feat: move user management to protected config file
This commit is contained in:
+27
-8
@@ -14,7 +14,7 @@ Backend:
|
||||
|
||||
- `app.py` creates the Flask app.
|
||||
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
|
||||
- Users are currently configured in `BETA_USERS` with Werkzeug password hashes.
|
||||
- Users are configured in local deployment file `config/users.json` with Werkzeug password hashes. This file is ignored by Git.
|
||||
- `/` renders the active calculator template.
|
||||
- `/help` renders the authenticated Help landing page.
|
||||
- `/help/user-manual` renders `docs/de/user_manual.md` server-side inside the RollCalc Help layout.
|
||||
@@ -104,21 +104,40 @@ This JSON is a compact summary for the dialog, not the complete release history.
|
||||
|
||||
## Authentication
|
||||
|
||||
RollCalc uses HTTP Basic Auth. User entries in `BETA_USERS` have this shape:
|
||||
RollCalc uses HTTP Basic Auth. User entries are stored in the local deployment file:
|
||||
|
||||
```python
|
||||
"username": {
|
||||
"password_hash": "..."
|
||||
```text
|
||||
config/users.json
|
||||
```
|
||||
|
||||
This file is intentionally ignored by Git. The versioned file `config/users.example.json` documents the JSON format only and must not contain real usernames, hashes, or passwords.
|
||||
|
||||
The file stores username-to-password-hash mappings:
|
||||
|
||||
```json
|
||||
{
|
||||
"username": "<hash>"
|
||||
}
|
||||
```
|
||||
|
||||
Password verification uses `werkzeug.security.check_password_hash`. New hashes or config snippets can be generated with:
|
||||
Password verification uses `werkzeug.security.check_password_hash`. Users are managed with:
|
||||
|
||||
```bash
|
||||
python scripts/manage_users.py username
|
||||
python3 scripts/manage_users.py
|
||||
```
|
||||
|
||||
Passwords and hashes must not be logged.
|
||||
The management tool provides a text menu for listing users, creating users, changing passwords, and deleting users. New hashes use the existing RollCalc method `pbkdf2:sha256:600000`.
|
||||
|
||||
The Flask app requires a readable, valid, non-empty `config/users.json` at startup and does not silently create an empty user file. If the file is missing or invalid, startup should fail with a message pointing to `python3 scripts/manage_users.py`.
|
||||
|
||||
Passwords must not be logged. Password hashes should only be stored in `config/users.json` or a future protected deployment-specific secret source.
|
||||
|
||||
Deployment notes:
|
||||
|
||||
- The systemd/service user must be able to read `config/users.json`.
|
||||
- Suitable server permissions can be owner `martin`, group `www-data`, mode `640`, adjusted to the actual deployment users.
|
||||
- Do not hard-code deployment owners or groups in Python.
|
||||
- Back up the productive `config/users.json` before deploying or replacing a server instance.
|
||||
|
||||
## Roll Geometry
|
||||
|
||||
|
||||
Reference in New Issue
Block a user