2026-08-05 19:04:48 +08:00
|
|
|
"""BadNote FastAPI server — main application.
|
|
|
|
|
|
|
|
|
|
Architecture (v1):
|
|
|
|
|
- Vault files are the source of truth (same layout as the Flutter vault).
|
|
|
|
|
- ``/api/v1/vault/*`` assists multi-device sync (manifest + PUT/GET/DELETE).
|
|
|
|
|
- ``/api/v1/ocr/*`` accepts ink rasters for deferred server OCR.
|
|
|
|
|
- Legacy ``/api/notes`` etc. remain mounted under ``/api/legacy/*`` for
|
|
|
|
|
compatibility with old experiments; new clients must not use them.
|
|
|
|
|
"""
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
|
|
|
|
|
import os
|
|
|
|
|
from contextlib import asynccontextmanager
|
|
|
|
|
|
|
|
|
|
from fastapi import FastAPI
|
|
|
|
|
from fastapi.middleware.cors import CORSMiddleware
|
|
|
|
|
|
|
|
|
|
from .config import settings
|
|
|
|
|
from .database import close_db, init_db
|
|
|
|
|
from .routers.auth_router import router as auth_router
|
|
|
|
|
from .routers.notes_router import router as notes_router
|
|
|
|
|
from .routers.documents_router import router as documents_router
|
|
|
|
|
from .routers.ocr_router import router as ocr_router
|
|
|
|
|
from .routers.sync_router import router as sync_router
|
2026-08-05 19:04:48 +08:00
|
|
|
from .routers.v1_vault_router import router as v1_vault_router
|
|
|
|
|
from .routers.v1_ocr_router import router as v1_ocr_router
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@asynccontextmanager
|
|
|
|
|
async def lifespan(app: FastAPI):
|
|
|
|
|
"""Startup: create directories and init DB. Shutdown: close DB."""
|
|
|
|
|
os.makedirs(settings.storage_path, exist_ok=True)
|
2026-08-05 19:04:48 +08:00
|
|
|
os.makedirs(settings.vault_path, exist_ok=True)
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
for subdir in ("pending", "processing", "done", "failed"):
|
|
|
|
|
os.makedirs(os.path.join(settings.queue_path, subdir), exist_ok=True)
|
|
|
|
|
await init_db()
|
|
|
|
|
yield
|
|
|
|
|
await close_db()
|
|
|
|
|
|
|
|
|
|
|
2026-08-05 19:04:48 +08:00
|
|
|
app = FastAPI(
|
|
|
|
|
title="BadNote Server",
|
|
|
|
|
version="2.0.0",
|
|
|
|
|
description=(
|
|
|
|
|
"Self-hosted companion for BadNote. "
|
|
|
|
|
"Primary API is /api/v1 (vault + OCR). "
|
|
|
|
|
"Legacy notes CRUD lives under /api/legacy."
|
|
|
|
|
),
|
|
|
|
|
lifespan=lifespan,
|
|
|
|
|
)
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
|
|
|
|
|
_cors_origins = settings.cors_origins or ["*"]
|
|
|
|
|
|
|
|
|
|
app.add_middleware(
|
|
|
|
|
CORSMiddleware,
|
|
|
|
|
allow_origins=_cors_origins,
|
|
|
|
|
allow_credentials=False,
|
|
|
|
|
allow_methods=["*"],
|
|
|
|
|
allow_headers=["*"],
|
|
|
|
|
)
|
|
|
|
|
|
2026-08-05 19:04:48 +08:00
|
|
|
# --- Auth (shared by v1 + legacy) ---
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
app.include_router(auth_router, prefix="/api/auth", tags=["auth"])
|
2026-08-05 19:04:48 +08:00
|
|
|
app.include_router(auth_router, prefix="/api/v1/auth", tags=["auth-v1"])
|
|
|
|
|
|
|
|
|
|
# --- Primary v1 API ---
|
|
|
|
|
app.include_router(v1_vault_router, prefix="/api/v1/vault", tags=["vault-v1"])
|
|
|
|
|
app.include_router(v1_ocr_router, prefix="/api/v1/ocr", tags=["ocr-v1"])
|
|
|
|
|
|
|
|
|
|
# --- Legacy (deprecated) ---
|
|
|
|
|
app.include_router(notes_router, prefix="/api/legacy/notes", tags=["legacy-notes"])
|
|
|
|
|
app.include_router(documents_router, prefix="/api/legacy/documents", tags=["legacy-documents"])
|
|
|
|
|
app.include_router(ocr_router, prefix="/api/legacy/ocr", tags=["legacy-ocr"])
|
|
|
|
|
app.include_router(sync_router, prefix="/api/legacy/sync", tags=["legacy-sync"])
|
|
|
|
|
# Keep old paths temporarily so existing bookmarks to /docs experiments still work,
|
|
|
|
|
# but they are the same legacy routers.
|
|
|
|
|
app.include_router(notes_router, prefix="/api/notes", tags=["legacy-notes"], include_in_schema=False)
|
|
|
|
|
app.include_router(documents_router, prefix="/api/documents", tags=["legacy-documents"], include_in_schema=False)
|
|
|
|
|
app.include_router(ocr_router, prefix="/api/ocr", tags=["legacy-ocr"], include_in_schema=False)
|
|
|
|
|
app.include_router(sync_router, prefix="/api/sync", tags=["legacy-sync"], include_in_schema=False)
|
Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
deletePageData, OCR FTS merge, migrations) in transactions to prevent data
loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.
UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
save/find), toolbar overflow handling, friendlier empty states, semantic OCR
status badges, relative timestamps, 1-based page indicators, large-deck PPT
navigation, and a scratchpad-scope label in split view.
Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
guard, constant-time login, and split out heavy OCR deps so the API/tests run
without them.
CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 03:18:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@app.get("/api/ping")
|
2026-08-05 19:04:48 +08:00
|
|
|
@app.get("/api/v1/health")
|
|
|
|
|
async def health() -> dict:
|
|
|
|
|
"""Liveness probe for clients and reverse proxies."""
|
|
|
|
|
return {
|
|
|
|
|
"status": "ok",
|
|
|
|
|
"version": "2.0.0",
|
|
|
|
|
"api": "v1",
|
|
|
|
|
"features": ["vault", "ocr", "auth"],
|
|
|
|
|
}
|