HKUDS/DeepTutor · error · HTTPException
Auth is disabled — profiles are not available.
Error message
Auth is disabled — profiles are not available.
What it means
Error "Auth is disabled — profiles are not available." thrown in HKUDS/DeepTutor.
Source
Thrown at deeptutor/api/routers/auth.py:602
The uploaded filename and Content-Type are attacker-controlled, so the
stored extension (and the media type served back) is derived from the
bytes alone. SVG is deliberately unsupported — serving user-supplied SVG
is a stored-XSS vector.
"""
if data[:8] == b"\x89PNG\r\n\x1a\n":
return "png"
if data[:3] == b"\xff\xd8\xff":
return "jpg"
if data[:4] == b"RIFF" and data[8:12] == b"WEBP":
return "webp"
return None
def _require_profile_identity(payload: TokenPayload | None) -> TokenPayload:
"""Shared guard for the self-service profile endpoints."""
if not AUTH_ENABLED or payload is None:
raise HTTPException(
status_code=status.HTTP_400_BAD_REQUEST,
detail="Auth is disabled — profiles are not available.",
)
return payload
@router.get("/profile", response_model=UserInfo)
async def get_profile(
payload: TokenPayload | None = Depends(require_auth),
) -> UserInfo:
"""Return the current user's own account info."""
current = _require_profile_identity(payload)
info = get_user_info(current.username)
if info is None:
# PocketBase-backed identities have no local record; fall back to the
# token claims so the profile page still renders.
return UserInfo(
id=current.user_id,View on GitHub (pinned to 3e82f13042)
When it happens
Trigger: Thrown at deeptutor/api/routers/auth.py:602 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of HKUDS/DeepTutor@3e82f13042 (2026-08-27).
Data as JSON: /api/errors/3a2b264375bc5538.
Report an issue: GitHub.