backend update auth settings and add brand catalogs

This commit is contained in:
sriram
2026-08-18 12:21:37 +05:30
parent dba8d36175
commit 691efef880
14 changed files with 8544 additions and 19 deletions

View File

@@ -32,16 +32,18 @@ API_CORS_ORIGINS=https://catalouge.nearle.ai.in,https://catalogue.nearle.ai.in
# --- Authentication --------------------------------------------------------
AUTH_ENABLED=true
# Freshly generated for this deployment - deliberately NOT the values from the
# development .env. Those hashes are for the passwords DevAdmin!2026 and
# DevUser!2026, which are sitting in plaintext in test_login_fix.py in this very
# repository: shipping them would publish working admin credentials.
# Sign-in passwords for the hashes below are in SIGNIN_PASSWORDS.txt (ignored).
# One interactive account: admin. The `user` account is disabled here by
# leaving AUTH_USER_PASSWORD_HASH unset - auth.py omits any account whose
# hash is empty, so only admin can sign in.
#
# AUTH_SECRET_KEY stays as generated for this deployment; rotating it would
# invalidate every token already issued.
# Sign-in password for the hash below: admin / admin123.
AUTH_SECRET_KEY=4Kmyr4Cjf_kdUIq_4EGxo5vFHfCT5_uKVR3eouszB8Le6F0n45m7eDY94_KJoqSz
AUTH_ADMIN_USERNAME=admin
AUTH_ADMIN_PASSWORD_HASH=pbkdf2_sha256$600000$JeTFySgfgNNcd0sYqOnrBg==$nqhgalX0wypGX+4jbvgUWayw2EEBQDiTfVfpw+cvIRQ=
AUTH_USER_USERNAME=user
AUTH_USER_PASSWORD_HASH=pbkdf2_sha256$600000$pUXRgFihWosQV06SbAyyng==$+elFMl9LuHg9npxRykMhGbbUYuGv5i6x7B6PqHnblsg=
AUTH_ADMIN_PASSWORD_HASH=pbkdf2_sha256$600000$S28AccXqQnNNElilb0JFsg==$IGPLr56iqwkwbrM5skVoXBMDFEfpZIKUA7NiaM74cmk=
# AUTH_USER_USERNAME=user
# AUTH_USER_PASSWORD_HASH= (unset: the `user` account is disabled)
AUTH_TOKEN_TTL_MINUTES=720
AUTH_MAX_LOGIN_ATTEMPTS=10