Public landing page is now served in English and Italian via path-
prefixed URLs (/en/ and /it/), with the bare / detecting the
visitor's language and 302-ing to the right one.
Routing
-------
* GET / : if authed → dashboard (unchanged). Otherwise the visitor's
language is resolved from (in priority order) the rtm.lang cookie,
the Accept-Language header, the cf-ipcountry geolocation header,
and finally DEFAULT_LANG, then a 302 redirects to /<lang>/.
* GET /en/ + /it/ : render the localised landing template, set the
rtm.lang cookie (1-year, SameSite=Lax) so the next /-visit goes
straight to the same translation. Logged-in users with user.lang
set bypass detection for / (same priority chain — user.lang wins
on every public surface they touch).
Storage
-------
* app/locales/<lang>.yaml — flat-ish nested copy files. YAML chosen
so a future translator can edit without touching Python. Strings
containing inline HTML (<strong>, <em>, <a>) are rendered with the
Jinja `safe` filter in the template.
* app/services/locales.py — loads at startup, exposes get_locale()
and detect_public_lang(). Wraps each YAML tree in a small _Dotted
view so templates can write {{ t.hero.subhead }} (deliberately NOT
a dict subclass — dict's built-in method names would shadow YAML
keys like `items`).
Template + chrome
-----------------
* landing.html ported in full to {{ t.<key> }} references.
* public_base.html gets <html lang="…"> + hreflang link tags (en/it/
x-default) when a route opts in via lang_switch=true. A tiny
EN | IT link group lands in the public header, only visible on
surfaces that opt in.
* public.css picks up the small lang-switch widget styles.
Scope (intentionally narrow)
----------------------------
* Only the landing page is localised. Pricing, terms, privacy,
disclaimer, login, verify all stay English-only for now; their
header chrome stays English too because localising labels there
while the linked content is still EN would be a worse mismatch.
* When other public pages get translated, lang_switch=true on those
routes will surface the same widget there with no template changes.
Tests
-----
* tests/test_locales.py covers YAML load parity (every active
language has a file), dotted access through the tree, the
detection precedence chain, and the unknown-locale fallback.
Deps
----
* pyyaml was already in requirements.lock as a transitive but not
declared. Added to pyproject so it stays pinned as an explicit
direct dependency.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
115 lines
4.7 KiB
Python
115 lines
4.7 KiB
Python
"""FastAPI entrypoint. Runs Alembic migrations on startup, bootstraps the
|
|
feeds table from TOML, mounts the API + HTML routers.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import asyncio
|
|
from contextlib import asynccontextmanager
|
|
from pathlib import Path
|
|
|
|
from alembic import command
|
|
from alembic.config import Config as AlembicConfig
|
|
from fastapi import FastAPI
|
|
from fastapi.middleware.gzip import GZipMiddleware
|
|
from fastapi.staticfiles import StaticFiles
|
|
|
|
from app import branding
|
|
from app.config import get_settings
|
|
from app.db import get_session_factory
|
|
from app.logging import configure_logging, get_logger
|
|
from app.routers import api as api_router
|
|
from app.routers import auth as auth_router
|
|
from app.routers import chat as chat_router
|
|
from app.routers import email as email_router
|
|
from app.routers import ops as ops_router
|
|
from app.routers import pages as pages_router
|
|
from app.routers import polar_webhook as polar_webhook_router
|
|
from app.routers import public as public_router
|
|
from app.routers import stripe_billing as stripe_router
|
|
from app.routers import sync as sync_router
|
|
from app.routers import ticker_validate as ticker_validate_router
|
|
from app.routers import universe as universe_router
|
|
from app.services.feeds_bootstrap import bootstrap_feeds
|
|
|
|
|
|
log = get_logger("cassandra")
|
|
APP_DIR = Path(__file__).resolve().parent
|
|
PROJECT_DIR = APP_DIR.parent
|
|
|
|
|
|
def _run_migrations() -> None:
|
|
"""Synchronous Alembic upgrade. Called once at lifespan startup."""
