Updated backend auth settings
This commit is contained in:
@@ -180,6 +180,22 @@ AUTH_USER_PASSWORD_HASH = (
|
||||
AUTH_MAX_LOGIN_ATTEMPTS = int(os.getenv("AUTH_MAX_LOGIN_ATTEMPTS", "10"))
|
||||
AUTH_LOCKOUT_SECONDS = int(os.getenv("AUTH_LOCKOUT_SECONDS", "300"))
|
||||
|
||||
# Local-development escape hatch: accept ANY password at /api/auth/login, so a
|
||||
# developer who does not have the configured passwords to hand can still reach
|
||||
# the admin and user pages. The username still selects the role, and the token
|
||||
# issued is a normal signed one - so every downstream guard, /api/auth/me, and
|
||||
# the React route gating all behave exactly as they do in production. What is
|
||||
# skipped is only the password check.
|
||||
#
|
||||
# This is NOT the same as AUTH_ENABLED=false. That disables every guard *and*
|
||||
# makes /api/auth/login return 503, which breaks the login page outright. This
|
||||
# flag keeps the whole auth machinery running and unlocks just the front door.
|
||||
#
|
||||
# Anyone who can reach the API can sign in as admin while it is on. Keep it
|
||||
# false anywhere the port is reachable by someone you would not hand the admin
|
||||
# password to.
|
||||
AUTH_ALLOW_ANY_LOGIN = _bool("AUTH_ALLOW_ANY_LOGIN", "false")
|
||||
|
||||
|
||||
def _parse_api_keys(raw: str) -> dict:
|
||||
"""
|
||||
|
||||
Reference in New Issue
Block a user