Use password hashes for authentication

This commit is contained in:
2026-07-07 16:16:50 +02:00
parent 8f64760add
commit dcca3fa042
5 changed files with 127 additions and 13 deletions
+20 -2
View File
@@ -14,7 +14,7 @@ Backend:
- `app.py` creates the Flask app.
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
- Users are currently hardcoded in `BETA_USERS`.
- Users are currently configured in `BETA_USERS` with Werkzeug password hashes.
- `/` renders the active calculator template.
- `/static/<path:filename>` is intended to serve static files behind Basic Auth.
- `/api/health` returns health/version information.
@@ -50,6 +50,24 @@ If `build_info.json` is missing, malformed, or does not contain a usable value,
The data is loaded centrally in `app.py` and made available to every template as `build_info`.
## Authentication
RollCalc uses HTTP Basic Auth. User entries in `BETA_USERS` have this shape:
```python
"username": {
"password_hash": "..."
}
```
Password verification uses `werkzeug.security.check_password_hash`. New hashes or config snippets can be generated with:
```bash
python scripts/manage_users.py username
```
Passwords and hashes must not be logged.
## Roll Geometry
Calculations assume an ideal cylindrical winding.
@@ -210,7 +228,7 @@ Login/access logging remains part of RollCalc, but log viewing and article-data
## