"""
services/auth.py — backwards-compat shim
=========================================
Older modules in this codebase (routes/websocket.py, routes/sessions.py,
routes/scenarios.py, etc.) import `from services.auth import …`. The real
implementation lives in `services/auth_service.py` and the FastAPI dependency
is in `middleware/auth_middleware.py`.

This shim re-exports the canonical names so legacy imports keep working
without us having to chase down every callsite.
"""
from __future__ import annotations

from services.auth_service import (  # noqa: F401
    create_token,
    decode_token,
    validate_access_key,
    get_candidate,
    advance_stage,
    get_redirect_url,
    get_stage_name,
)
from middleware.auth_middleware import get_current_candidate as get_current_user  # noqa: F401
from middleware.auth_middleware import get_current_candidate                      # noqa: F401


# Admin gate — minimal stub. Real implementation should check an admin role
# claim on the JWT or a separate admin token. For now we just rely on the
# candidate dependency so the route is at least authenticated.
def require_admin(candidate: dict = None):  # type: ignore[assignment]
    """FastAPI dependency stub — replace with real admin check in production."""
    # Lazy import so this module stays cheap to import
    from fastapi import Depends, HTTPException, status

    def _gate(c: dict = Depends(get_current_candidate)) -> dict:
        if not (c.get("is_admin") or c.get("role") == "admin"):
            raise HTTPException(
                status.HTTP_403_FORBIDDEN,
                "Admin privileges required for this action.",
            )
        return c

    # When used as `Depends(require_admin)`, FastAPI calls it without args.
    # Returning the inner callable here would break that contract; instead
    # we resolve the dependency directly.
    if candidate is None:
        # Called as a dependency factory — return the gate
        return _gate  # type: ignore[return-value]
    return _gate(candidate)
