feat: configure Kanban login with optional email
This commit is contained in:
@@ -28,8 +28,8 @@ def run():
|
||||
print('PASS: CSP, frame protection, Host and cross-origin rejection')
|
||||
|
||||
operator=Client()
|
||||
credentials={'username':os.environ.get('OPERATOR_USER','operator'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')}
|
||||
encoded=base64.b64encode((credentials['username']+':'+credentials['password']).encode()).decode()
|
||||
credentials={'email':os.environ.get('OPERATOR_EMAIL','operator@example.test'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')}
|
||||
encoded=base64.b64encode((credentials['email']+':'+credentials['password']).encode()).decode()
|
||||
raw('/api/operator/board',401,{'Authorization':'Basic '+encoded})
|
||||
operator.call('/operator/login',credentials)
|
||||
token=next(c for c in operator.jar if c.name=='dtf_operator')
|
||||
@@ -58,9 +58,9 @@ def run():
|
||||
print('PASS: extension allowlist, exact multipart Content-Length signature, pending upload quota')
|
||||
|
||||
# Unique identity avoids locking out the real local operator.
|
||||
attacker=Client();username='test-'+uuid4().hex
|
||||
for _ in range(10):attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=401)
|
||||
attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=429)
|
||||
attacker=Client();email='test-'+uuid4().hex+'@example.test'
|
||||
for _ in range(10):attacker.call('/operator/login',{'email':email,'password':'invalid'},expected=401)
|
||||
attacker.call('/operator/login',{'email':email,'password':'invalid'},expected=429)
|
||||
print('PASS: operator login throttling (only synthetic account bucket exhausted)')
|
||||
|
||||
if __name__=='__main__':run()
|
||||
|
||||
Reference in New Issue
Block a user