Updated backend auth settings
This commit is contained in:
@@ -14,6 +14,10 @@ user table, no registration flow and no password reset, and inventing one here
|
||||
would be a bigger change than the problem calls for. Machine consumers get
|
||||
API_KEYS instead. If per-user accounts become a real requirement, this module
|
||||
is the seam to replace.
|
||||
|
||||
For local work there is AUTH_ALLOW_ANY_LOGIN, which skips the password check
|
||||
here and nowhere else - the token still gets signed and every guard downstream
|
||||
still checks it. It is off by default and logs a warning at startup when on.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
@@ -35,6 +39,7 @@ from app.infrastructure.security import (
|
||||
from app.infrastructure.settings import (
|
||||
AUTH_ADMIN_PASSWORD_HASH,
|
||||
AUTH_ADMIN_USERNAME,
|
||||
AUTH_ALLOW_ANY_LOGIN,
|
||||
AUTH_ENABLED,
|
||||
AUTH_LOCKOUT_SECONDS,
|
||||
AUTH_MAX_LOGIN_ATTEMPTS,
|
||||
@@ -45,6 +50,13 @@ from app.infrastructure.settings import (
|
||||
logger = logging.getLogger(__name__)
|
||||
router = APIRouter(prefix="/auth", tags=["auth"])
|
||||
|
||||
if AUTH_ENABLED and AUTH_ALLOW_ANY_LOGIN:
|
||||
logger.warning(
|
||||
"AUTH_ALLOW_ANY_LOGIN=true: /api/auth/login accepts ANY password, so anyone "
|
||||
"who can reach this port can sign in as admin. Local development only - "
|
||||
"set it to false in backend/.env before exposing this server."
|
||||
)
|
||||
|
||||
|
||||
class LoginRequest(BaseModel):
|
||||
username: str = Field(min_length=1, max_length=150)
|
||||
@@ -168,24 +180,42 @@ def login(payload: LoginRequest, request: Request) -> LoginResponse:
|
||||
|
||||
username = payload.username.strip().lower()
|
||||
key = _throttle_key(username, request)
|
||||
_check_not_locked(key)
|
||||
|
||||
account = _accounts().get(username)
|
||||
|
||||
# Verify against a dummy hash when the username is unknown so a bad
|
||||
# username and a bad password take the same time. Otherwise the response
|
||||
# latency alone enumerates valid usernames.
|
||||
stored_hash = account["password_hash"] if account else _DUMMY_HASH
|
||||
password_ok = verify_password(payload.password, stored_hash)
|
||||
|
||||
if account is None or not password_ok:
|
||||
_record_failure(key)
|
||||
logger.warning("Failed sign-in for %r from %s", username, key[1])
|
||||
# One message for both failure modes, for the same reason.
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid username or password.",
|
||||
if AUTH_ALLOW_ANY_LOGIN:
|
||||
# Dev bypass: any password gets in. The username still picks the
|
||||
# account, so `admin` lands on the admin pages and `user` on the user
|
||||
# ones; anything else is an unconfigured name and gets the lower of the
|
||||
# two roles rather than silently minting an admin. Throttling is skipped
|
||||
# because there is no longer a password to guess.
|
||||
account = _accounts().get(username) or {
|
||||
"role": "user",
|
||||
"display_name": payload.username.strip() or username,
|
||||
"email": f"{username}@nutritionintel.com",
|
||||
}
|
||||
logger.warning(
|
||||
"AUTH_ALLOW_ANY_LOGIN: signing in %r as %s without checking the password",
|
||||
username,
|
||||
account["role"],
|
||||
)
|
||||
else:
|
||||
_check_not_locked(key)
|
||||
|
||||
account = _accounts().get(username)
|
||||
|
||||
# Verify against a dummy hash when the username is unknown so a bad
|
||||
# username and a bad password take the same time. Otherwise the response
|
||||
# latency alone enumerates valid usernames.
|
||||
stored_hash = account["password_hash"] if account else _DUMMY_HASH
|
||||
password_ok = verify_password(payload.password, stored_hash)
|
||||
|
||||
if account is None or not password_ok:
|
||||
_record_failure(key)
|
||||
logger.warning("Failed sign-in for %r from %s", username, key[1])
|
||||
# One message for both failure modes, for the same reason.
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid username or password.",
|
||||
)
|
||||
|
||||
_clear_failures(key)
|
||||
role = account["role"]
|
||||
|
||||
@@ -180,6 +180,22 @@ AUTH_USER_PASSWORD_HASH = (
|
||||
AUTH_MAX_LOGIN_ATTEMPTS = int(os.getenv("AUTH_MAX_LOGIN_ATTEMPTS", "10"))
|
||||
AUTH_LOCKOUT_SECONDS = int(os.getenv("AUTH_LOCKOUT_SECONDS", "300"))
|
||||
|
||||
# Local-development escape hatch: accept ANY password at /api/auth/login, so a
|
||||
# developer who does not have the configured passwords to hand can still reach
|
||||
# the admin and user pages. The username still selects the role, and the token
|
||||
# issued is a normal signed one - so every downstream guard, /api/auth/me, and
|
||||
# the React route gating all behave exactly as they do in production. What is
|
||||
# skipped is only the password check.
|
||||
#
|
||||
# This is NOT the same as AUTH_ENABLED=false. That disables every guard *and*
|
||||
# makes /api/auth/login return 503, which breaks the login page outright. This
|
||||
# flag keeps the whole auth machinery running and unlocks just the front door.
|
||||
#
|
||||
# Anyone who can reach the API can sign in as admin while it is on. Keep it
|
||||
# false anywhere the port is reachable by someone you would not hand the admin
|
||||
# password to.
|
||||
AUTH_ALLOW_ANY_LOGIN = _bool("AUTH_ALLOW_ANY_LOGIN", "false")
|
||||
|
||||
|
||||
def _parse_api_keys(raw: str) -> dict:
|
||||
"""
|
||||
|
||||
Reference in New Issue
Block a user