klg-asutk-app/backend/app/api/routes/tasks.py
Yuriy aa052763f6 Безопасность и качество: 8 исправлений + обновления
- .env.example: полный шаблон, защита секретов
- .gitignore: явное исключение .env.* и секретов
- layout.tsx: XSS — заменён dangerouslySetInnerHTML на next/script для SW
- ESLint: no-console error (allow warn/error), ignore scripts/
- scripts/remove-console-logs.js: очистка console.log без glob
- backend/routes/modules: README с планом рефакторинга крупных файлов
- SECURITY.md: гид по секретам, XSS, CORS, auth, линту
- .husky/pre-commit: запуск npm run lint

+ прочие правки приложения и бэкенда

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-14 21:29:16 +03:00

31 lines
1.3 KiB
Python

from app.schemas.tasks import TaskOut
"""Tasks API — unified task view across entities."""
from datetime import datetime, timezone
from typing import List
from fastapi import APIRouter, Depends, Query
from sqlalchemy.orm import Session
from app.db.session import get_db
from app.api.deps import get_current_user
from app.api.helpers import is_authority
from app.models.cert_application import CertApplication
router = APIRouter(tags=["tasks"])
@router.get("/tasks", response_model=List[TaskOut])
def list_tasks(state: str = Query(default="open"), db: Session = Depends(get_db), user=Depends(get_current_user)):
q = db.query(CertApplication)
if not is_authority(user) and user.organization_id:
q = q.filter(CertApplication.applicant_org_id == user.organization_id)
if state == "open":
q = q.filter(CertApplication.status.in_(["submitted", "under_review", "remarks"]))
now = datetime.now(timezone.utc)
return [
TaskOut(entity_type="cert_application", entity_id=a.id, title=f"Заявка №{a.number}",
status=a.status, due_at=a.remarks_deadline_at,
priority="high" if a.remarks_deadline_at and a.remarks_deadline_at <= now else "normal",
updated_at=a.updated_at)
for a in q.order_by(CertApplication.updated_at.desc()).limit(100).all()
]