backend update auth settings and add brand catalogs
This commit is contained in:
@@ -94,21 +94,31 @@ def _accounts() -> Dict[str, dict]:
|
||||
Usernames are compared case-insensitively (matching what the login form
|
||||
sends), but the password is not touched - the previous version lowercased
|
||||
it before comparing, which silently shrank the effective keyspace.
|
||||
|
||||
An account with a blank password hash is omitted entirely rather than
|
||||
included with an unmatchable digest. Both spellings deny the login, but
|
||||
only omission keeps it out of the account table, so nothing downstream can
|
||||
treat it as a real account. This is how the optional `user` account is
|
||||
switched off: leave AUTH_USER_PASSWORD_HASH unset and only `admin` exists.
|
||||
"""
|
||||
return {
|
||||
accounts = {
|
||||
AUTH_ADMIN_USERNAME.lower(): {
|
||||
"password_hash": AUTH_ADMIN_PASSWORD_HASH,
|
||||
"role": "admin",
|
||||
"display_name": "System Administrator",
|
||||
"email": "admin@nutritionintel.com",
|
||||
},
|
||||
AUTH_USER_USERNAME.lower(): {
|
||||
}
|
||||
|
||||
if AUTH_USER_PASSWORD_HASH:
|
||||
accounts[AUTH_USER_USERNAME.lower()] = {
|
||||
"password_hash": AUTH_USER_PASSWORD_HASH,
|
||||
"role": "user",
|
||||
"display_name": "Product & Store Manager",
|
||||
"email": "user@nutritionintel.com",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
return accounts
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user