from rest_framework.authentication import BaseAuthentication from rest_framework.exceptions import AuthenticationFailed from rowers.models import APIKey class APIKeyAuthentication(BaseAuthentication): def authenticate(self, request): auth_header = request.META.get('HTTP_AUTHORIZATION') if not auth_header: return None # Handle "ApiKey " format (CrewNerd standard) if auth_header.startswith('ApiKey '): api_key_value = auth_header[7:] # Strip "ApiKey " prefix else: # Support raw key for backward compatibility api_key_value = auth_header try: api_key = APIKey.objects.get(key=api_key_value, is_active=True) except APIKey.DoesNotExist: raise AuthenticationFailed('Invalid API key') return (api_key.user, None)