Production Login page passcode updates
This commit is contained in:
56
app/main.py
56
app/main.py
@@ -20,7 +20,12 @@ from fastapi.staticfiles import StaticFiles
|
||||
from fastapi.responses import FileResponse
|
||||
|
||||
from app.infrastructure.persistence import restore_bundled_assets
|
||||
from app.infrastructure.settings import API_CORS_ORIGINS, BRAND_SYNC_INTERVAL_SECONDS
|
||||
from app.infrastructure.settings import (
|
||||
API_CORS_ORIGINS,
|
||||
BRAND_SYNC_INTERVAL_SECONDS,
|
||||
cleaned_env_names,
|
||||
)
|
||||
from app.infrastructure.security import auth_config_summary
|
||||
from app.api.routers import health, brands, search, suggest, chat, catalog, system
|
||||
from app.api.routers import stores, discounts, analytics as store_analytics, trending, recommendations, store_admin
|
||||
from app.api.routers import nutrition, nutrition_admin, upload
|
||||
@@ -186,6 +191,55 @@ if API_CORS_ORIGINS and all(
|
||||
", ".join(API_CORS_ORIGINS),
|
||||
)
|
||||
|
||||
# The same argument as the CORS block above, for the other setting whose
|
||||
# misconfiguration is invisible from the outside. A wrong credential fails only
|
||||
# as "Invalid username or password.", which is indistinguishable from a user
|
||||
# mistyping - so state what the process actually loaded, at startup, where it
|
||||
# can be compared against the config the image was built from.
|
||||
#
|
||||
# No password and no hash is printed. `fingerprint` identifies WHICH credential
|
||||
# is loaded (see security.password_hash_fingerprint); `source` says whether it
|
||||
# came from the container's environment or from the .env file, which is the
|
||||
# only way to notice a deployment platform's Environment tab overriding the
|
||||
# image. Compare against: python scripts/make_auth_secrets.py --fingerprint
|
||||
_auth_cfg = auth_config_summary()
|
||||
logger.info(
|
||||
"Auth config: enabled=%s allow_any_login=%s admin_username=%r "
|
||||
"hash=%s/%s fingerprint=%s source=%s (username source=%s)",
|
||||
_auth_cfg["enabled"],
|
||||
_auth_cfg["allow_any_login"],
|
||||
_auth_cfg["admin_username"],
|
||||
"pbkdf2_sha256" if _auth_cfg["password_hash_valid"] else "INVALID",
|
||||
_auth_cfg["password_hash_iterations"],
|
||||
_auth_cfg["password_hash_fingerprint"] or "(none)",
|
||||
_auth_cfg["password_hash_source"],
|
||||
_auth_cfg["admin_username_source"],
|
||||
)
|
||||
if cleaned_env_names():
|
||||
logger.warning(
|
||||
"These settings arrived wrapped in quotes or padded with whitespace and were "
|
||||
"cleaned before use: %s. Pasting into a deployment platform's Environment tab "
|
||||
"is the usual source. They work now, but the next value may not - store them "
|
||||
"unquoted.",
|
||||
", ".join(cleaned_env_names()),
|
||||
)
|
||||
if _auth_cfg["enabled"] and _auth_cfg["password_hash_source"] == "process-env":
|
||||
logger.warning(
|
||||
"AUTH_ADMIN_PASSWORD_HASH came from the process environment, which OVERRIDES "
|
||||
"the .env file (load_dotenv is called without override=True). Under "
|
||||
"docker-compose that is just `env_file:` and is expected. Under Dokploy it "
|
||||
"means the service's Environment tab is supplying this credential and the one "
|
||||
"baked into the image by `COPY .env.production .env` is being ignored - which "
|
||||
"is how a corrected password keeps failing after a redeploy."
|
||||
)
|
||||
if _auth_cfg["enabled"] and not _auth_cfg["password_hash_valid"]:
|
||||
logger.error(
|
||||
"AUTH_ADMIN_PASSWORD_HASH is not a usable PBKDF2 digest, so EVERY sign-in "
|
||||
"will return 401 no matter which password is typed. It came from %s. "
|
||||
"Regenerate it with: python scripts/make_auth_secrets.py",
|
||||
_auth_cfg["password_hash_source"],
|
||||
)
|
||||
|
||||
app.include_router(health.router, prefix="/api")
|
||||
app.include_router(auth.router, prefix="/api")
|
||||
app.include_router(user_products.router, prefix="/api")
|
||||
|
||||
Reference in New Issue
Block a user