Updated backend auth settings
This commit is contained in:
@@ -14,6 +14,10 @@ user table, no registration flow and no password reset, and inventing one here
|
||||
would be a bigger change than the problem calls for. Machine consumers get
|
||||
API_KEYS instead. If per-user accounts become a real requirement, this module
|
||||
is the seam to replace.
|
||||
|
||||
For local work there is AUTH_ALLOW_ANY_LOGIN, which skips the password check
|
||||
here and nowhere else - the token still gets signed and every guard downstream
|
||||
still checks it. It is off by default and logs a warning at startup when on.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
@@ -35,6 +39,7 @@ from app.infrastructure.security import (
|
||||
from app.infrastructure.settings import (
|
||||
AUTH_ADMIN_PASSWORD_HASH,
|
||||
AUTH_ADMIN_USERNAME,
|
||||
AUTH_ALLOW_ANY_LOGIN,
|
||||
AUTH_ENABLED,
|
||||
AUTH_LOCKOUT_SECONDS,
|
||||
AUTH_MAX_LOGIN_ATTEMPTS,
|
||||
@@ -45,6 +50,13 @@ from app.infrastructure.settings import (
|
||||
logger = logging.getLogger(__name__)
|
||||
router = APIRouter(prefix="/auth", tags=["auth"])
|
||||
|
||||
if AUTH_ENABLED and AUTH_ALLOW_ANY_LOGIN:
|
||||
logger.warning(
|
||||
"AUTH_ALLOW_ANY_LOGIN=true: /api/auth/login accepts ANY password, so anyone "
|
||||
"who can reach this port can sign in as admin. Local development only - "
|
||||
"set it to false in backend/.env before exposing this server."
|
||||
)
|
||||
|
||||
|
||||
class LoginRequest(BaseModel):
|
||||
username: str = Field(min_length=1, max_length=150)
|
||||
@@ -168,24 +180,42 @@ def login(payload: LoginRequest, request: Request) -> LoginResponse:
|
||||
|
||||
username = payload.username.strip().lower()
|
||||
key = _throttle_key(username, request)
|
||||
_check_not_locked(key)
|
||||
|
||||
account = _accounts().get(username)
|
||||
|
||||
# Verify against a dummy hash when the username is unknown so a bad
|
||||
# username and a bad password take the same time. Otherwise the response
|
||||
# latency alone enumerates valid usernames.
|
||||
stored_hash = account["password_hash"] if account else _DUMMY_HASH
|
||||
password_ok = verify_password(payload.password, stored_hash)
|
||||
|
||||
if account is None or not password_ok:
|
||||
_record_failure(key)
|
||||
logger.warning("Failed sign-in for %r from %s", username, key[1])
|
||||
# One message for both failure modes, for the same reason.
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid username or password.",
|
||||
if AUTH_ALLOW_ANY_LOGIN:
|
||||
# Dev bypass: any password gets in. The username still picks the
|
||||
# account, so `admin` lands on the admin pages and `user` on the user
|
||||
# ones; anything else is an unconfigured name and gets the lower of the
|
||||
# two roles rather than silently minting an admin. Throttling is skipped
|
||||
# because there is no longer a password to guess.
|
||||
account = _accounts().get(username) or {
|
||||
"role": "user",
|
||||
"display_name": payload.username.strip() or username,
|
||||
"email": f"{username}@nutritionintel.com",
|
||||
}
|
||||
logger.warning(
|
||||
"AUTH_ALLOW_ANY_LOGIN: signing in %r as %s without checking the password",
|
||||
username,
|
||||
account["role"],
|
||||
)
|
||||
else:
|
||||
_check_not_locked(key)
|
||||
|
||||
account = _accounts().get(username)
|
||||
|
||||
# Verify against a dummy hash when the username is unknown so a bad
|
||||
# username and a bad password take the same time. Otherwise the response
|
||||
# latency alone enumerates valid usernames.
|
||||
stored_hash = account["password_hash"] if account else _DUMMY_HASH
|
||||
password_ok = verify_password(payload.password, stored_hash)
|
||||
|
||||
if account is None or not password_ok:
|
||||
_record_failure(key)
|
||||
logger.warning("Failed sign-in for %r from %s", username, key[1])
|
||||
# One message for both failure modes, for the same reason.
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_401_UNAUTHORIZED,
|
||||
detail="Invalid username or password.",
|
||||
)
|
||||
|
||||
_clear_failures(key)
|
||||
role = account["role"]
|
||||
|
||||
Reference in New Issue
Block a user