fix: restore session creation broken by missing import

local/auth.py used os.environ without importing os, so new_session raised
NameError. Every first visit to /api/session, every registration and every
login returned 500, which left Site checkout, cart recovery and the customer
portal unusable since the R2 stack change.

Read COOKIE_SECURE once as a module constant and share it with local/app.py
instead of resolving the same variable in two places.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-18 18:32:17 -03:00
parent 99fd92bdb8
commit 9046ec6db0
2 changed files with 5 additions and 4 deletions

View File

@@ -17,7 +17,7 @@ from . import db
from .adapters import FakeFreight, FakePayment, LocalS3Storage, require_runtime from .adapters import FakeFreight, FakePayment, LocalS3Storage, require_runtime
from .models import Freight, Move, Pay, QuoteRequest, Review, UploadStart, OperatorLogin from .models import Freight, Move, Pay, QuoteRequest, Review, UploadStart, OperatorLogin
from .pricing import price from .pricing import price
from .auth import owner, session_row, new_session, operator, throttle, audit, rate_limit from .auth import COOKIE_SECURE, owner, session_row, new_session, operator, throttle, audit, rate_limit
from .scanning import require_clean from .scanning import require_clean
require_runtime() require_runtime()
@@ -28,7 +28,6 @@ ENVIRONMENT = os.environ.get('APP_ENV', 'local')
PUBLIC_ORIGIN = os.environ.get('PUBLIC_ORIGIN', 'http://localhost') PUBLIC_ORIGIN = os.environ.get('PUBLIC_ORIGIN', 'http://localhost')
ALLOWED_HOSTS = [host for host in os.environ.get('ALLOWED_HOSTS', 'localhost,127.0.0.1').split(',') if host] ALLOWED_HOSTS = [host for host in os.environ.get('ALLOWED_HOSTS', 'localhost,127.0.0.1').split(',') if host]
ALLOWED_ORIGINS = [origin for origin in os.environ.get('ALLOWED_ORIGINS', PUBLIC_ORIGIN).split(',') if origin] ALLOWED_ORIGINS = [origin for origin in os.environ.get('ALLOWED_ORIGINS', PUBLIC_ORIGIN).split(',') if origin]
COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true'
PART_BYTES = int(os.environ.get('UPLOAD_PART_BYTES', '8388608')) PART_BYTES = int(os.environ.get('UPLOAD_PART_BYTES', '8388608'))
if not 5242880 <= PART_BYTES <= 67108864: if not 5242880 <= PART_BYTES <= 67108864:
raise RuntimeError('UPLOAD_PART_BYTES must be between 5 and 64 MiB') raise RuntimeError('UPLOAD_PART_BYTES must be between 5 and 64 MiB')

View File

@@ -1,5 +1,6 @@
"""Local customer passwords and revocable database sessions. No email service.""" """Local customer passwords and revocable database sessions. No email service."""
import hashlib import hashlib
import os
import secrets import secrets
import logging import logging
import json import json
@@ -7,6 +8,8 @@ from uuid import UUID, uuid4
from fastapi import HTTPException, Request from fastapi import HTTPException, Request
from .db import connect from .db import connect
COOKIE_SECURE = os.environ.get('COOKIE_SECURE', 'false').lower() == 'true'
def password_hash(password, salt=None): def password_hash(password, salt=None):
salt = salt or secrets.token_hex(16) salt = salt or secrets.token_hex(16)
digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex() digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex()
@@ -42,8 +45,7 @@ def new_session(c, response, identity=None):
sid = uuid4() sid = uuid4()
identity = identity or uuid4() identity = identity or uuid4()
c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity)) c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity))
response.set_cookie('dtf_session', str(sid), httponly=True, response.set_cookie('dtf_session', str(sid), httponly=True, secure=COOKIE_SECURE,
secure=os.environ.get('COOKIE_SECURE', 'false').lower() == 'true',
samesite='strict', max_age=86400*7) samesite='strict', max_age=86400*7)
return identity return identity