This document guides you through setting up the DBAB API to support the Discord Bot Dashboard.
- ✅ Discord OAuth2 Authentication
- ✅ JWT Token-based Authentication
- ✅ Guild Management (Server tracking)
- ✅ Enhanced Appeal Management with Dashboard Routes
- ✅ User Account Management
New tables have been added to support the dashboard:
Stores Discord user information for dashboard access.
CREATE TABLE users (
id VARCHAR PRIMARY KEY,
discord_id VARCHAR UNIQUE NOT NULL,
discord_tag VARCHAR NOT NULL,
avatar VARCHAR,
email VARCHAR,
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
updated_at DATETIME DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
);Stores guild (server) information linked to users.
CREATE TABLE guilds (
id VARCHAR PRIMARY KEY,
name VARCHAR NOT NULL,
icon VARCHAR,
owner_id VARCHAR NOT NULL,
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
updated_at DATETIME DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
);Added new fields for dashboard support:
ALTER TABLE appeals ADD COLUMN status VARCHAR DEFAULT 'pending';
ALTER TABLE appeals ADD COLUMN response TEXT;
ALTER TABLE appeals ADD COLUMN userDiscordTag VARCHAR;Edit ~/.dbab-config/dbab.json and add the following:
{
"bot": {
"token": "your_bot_token_here"
},
"mysql": {
"host": "localhost",
"user": "root",
"password": "your_password",
"database": "dbab_bot",
"port": 3306
},
"discord": {
"client_id": "YOUR_DISCORD_APP_ID",
"client_secret": "YOUR_DISCORD_APP_SECRET",
"redirect_uri": "http://localhost:5173/auth/discord/callback"
},
"jwt": {
"secret": "your_very_secret_jwt_key_change_this"
}
}- Go to Discord Developer Portal
- Click "New Application" and name it
- Go to "OAuth2" → "General"
- Copy your Client ID and Client Secret
- Add Redirect URI:
http://localhost:5173/auth/discord/callback - Add them to your config file
pip install -r requirements.txtThe following packages were added:
PyJWT==2.8.1- For JWT token generationaiohttp==3.9.1- For Discord API requestspython-dotenv==1.0.0- For environment variables
Returns the Discord OAuth authorization URL
- Auth: None (Public)
- Response:
{ "url": "https://discord.com/api/oauth2/authorize?..." }
Handles Discord OAuth callback
- Auth: None (Public)
- Body:
{ "code": "oauth_code" } - Response:
{ "token": "jwt_token", "user": {...} }
Get current authenticated user
- Auth: Bearer token (JWT)
- Response: User object with ID, Discord tag, avatar, etc.
Get all guilds owned by current user
- Auth: Bearer token (JWT)
- Response: Array of guild objects
Get specific guild details
- Auth: Bearer token (JWT)
- Response: Guild object
Get appeal statistics for a guild
- Auth: Bearer token (JWT)
- Response: Stats object with total, pending, approved, denied counts
Get all appeals for user's guilds
- Auth: Bearer token (JWT)
- Response: Array of appeal objects
Get all appeals for a specific guild
- Auth: Bearer token (JWT)
- Response: Array of appeal objects
Get specific appeal details
- Auth: Bearer token (JWT)
- Response: Appeal object with all details
Update appeal status (approve/deny)
- Auth: Bearer token (JWT)
- Body:
{ "status": "approved|denied", "reason": "response_message" } - Response: Updated appeal object
- User clicks "Login with Discord" in dashboard
- API returns Discord auth URL via
/auth/discord-auth-url - User authorizes Discord app and is redirected to callback
- Dashboard exchanges code for token via
/auth/discord-callback - API validates code with Discord servers
- User data retrieved from Discord and stored in database
- JWT token generated and returned to dashboard
- Dashboard stores token in localStorage
- All subsequent requests include JWT in Authorization header
For authenticated requests, include the JWT token:
Authorization: Bearer <your_jwt_token_here>
If you get CORS errors, the API already has CORS configured for all origins. Clear browser cache and try again.
- Verify Client ID and Secret are correct
- Check that redirect URI exactly matches config and Discord settings
- Ensure redirect_uri starts with
http://(nothttps://for localhost)
Run these migrations to ensure tables exist:
-- Create users table if missing
CREATE TABLE IF NOT EXISTS users (
id VARCHAR(255) PRIMARY KEY,
discord_id VARCHAR(255) UNIQUE NOT NULL,
discord_tag VARCHAR(255) NOT NULL,
avatar VARCHAR(255),
email VARCHAR(255),
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
updated_at DATETIME DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
);
-- Create guilds table if missing
CREATE TABLE IF NOT EXISTS guilds (
id VARCHAR(255) PRIMARY KEY,
name VARCHAR(255) NOT NULL,
icon VARCHAR(255),
owner_id VARCHAR(255) NOT NULL,
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
updated_at DATETIME DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
);
-- Add missing columns to appeals
ALTER TABLE appeals ADD COLUMN IF NOT EXISTS status VARCHAR(50) DEFAULT 'pending';
ALTER TABLE appeals ADD COLUMN IF NOT EXISTS response TEXT;
ALTER TABLE appeals ADD COLUMN IF NOT EXISTS userDiscordTag VARCHAR(255);- Clear localStorage in the dashboard (DevTools → Application → Storage)
- Re-login through Discord OAuth
- Ensure JWT secret in config is consistent
python main.pyThe API will start on http://localhost:3000 and the dashboard on http://localhost:5173.
- Change the JWT secret in production (
jwt.secretin config) - Use HTTPS in production
- Never commit config files with secrets
- Keep Discord credentials private
- Validate all user input on the backend
The DBAB Dashboard is pre-configured to work with these endpoints. To connect:
- Ensure API is running on http://localhost:3000
- Start dashboard:
npm run devin the DBAB-APP folder - Visit http://localhost:5173
- Click "Login with Discord"
The dashboard will automatically handle all OAuth flows and token management.