feat: configure Kanban login by operator email
All checks were successful
Build and deploy / Validate source (push) Successful in 13s
Build and deploy / Publish images and notify Portainer (push) Successful in 1m2s

This commit is contained in:
Cauê Faleiros
2026-09-18 12:54:04 -03:00
parent 9d348ca893
commit 508fa03664
14 changed files with 59 additions and 48 deletions

View File

@@ -49,8 +49,9 @@ app.add_middleware(TrustedHostMiddleware, allowed_hosts=ALLOWED_HOSTS)
@app.post('/api/operator/login')
def operator_login(body: OperatorLogin, request: Request, response: Response):
throttle('operator:'+body.username, request)
valid_user = secrets.compare_digest(body.username.encode(), os.environ['OPERATOR_USER'].encode())
email = body.email
throttle('operator:'+email, request)
valid_user = secrets.compare_digest(email.encode(), os.environ['OPERATOR_EMAIL'].strip().lower().encode())
valid_password = secrets.compare_digest(body.password.encode(), os.environ['OPERATOR_PASSWORD'].encode())
if not (valid_user and valid_password):
audit('operator_login_failed')
@@ -60,10 +61,10 @@ def operator_login(body: OperatorLogin, request: Request, response: Response):
previous = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest()
c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (previous,))
c.execute('INSERT INTO dtf_local.operator_sessions(token_hash,username) VALUES(%s,%s)',
(hashlib.sha256(token.encode()).hexdigest(), body.username))
(hashlib.sha256(token.encode()).hexdigest(), email))
response.set_cookie('dtf_operator', token, httponly=True, secure=COOKIE_SECURE,
samesite='strict', path='/api/operator', max_age=28800)
audit('operator_login_success', operator=body.username)
audit('operator_login_success', operator=email)
return {'ok': True}
@app.post('/api/operator/logout')