first time building frontend app,
in backend i'm running fastapi , I prepare the all required functionalities for security using JWT , and it being tested for all existing endpoints (non are webpage).
Now i added a small app to frontend and i'd like to understand how i should restrict the access to users with valid token .
JWT restrict all non frontend endpoint by:
current_user: User = Security(get_current_active_user, scopes=["user_read"])
now i added frontend:
@customers_router.get("/customers", tags=["home"])
async def home(request: Request ,limit: int = 10) :
customers_cursor = DB.customer.find()
customers = await customers_cursor.to_list(length=limit)
customers = list(map(fix_customer_id, customers))
return templates.TemplateResponse("customer.html",{"request": request, "customers": customers})
I'm not sure for how it should work... I understand user need the be authorize by token and if his token is valid then he he should be able to get to the webpage "/customers", can some1 guide me what i missing ?