|
|
cfg = AlembicConfig(str(PROJECT_DIR / "alembic.ini"))
|
|
cfg.set_main_option("script_location", str(PROJECT_DIR / "alembic"))
|
|
cfg.set_main_option("sqlalchemy.url", get_settings().DATABASE_URL)
|
|
command.upgrade(cfg, "head")
|
|
|
|
|
|
@asynccontextmanager
|
|
async def lifespan(app: FastAPI):
|
|
configure_logging()
|
|
log.info("cassandra.startup")
|
|
s = get_settings()
|
|
if not s.PORTFOLIO_SYNC_PEPPER and not s.DATABASE_URL.startswith("sqlite"):
|
|
# Outer wrap still works (it just degrades to a per-user derived
|
|
# key with no shared secret), but a DB leak would let an attacker
|
|
# brute-force the PIN offline. Loud warning, not a hard failure.
|
|
log.warning("cassandra.portfolio_sync.pepper_missing")
|
|
try:
|
|
# Alembic's env.py uses asyncio.run() internally; offload it to a
|
|
# worker thread so it doesn't collide with FastAPI's running loop.
|
|
await asyncio.to_thread(_run_migrations)
|
|
log.info("cassandra.migrations.applied")
|
|
except Exception as e:
|
|
log.error("cassandra.migrations.failed", error=str(e))
|
|
raise
|
|
async with get_session_factory()() as session:
|
|
inserted = await bootstrap_feeds(session)
|
|
log.info("cassandra.feeds.bootstrap", inserted=inserted)
|
|
# Load public-page translation YAMLs into memory once at startup.
|
|
# Lazy-loaded otherwise, but pre-loading lets startup fail loudly
|
|
# if a YAML file is corrupted instead of failing on the first
|
|
# landing-page request.
|
|
from app.services.locales import load_locales
|
|
load_locales()
|
|
yield
|
|
log.info("cassandra.shutdown")
|
|
|
|
|
|
app = FastAPI(
|
|
title=branding.BRAND_NAME,
|
|
description="Macro-strategy dashboard",
|
|
version="0.1.0",
|
|
lifespan=lifespan,
|
|
)
|
|
|
|
# Gzip responses ≥500 bytes when the client sends Accept-Encoding: gzip.
|
|
# The Phase G universe payload is repetitive JSON that gzips to ~25-30%
|
|
# of raw size; compression is mandatory for that endpoint to be cheap.
|
|
app.add_middleware(GZipMiddleware, minimum_size=500)
|
|
|
|
app.mount(
|
|
"/static",
|
|
StaticFiles(directory=str(APP_DIR / "static")),
|
|
name="static",
|
|
)
|
|
|
|
app.include_router(auth_router.router, tags=["auth"])
|
|
app.include_router(email_router.router, tags=["email"])
|
|
app.include_router(api_router.router, prefix="/api", tags=["api"])
|
|
app.include_router(chat_router.router, prefix="/api", tags=["chat"])
|
|
app.include_router(ops_router.router, prefix="/api", tags=["ops"])
|
|
app.include_router(universe_router.router, prefix="/api", tags=["universe"])
|
|
app.include_router(ticker_validate_router.router, prefix="/api", tags=["ticker-validate"])
|
|
app.include_router(sync_router.router, tags=["portfolio-sync"])
|
|
# Polar webhook (no bearer-token auth — authenticity via HMAC). Path
|
|
# `/api/polar/webhook` is set on the route itself so the URL Polar
|
|
# stores remains stable even if api_router's prefix ever moves.
|
|
app.include_router(polar_webhook_router.router, tags=["polar-webhook"])
|
|
# Stripe billing (checkout, portal, webhook). Auth lives per-route:
|
|
# checkout + portal require_auth, webhook is signature-gated.
|
|
app.include_router(stripe_router.router, tags=["stripe-billing"])
|
|
# Public router (no auth dep) before pages_router so the marketing/legal
|
|
# paths can never collide with future authenticated routes.
|
|
app.include_router(public_router.router)
|
|
app.include_router(pages_router.router, tags=["pages"])
|