Improve UI security and deploy workflow
This commit is contained in:
1 parent
be7762e369
commit
db9c4054a5
13 files changed
+435
-129
No files matched your search
@@ -1,13 +1,14 @@
|
||||
"""Authentication endpoints: login, logout, first-run setup."""
|
||||
import re
|
||||
|
||||
from fastapi import APIRouter, HTTPException, Request, Response
|
||||
from fastapi import APIRouter, Depends, HTTPException, Request, Response
|
||||
from pydantic import BaseModel, Field
|
||||
|
||||
from ..auth import (
|
||||
clear_auth_cookies,
|
||||
get_stored_admin,
|
||||
is_admin_configured,
|
||||
require_session_and_csrf,
|
||||
set_auth_cookies,
|
||||
store_admin,
|
||||
verify_password,
|
||||
@@ -43,7 +44,7 @@ async def api_login(request: Request, response: Response, payload: LoginRequest)
|
||||
|
||||
|
||||
@router.post("/api/logout")
|
||||
async def api_logout(response: Response):
|
||||
async def api_logout(response: Response, user=Depends(require_session_and_csrf)):
|
||||
clear_auth_cookies(response)
|
||||
return {"ok": True}
|
||||
|
||||
|
||||
+7
-1
@@ -5,6 +5,7 @@ from fastapi.templating import Jinja2Templates
|
||||
|
||||
from ..auth import CSRF_COOKIE, current_user, is_admin_configured, make_csrf_token
|
||||
from ..config import load_config
|
||||
from ..settings import settings
|
||||
|
||||
router = APIRouter()
|
||||
templates = Jinja2Templates(directory="app/templates")
|
||||
@@ -15,7 +16,12 @@ def _ensure_csrf(request: Request, response):
|
||||
if not token:
|
||||
token = make_csrf_token()
|
||||
response.set_cookie(
|
||||
CSRF_COOKIE, token, httponly=False, samesite="lax", path="/"
|
||||
CSRF_COOKIE,
|
||||
token,
|
||||
httponly=False,
|
||||
samesite="lax",
|
||||
secure=settings.trust_proxy,
|
||||
path="/",
|
||||
)
|
||||
return token
|
||||
|
||||
|
||||
Reference in new issue
Block a user