feat: move user management to protected config file

This commit is contained in:
2026-07-28 13:46:05 +02:00
parent 2276a124b8
commit 3b54f5ecc0
6 changed files with 368 additions and 86 deletions
+27 -8
View File
@@ -14,7 +14,7 @@ Backend:
- `app.py` creates the Flask app.
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
- Users are currently configured in `BETA_USERS` with Werkzeug password hashes.
- Users are configured in local deployment file `config/users.json` with Werkzeug password hashes. This file is ignored by Git.
- `/` renders the active calculator template.
- `/help` renders the authenticated Help landing page.
- `/help/user-manual` renders `docs/de/user_manual.md` server-side inside the RollCalc Help layout.
@@ -104,21 +104,40 @@ This JSON is a compact summary for the dialog, not the complete release history.
## Authentication
RollCalc uses HTTP Basic Auth. User entries in `BETA_USERS` have this shape:
RollCalc uses HTTP Basic Auth. User entries are stored in the local deployment file:
```python
"username": {
"password_hash": "..."
```text
config/users.json
```
This file is intentionally ignored by Git. The versioned file `config/users.example.json` documents the JSON format only and must not contain real usernames, hashes, or passwords.
The file stores username-to-password-hash mappings:
```json
{
"username": "<hash>"
}
```
Password verification uses `werkzeug.security.check_password_hash`. New hashes or config snippets can be generated with:
Password verification uses `werkzeug.security.check_password_hash`. Users are managed with:
```bash
python scripts/manage_users.py username
python3 scripts/manage_users.py
```
Passwords and hashes must not be logged.
The management tool provides a text menu for listing users, creating users, changing passwords, and deleting users. New hashes use the existing RollCalc method `pbkdf2:sha256:600000`.
The Flask app requires a readable, valid, non-empty `config/users.json` at startup and does not silently create an empty user file. If the file is missing or invalid, startup should fail with a message pointing to `python3 scripts/manage_users.py`.
Passwords must not be logged. Password hashes should only be stored in `config/users.json` or a future protected deployment-specific secret source.
Deployment notes:
- The systemd/service user must be able to read `config/users.json`.
- Suitable server permissions can be owner `martin`, group `www-data`, mode `640`, adjusted to the actual deployment users.
- Do not hard-code deployment owners or groups in Python.
- Back up the productive `config/users.json` before deploying or replacing a server instance.
## Roll Geometry