Revert "feat: configure Kanban login by operator email"
All checks were successful
Build and deploy / Validate source (push) Successful in 12s
Build and deploy / Publish images and notify Portainer (push) Successful in 54s

This reverts commit 508fa03664.
This commit is contained in:
Cauê Faleiros
2026-09-18 13:45:08 -03:00
parent 508fa03664
commit d4190ebfeb
14 changed files with 48 additions and 59 deletions

View File

@@ -49,9 +49,8 @@ app.add_middleware(TrustedHostMiddleware, allowed_hosts=ALLOWED_HOSTS)
@app.post('/api/operator/login')
def operator_login(body: OperatorLogin, request: Request, response: Response):
email = body.email
throttle('operator:'+email, request)
valid_user = secrets.compare_digest(email.encode(), os.environ['OPERATOR_EMAIL'].strip().lower().encode())
throttle('operator:'+body.username, request)
valid_user = secrets.compare_digest(body.username.encode(), os.environ['OPERATOR_USER'].encode())
valid_password = secrets.compare_digest(body.password.encode(), os.environ['OPERATOR_PASSWORD'].encode())
if not (valid_user and valid_password):
audit('operator_login_failed')
@@ -61,10 +60,10 @@ def operator_login(body: OperatorLogin, request: Request, response: Response):
previous = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest()
c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (previous,))
c.execute('INSERT INTO dtf_local.operator_sessions(token_hash,username) VALUES(%s,%s)',
(hashlib.sha256(token.encode()).hexdigest(), email))
(hashlib.sha256(token.encode()).hexdigest(), body.username))
response.set_cookie('dtf_operator', token, httponly=True, secure=COOKIE_SECURE,
samesite='strict', path='/api/operator', max_age=28800)
audit('operator_login_success', operator=email)
audit('operator_login_success', operator=body.username)
return {'ok': True}
@app.post('/api/operator/logout')