feat: configure Kanban login with optional email
This commit is contained in:
12
local/app.py
12
local/app.py
@@ -49,8 +49,12 @@ app.add_middleware(TrustedHostMiddleware, allowed_hosts=ALLOWED_HOSTS)
|
||||
|
||||
@app.post('/api/operator/login')
|
||||
def operator_login(body: OperatorLogin, request: Request, response: Response):
|
||||
throttle('operator:'+body.username, request)
|
||||
valid_user = secrets.compare_digest(body.username.encode(), os.environ['OPERATOR_USER'].encode())
|
||||
configured_email = os.environ.get('OPERATOR_EMAIL', '').strip().lower()
|
||||
if not configured_email:
|
||||
raise HTTPException(503, 'Kanban operator email is not configured')
|
||||
email = body.email
|
||||
throttle('operator:'+email, request)
|
||||
valid_user = secrets.compare_digest(email.encode(), configured_email.encode())
|
||||
valid_password = secrets.compare_digest(body.password.encode(), os.environ['OPERATOR_PASSWORD'].encode())
|
||||
if not (valid_user and valid_password):
|
||||
audit('operator_login_failed')
|
||||
@@ -60,10 +64,10 @@ def operator_login(body: OperatorLogin, request: Request, response: Response):
|
||||
previous = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest()
|
||||
c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (previous,))
|
||||
c.execute('INSERT INTO dtf_local.operator_sessions(token_hash,username) VALUES(%s,%s)',
|
||||
(hashlib.sha256(token.encode()).hexdigest(), body.username))
|
||||
(hashlib.sha256(token.encode()).hexdigest(), email))
|
||||
response.set_cookie('dtf_operator', token, httponly=True, secure=COOKIE_SECURE,
|
||||
samesite='strict', path='/api/operator', max_age=28800)
|
||||
audit('operator_login_success', operator=body.username)
|
||||
audit('operator_login_success', operator=email)
|
||||
return {'ok': True}
|
||||
|
||||
@app.post('/api/operator/logout')
|
||||
|
||||
Reference in New Issue
Block a user