker-compose.yml`,
|
||||
launches Ollama in the background if it's installed but not running,
|
||||
seeds sample data if needed, then starts uvicorn on port 8000.
|
||||
```bash
|
||||
python run_project.py --backend-only
|
||||
```
|
||||
|
||||
Picks up `backend/venv` if present (else the current interpreter) and starts
|
||||
uvicorn with autoreload on port 8000. Drop `--backend-only` to run the React
|
||||
frontend alongside it; `--help` lists the port and reload flags.
|
||||
|
||||
It does **not** start Postgres or Ollama for you - it reports them via
|
||||
`/api/health` and warns if either is unreachable. Bring those up first
|
||||
(see Manual below, and "Pulling the local LLM").
|
||||
|
||||
### Manual
|
||||
|
||||
@@ -30,6 +36,10 @@ pip install -r requirements.txt
|
||||
|
||||
cp .env.example .env # then edit DB_PASSWORD etc.
|
||||
|
||||
# Auth is required: the app will not start without AUTH_SECRET_KEY and the two
|
||||
# password hashes. This prints them, plus the sign-in passwords (shown once).
|
||||
python scripts/make_auth_secrets.py
|
||||
|
||||
# Option A: already have a Postgres+pgvector catalog from the old project?
|
||||
# Just point .env at it (DB_HOST/DB_PORT/DB_NAME/DB_USER/DB_PASSWORD) - done.
|
||||
# Option B: starting fresh locally?
|
||||
@@ -42,6 +52,23 @@ uvicorn app.main:app --reload --port 8000
|
||||
Then open http://localhost:8000/docs for interactive API docs, or run the
|
||||
frontend (`../frontend/README.md`) to use the React UI.
|
||||
|
||||
## Authentication
|
||||
|
||||
Reads are public; the 18 write/compute endpoints require a credential, enforced
|
||||
by a dependency on each route (`app/api/deps.py`). Sign in for a bearer token:
|
||||
|
||||
```bash
|
||||
curl -X POST localhost:8000/api/auth/login \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{"username":"admin","password":"<from make_auth_secrets.py>"}'
|
||||
```
|
||||
|
||||
Send it as `Authorization: Bearer <token>`, or use an `X-API-Key` from the
|
||||
`API_KEYS` setting for server-to-server callers. `admin` passes every
|
||||
permission check; `user` holds the product/store/inventory permissions.
|
||||
`AUTH_ENABLED=false` disables all of it for local work — never in a deployment.
|
||||
See the Authentication section of `../DEPLOYMENT.md` for the full endpoint map.
|
||||
|
||||
## Pulling the local LLM (one-time)
|
||||
|
||||
```bash
|
||||
|
||||
Reference in New Issue
Block a user