Production Login page passcode updates

This commit is contained in:
sriram
2026-08-24 22:55:06 +05:30
parent 2482fe43e3
commit 1b347f91db
11 changed files with 878 additions and 67 deletions

View File

@@ -20,7 +20,12 @@ from fastapi.staticfiles import StaticFiles
from fastapi.responses import FileResponse
from app.infrastructure.persistence import restore_bundled_assets
from app.infrastructure.settings import API_CORS_ORIGINS, BRAND_SYNC_INTERVAL_SECONDS
from app.infrastructure.settings import (
API_CORS_ORIGINS,
BRAND_SYNC_INTERVAL_SECONDS,
cleaned_env_names,
)
from app.infrastructure.security import auth_config_summary
from app.api.routers import health, brands, search, suggest, chat, catalog, system
from app.api.routers import stores, discounts, analytics as store_analytics, trending, recommendations, store_admin
from app.api.routers import nutrition, nutrition_admin, upload
@@ -186,6 +191,55 @@ if API_CORS_ORIGINS and all(
", ".join(API_CORS_ORIGINS),
)
# The same argument as the CORS block above, for the other setting whose
# misconfiguration is invisible from the outside. A wrong credential fails only
# as "Invalid username or password.", which is indistinguishable from a user
# mistyping - so state what the process actually loaded, at startup, where it
# can be compared against the config the image was built from.
#
# No password and no hash is printed. `fingerprint` identifies WHICH credential
# is loaded (see security.password_hash_fingerprint); `source` says whether it
# came from the container's environment or from the .env file, which is the
# only way to notice a deployment platform's Environment tab overriding the
# image. Compare against: python scripts/make_auth_secrets.py --fingerprint
_auth_cfg = auth_config_summary()
logger.info(
"Auth config: enabled=%s allow_any_login=%s admin_username=%r "
"hash=%s/%s fingerprint=%s source=%s (username source=%s)",
_auth_cfg["enabled"],
_auth_cfg["allow_any_login"],
_auth_cfg["admin_username"],
"pbkdf2_sha256" if _auth_cfg["password_hash_valid"] else "INVALID",
_auth_cfg["password_hash_iterations"],
_auth_cfg["password_hash_fingerprint"] or "(none)",
_auth_cfg["password_hash_source"],
_auth_cfg["admin_username_source"],
)
if cleaned_env_names():
logger.warning(
"These settings arrived wrapped in quotes or padded with whitespace and were "
"cleaned before use: %s. Pasting into a deployment platform's Environment tab "
"is the usual source. They work now, but the next value may not - store them "
"unquoted.",
", ".join(cleaned_env_names()),
)
if _auth_cfg["enabled"] and _auth_cfg["password_hash_source"] == "process-env":
logger.warning(
"AUTH_ADMIN_PASSWORD_HASH came from the process environment, which OVERRIDES "
"the .env file (load_dotenv is called without override=True). Under "
"docker-compose that is just `env_file:` and is expected. Under Dokploy it "
"means the service's Environment tab is supplying this credential and the one "
"baked into the image by `COPY .env.production .env` is being ignored - which "
"is how a corrected password keeps failing after a redeploy."
)
if _auth_cfg["enabled"] and not _auth_cfg["password_hash_valid"]:
logger.error(
"AUTH_ADMIN_PASSWORD_HASH is not a usable PBKDF2 digest, so EVERY sign-in "
"will return 401 no matter which password is typed. It came from %s. "
"Regenerate it with: python scripts/make_auth_secrets.py",
_auth_cfg["password_hash_source"],
)
app.include_router(health.router, prefix="/api")
app.include_router(auth.router, prefix="/api")
app.include_router(user_products.router, prefix="/api")