diff --git a/local/app.py b/local/app.py index 1abe977..7476c57 100644 --- a/local/app.py +++ b/local/app.py @@ -17,7 +17,7 @@ from . import db from .adapters import FakeFreight, FakePayment, LocalS3Storage, require_runtime from .models import Freight, Move, Pay, QuoteRequest, Review, UploadStart, OperatorLogin from .pricing import price -from .auth import owner, session_row, new_session, operator, throttle, audit, rate_limit +from .auth import COOKIE_SECURE, owner, session_row, new_session, operator, throttle, audit, rate_limit from .scanning import require_clean require_runtime() @@ -28,7 +28,6 @@ ENVIRONMENT = os.environ.get('APP_ENV', 'local') PUBLIC_ORIGIN = os.environ.get('PUBLIC_ORIGIN', 'http://localhost') ALLOWED_HOSTS = [host for host in os.environ.get('ALLOWED_HOSTS', 'localhost,127.0.0.1').split(',') if host] ALLOWED_ORIGINS = [origin for origin in os.environ.get('ALLOWED_ORIGINS', PUBLIC_ORIGIN).split(',') if origin] -COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true' PART_BYTES = int(os.environ.get('UPLOAD_PART_BYTES', '8388608')) if not 5242880 <= PART_BYTES <= 67108864: raise RuntimeError('UPLOAD_PART_BYTES must be between 5 and 64 MiB') diff --git a/local/auth.py b/local/auth.py index 998d167..cd4bae7 100644 --- a/local/auth.py +++ b/local/auth.py @@ -1,5 +1,6 @@ """Local customer passwords and revocable database sessions. No email service.""" import hashlib +import os import secrets import logging import json @@ -7,6 +8,8 @@ from uuid import UUID, uuid4 from fastapi import HTTPException, Request from .db import connect +COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true' + def password_hash(password, salt=None): salt = salt or secrets.token_hex(16) digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex() @@ -42,8 +45,7 @@ def new_session(c, response, identity=None): sid = uuid4() identity = identity or uuid4() c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity)) - response.set_cookie('dtf_session', str(sid), httponly=True, - secure=os.environ.get('COOKIE_SECURE', 'false').lower() == 'true', + response.set_cookie('dtf_session', str(sid), httponly=True, secure=COOKIE_SECURE, samesite='strict', max_age=86400*7) return identity