From 6f1912261a5c0ddce3ed1d132ace6cf0b5e93ecd Mon Sep 17 00:00:00 2001 From: Noloquideus Date: Sun, 28 Jun 2026 14:12:24 +0300 Subject: [PATCH] fix: harden kyc startup and beorg errors --- src/infrastructure/beorg/client.py | 15 +++++++++++++-- src/infrastructure/config/settings.py | 1 + src/main.py | 12 +++++++----- 3 files changed, 21 insertions(+), 7 deletions(-) diff --git a/src/infrastructure/beorg/client.py b/src/infrastructure/beorg/client.py index 5e249b1..3e925e2 100644 --- a/src/infrastructure/beorg/client.py +++ b/src/infrastructure/beorg/client.py @@ -1,6 +1,7 @@ from __future__ import annotations from typing import Any import aiohttp +from pydantic import ValidationError from src.application.contracts import IBeorgService from src.application.domain.dto import BeorgKycCreateResponse,BeorgKycResultResponse from src.application.domain.exceptions import BeorgConfigException,BeorgRejectedException,BeorgUnavailableException @@ -50,11 +51,16 @@ class BeorgService(IBeorgService): raise BeorgUnavailableException() from None except aiohttp.ClientError: raise BeorgUnavailableException() from None + except (ValueError,ValidationError): + raise BeorgUnavailableException() from None if response.status >= 500: raise BeorgUnavailableException() - result = BeorgKycCreateResponse.model_validate(data) + try: + result = BeorgKycCreateResponse.model_validate(data) + except ValidationError: + raise BeorgUnavailableException() from None if not result.status: raise BeorgRejectedException(result.error or 'Beorg rejected kyc request') @@ -79,11 +85,16 @@ class BeorgService(IBeorgService): raise BeorgUnavailableException() from None except aiohttp.ClientError: raise BeorgUnavailableException() from None + except (ValueError,ValidationError): + raise BeorgUnavailableException() from None if response.status >= 500: raise BeorgUnavailableException() - return BeorgKycResultResponse.model_validate(data) + try: + return BeorgKycResultResponse.model_validate(data) + except ValidationError: + raise BeorgUnavailableException() from None def _ensure_configured(self) -> None: diff --git a/src/infrastructure/config/settings.py b/src/infrastructure/config/settings.py index ad65ce5..76ee290 100644 --- a/src/infrastructure/config/settings.py +++ b/src/infrastructure/config/settings.py @@ -14,6 +14,7 @@ class Settings(BaseSettings): DOCS_USERNAME: str = 'admin' DOCS_PASSWORD: str = 'admin' + CORS_ALLOW_ORIGIN_REGEX: str = r'https?://([a-z0-9-]+\.)*elcsa\.ru(:\d+)?$' VAULT_ADDR: str = 'https://corp.vault.elcsa.ru' VAULT_ROLE_ID: str = '' VAULT_SECRET_ID: str = '' diff --git a/src/main.py b/src/main.py index 2ff3fa2..f19d39f 100644 --- a/src/main.py +++ b/src/main.py @@ -84,10 +84,12 @@ async def lifespan(app: FastAPI) -> AsyncGenerator[None, None]: app.state.jwt_key_store = jwt_store app.state.jwt_keys_scheduler = jwt_scheduler app.state.kyc_scheduler = kyc_scheduler - yield - app.state.kyc_scheduler.shutdown(wait=False) - app.state.jwt_keys_scheduler.shutdown(wait=False) - logger.info(f'Users service instance ended with id {instance_id}') + try: + yield + finally: + app.state.kyc_scheduler.shutdown(wait=False) + app.state.jwt_keys_scheduler.shutdown(wait=False) + logger.info(f'KYC service instance ended with id {instance_id}') app: FastAPI = FastAPI( @@ -126,7 +128,7 @@ app.add_middleware( app.add_middleware( CORSMiddleware, allow_origins=[], - allow_origin_regex='.*', + allow_origin_regex=settings.CORS_ALLOW_ORIGIN_REGEX, allow_credentials=True, allow_methods=['*'], allow_headers=['*'],