#!/usr/bin/env python3
"""One-command start (GOV-B7.4): python3 run.py [--host 127.0.0.1] [--port 8000] [--engine glm|stub]
First run prints the generated admin password ONCE and stores its scrypt hash in
users.json (delete users.json to re-seed, or set ADMIN_USER / ADMIN_PASS before the
first run). The GLM engine needs GLM_API_KEY in the ENVIRONMENT — never a file.
"""
import argparse
import os
import sys
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
import app as webapp # noqa: E402 — ONE store, shared with the handler
def main() -> int:
parser = argparse.ArgumentParser(description="Governed reference web application")
parser.add_argument("--host", default="127.0.0.1")
parser.add_argument("--port", type=int, default=8000)
parser.add_argument("--engine", choices=["glm", "stub"], default="glm",
help="glm = real engine (needs GLM_API_KEY env); stub = offline echo for tests/demo")
args = parser.parse_args()
one_time = webapp.store.ensure_admin() # the SAME UserStore the request handler checks against
if one_time:
print("=" * 64)
print(f"FIRST RUN — admin account '{os.environ.get('ADMIN_USER', 'admin')}' created.")
print(f"One-time password: {one_time}")
print("It is not stored in plaintext anywhere; it will not be shown again.")
print("=" * 64)
if args.engine == "glm" and not os.environ.get("GLM_API_KEY"):
print("NOTE: GLM_API_KEY is not set — /api/chat will return an engine error until it is.")
print(" Set it in the server environment (never in a file). Use --engine stub to try without a key.")
webapp.serve(args.host, args.port, args.engine)
return 0
if __name__ == "__main__":
raise SystemExit(main())