Revert "feat: configure Kanban login by operator email"
All checks were successful
Build and deploy / Validate source (push) Successful in 12s
Build and deploy / Publish images and notify Portainer (push) Successful in 54s

This reverts commit 508fa03664.
This commit is contained in:
Cauê Faleiros
2026-09-18 13:45:08 -03:00
parent 508fa03664
commit d4190ebfeb
14 changed files with 48 additions and 59 deletions

View File

@@ -28,8 +28,8 @@ def run():
print('PASS: CSP, frame protection, Host and cross-origin rejection')
operator=Client()
credentials={'email':os.environ.get('OPERATOR_EMAIL','operator@example.test'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')}
encoded=base64.b64encode((credentials['email']+':'+credentials['password']).encode()).decode()
credentials={'username':os.environ.get('OPERATOR_USER','operator'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')}
encoded=base64.b64encode((credentials['username']+':'+credentials['password']).encode()).decode()
raw('/api/operator/board',401,{'Authorization':'Basic '+encoded})
operator.call('/operator/login',credentials)
token=next(c for c in operator.jar if c.name=='dtf_operator')
@@ -58,9 +58,9 @@ def run():
print('PASS: extension allowlist, exact multipart Content-Length signature, pending upload quota')
# Unique identity avoids locking out the real local operator.
attacker=Client();email='test-'+uuid4().hex+'@example.test'
for _ in range(10):attacker.call('/operator/login',{'email':email,'password':'invalid'},expected=401)
attacker.call('/operator/login',{'email':email,'password':'invalid'},expected=429)
attacker=Client();username='test-'+uuid4().hex
for _ in range(10):attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=401)
attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=429)
print('PASS: operator login throttling (only synthetic account bucket exhausted)')
if __name__=='__main__':run()