fix: restore session creation broken by missing import

local/auth.py used os.environ without importing os, so new_session raised
NameError. Every first visit to /api/session, every registration and every
login returned 500, which left Site checkout, cart recovery and the customer
portal unusable since the R2 stack change.

Read COOKIE_SECURE once as a module constant and share it with local/app.py
instead of resolving the same variable in two places.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-18 18:32:17 -03:00
parent 99fd92bdb8
commit 9046ec6db0
2 changed files with 5 additions and 4 deletions

View File

@@ -17,7 +17,7 @@ from . import db
from .adapters import FakeFreight, FakePayment, LocalS3Storage, require_runtime
from .models import Freight, Move, Pay, QuoteRequest, Review, UploadStart, OperatorLogin
from .pricing import price
from .auth import owner, session_row, new_session, operator, throttle, audit, rate_limit
from .auth import COOKIE_SECURE, owner, session_row, new_session, operator, throttle, audit, rate_limit
from .scanning import require_clean
require_runtime()
@@ -28,7 +28,6 @@ ENVIRONMENT = os.environ.get('APP_ENV', 'local')
PUBLIC_ORIGIN = os.environ.get('PUBLIC_ORIGIN', 'http://localhost')
ALLOWED_HOSTS = [host for host in os.environ.get('ALLOWED_HOSTS', 'localhost,127.0.0.1').split(',') if host]
ALLOWED_ORIGINS = [origin for origin in os.environ.get('ALLOWED_ORIGINS', PUBLIC_ORIGIN).split(',') if origin]
COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true'
PART_BYTES = int(os.environ.get('UPLOAD_PART_BYTES', '8388608'))
if not 5242880 <= PART_BYTES <= 67108864:
raise RuntimeError('UPLOAD_PART_BYTES must be between 5 and 64 MiB')

View File

@@ -1,5 +1,6 @@
"""Local customer passwords and revocable database sessions. No email service."""
import hashlib
import os
import secrets
import logging
import json
@@ -7,6 +8,8 @@ from uuid import UUID, uuid4
from fastapi import HTTPException, Request
from .db import connect
COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true'
def password_hash(password, salt=None):
salt = salt or secrets.token_hex(16)
digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex()
@@ -42,8 +45,7 @@ def new_session(c, response, identity=None):
sid = uuid4()
identity = identity or uuid4()
c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity))
response.set_cookie('dtf_session', str(sid), httponly=True,
secure=os.environ.get('COOKIE_SECURE', 'false').lower() == 'true',
response.set_cookie('dtf_session', str(sid), httponly=True, secure=COOKIE_SECURE,
samesite='strict', max_age=86400*7)
return identity