feat: configure Kanban login by operator email
This commit is contained in:
@@ -49,8 +49,9 @@ app.add_middleware(TrustedHostMiddleware, allowed_hosts=ALLOWED_HOSTS)
|
||||
|
||||
@app.post('/api/operator/login')
|
||||
def operator_login(body: OperatorLogin, request: Request, response: Response):
|
||||
throttle('operator:'+body.username, request)
|
||||
valid_user = secrets.compare_digest(body.username.encode(), os.environ['OPERATOR_USER'].encode())
|
||||
email = body.email
|
||||
throttle('operator:'+email, request)
|
||||
valid_user = secrets.compare_digest(email.encode(), os.environ['OPERATOR_EMAIL'].strip().lower().encode())
|
||||
valid_password = secrets.compare_digest(body.password.encode(), os.environ['OPERATOR_PASSWORD'].encode())
|
||||
if not (valid_user and valid_password):
|
||||
audit('operator_login_failed')
|
||||
@@ -60,10 +61,10 @@ def operator_login(body: OperatorLogin, request: Request, response: Response):
|
||||
previous = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest()
|
||||
c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (previous,))
|
||||
c.execute('INSERT INTO dtf_local.operator_sessions(token_hash,username) VALUES(%s,%s)',
|
||||
(hashlib.sha256(token.encode()).hexdigest(), body.username))
|
||||
(hashlib.sha256(token.encode()).hexdigest(), email))
|
||||
response.set_cookie('dtf_operator', token, httponly=True, secure=COOKIE_SECURE,
|
||||
samesite='strict', path='/api/operator', max_age=28800)
|
||||
audit('operator_login_success', operator=body.username)
|
||||
audit('operator_login_success', operator=email)
|
||||
return {'ok': True}
|
||||
|
||||
@app.post('/api/operator/logout')
|
||||
|
||||
Reference in New Issue
Block a user