# Distill Context Bundle

Schema: distill-lock/v0

<!-- distill-lock/v0 chunk=0 path="auth.py" start=0 end=266 sha256=749ae2fdc4a479973e00d7642e27039c758a93e1eefc15b16ee3aacf51018f37 -->
"""Fixture authentication: two public test identities, no production credentials."""


def authenticate(header):
    return {
        "Bearer fixture-user-one": {"tenant": "tenant-one"},
        "Bearer fixture-user-two": {"tenant": "tenant-two"},
    }.get(header)

<!-- /distill-lock/v0 -->

<!-- distill-lock/v0 chunk=1 path="repository.py" start=0 end=187 sha256=84e969d18a1a139632b04f72dceffaf63d21af258ed5ff9ab6783f075edb1d67 -->
"""The record lookup under review."""


def lookup(db, record_id, tenant):
    return db.execute(
        "SELECT value FROM records WHERE id = ?",
        (record_id,),
    ).fetchone()

<!-- /distill-lock/v0 -->

<!-- distill-lock/v0 chunk=2 path="server.py" start=0 end=1669 sha256=339aee0bfb25b915721204a1420e6d0fcddc51c09362615f5045ffc4c8e7ca8e -->
"""Constructed local study application. Marker data and credentials are public."""
import json
import sqlite3
from http.server import BaseHTTPRequestHandler, HTTPServer

from auth import authenticate
from repository import lookup


class Handler(BaseHTTPRequestHandler):
    def do_GET(self):
        actor = authenticate(self.headers.get("Authorization", ""))
        if actor is None:
            self.reply(401, {"error": "authentication required"})
            return
        if not self.path.startswith("/records/"):
            self.reply(404, {"error": "not found"})
            return
        record_id = self.path.removeprefix("/records/")
        db = sqlite3.connect(":memory:")
        db.execute("CREATE TABLE records (id TEXT, tenant TEXT, value TEXT)")
        db.executemany("INSERT INTO records VALUES (?, ?, ?)", [
            ("r1", "tenant-one", "public-marker-one"),
            ("r2", "tenant-two", "public-marker-two"),
        ])
        try:
            row = lookup(db, record_id, actor["tenant"])
        finally:
            db.close()
        self.reply(200, {"value": row[0]}) if row else self.reply(404, {"error": "not found"})

    def reply(self, status, body):
        data = json.dumps(body).encode()
        self.send_response(status)
        self.send_header("Content-Type", "application/json")
        self.send_header("Content-Length", str(len(data)))
        self.end_headers()
        self.wfile.write(data)

    def log_message(self, *_args):
        pass


if __name__ == "__main__":
    server = HTTPServer(("127.0.0.1", 0), Handler)
    print(json.dumps({"port": server.server_port}), flush=True)
    server.serve_forever()

<!-- /distill-lock/v0 -->

