fix: restore session creation broken by missing import
local/auth.py used os.environ without importing os, so new_session raised NameError. Every first visit to /api/session, every registration and every login returned 500, which left Site checkout, cart recovery and the customer portal unusable since the R2 stack change. Read COOKIE_SECURE once as a module constant and share it with local/app.py instead of resolving the same variable in two places. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
"""Local customer passwords and revocable database sessions. No email service."""
|
||||
import hashlib
|
||||
import os
|
||||
import secrets
|
||||
import logging
|
||||
import json
|
||||
@@ -7,6 +8,8 @@ from uuid import UUID, uuid4
|
||||
from fastapi import HTTPException, Request
|
||||
from .db import connect
|
||||
|
||||
COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true'
|
||||
|
||||
def password_hash(password, salt=None):
|
||||
salt = salt or secrets.token_hex(16)
|
||||
digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex()
|
||||
@@ -42,8 +45,7 @@ def new_session(c, response, identity=None):
|
||||
sid = uuid4()
|
||||
identity = identity or uuid4()
|
||||
c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity))
|
||||
response.set_cookie('dtf_session', str(sid), httponly=True,
|
||||
secure=os.environ.get('COOKIE_SECURE', 'false').lower() == 'true',
|
||||
response.set_cookie('dtf_session', str(sid), httponly=True, secure=COOKIE_SECURE,
|
||||
samesite='strict', max_age=86400*7)
|
||||
return identity
|
||||
|
||||
|
||||
Reference in New Issue
Block a user