backend update auth settings and add brand catalogs
This commit is contained in:
@@ -94,21 +94,31 @@ def _accounts() -> Dict[str, dict]:
|
||||
Usernames are compared case-insensitively (matching what the login form
|
||||
sends), but the password is not touched - the previous version lowercased
|
||||
it before comparing, which silently shrank the effective keyspace.
|
||||
|
||||
An account with a blank password hash is omitted entirely rather than
|
||||
included with an unmatchable digest. Both spellings deny the login, but
|
||||
only omission keeps it out of the account table, so nothing downstream can
|
||||
treat it as a real account. This is how the optional `user` account is
|
||||
switched off: leave AUTH_USER_PASSWORD_HASH unset and only `admin` exists.
|
||||
"""
|
||||
return {
|
||||
accounts = {
|
||||
AUTH_ADMIN_USERNAME.lower(): {
|
||||
"password_hash": AUTH_ADMIN_PASSWORD_HASH,
|
||||
"role": "admin",
|
||||
"display_name": "System Administrator",
|
||||
"email": "admin@nutritionintel.com",
|
||||
},
|
||||
AUTH_USER_USERNAME.lower(): {
|
||||
}
|
||||
|
||||
if AUTH_USER_PASSWORD_HASH:
|
||||
accounts[AUTH_USER_USERNAME.lower()] = {
|
||||
"password_hash": AUTH_USER_PASSWORD_HASH,
|
||||
"role": "user",
|
||||
"display_name": "Product & Store Manager",
|
||||
"email": "user@nutritionintel.com",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
return accounts
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
@@ -226,20 +226,24 @@ AUTH_SECRET_KEY = (
|
||||
# working day needs one sign-in, short enough that a leaked token expires.
|
||||
AUTH_TOKEN_TTL_MINUTES = int(os.getenv("AUTH_TOKEN_TTL_MINUTES", "720"))
|
||||
|
||||
# The two interactive accounts. Only PBKDF2 digests are stored - never a
|
||||
# password. `make_auth_secrets.py` prints both lines ready to paste.
|
||||
# The interactive accounts. Only PBKDF2 digests are stored - never a password.
|
||||
# `make_auth_secrets.py` prints the lines ready to paste.
|
||||
#
|
||||
# `admin` is required whenever auth is on: without it nobody could sign in.
|
||||
AUTH_ADMIN_USERNAME = os.getenv("AUTH_ADMIN_USERNAME", "admin")
|
||||
AUTH_ADMIN_PASSWORD_HASH = (
|
||||
_require("AUTH_ADMIN_PASSWORD_HASH", feature_flag="AUTH_ENABLED")
|
||||
if AUTH_ENABLED
|
||||
else os.getenv("AUTH_ADMIN_PASSWORD_HASH", "")
|
||||
)
|
||||
|
||||
# The second `user` account is OPTIONAL, and left unset in this deployment.
|
||||
# An empty hash is how the account is switched off: auth.py builds its account
|
||||
# table from these values and omits any entry whose hash is blank, so there is
|
||||
# nothing to sign in to. Setting the hash again re-enables it with no code
|
||||
# change - which is exactly what the test suite does in tests/conftest.py.
|
||||
AUTH_USER_USERNAME = os.getenv("AUTH_USER_USERNAME", "user")
|
||||
AUTH_USER_PASSWORD_HASH = (
|
||||
_require("AUTH_USER_PASSWORD_HASH", feature_flag="AUTH_ENABLED")
|
||||
if AUTH_ENABLED
|
||||
else os.getenv("AUTH_USER_PASSWORD_HASH", "")
|
||||
)
|
||||
AUTH_USER_PASSWORD_HASH = os.getenv("AUTH_USER_PASSWORD_HASH", "")
|
||||
|
||||
# Failed-login throttle, applied per username+client-IP. Prevents an exposed
|
||||
# login endpoint from being a free password oracle.
|
||||
|
||||
Reference in New Issue
Block a user