"""Shared JSON envelope helpers (Chapter 11). Every existing /api/... endpoint already hand-builds this exact shape via jsonify(data=..., meta=...) — audited for compliance in docs/api-contract- final.md. This module exists so NEW endpoints (e.g. this chapter's unauthorized_handler) have one call site instead of re-typing the shape. """ from __future__ import annotations from flask import jsonify def api_ok(data, meta: dict | None = None): return jsonify(data=data, meta=meta or {}) def api_error(code: str, message: str, status: int): return jsonify(error={"code": code, "message": message}), status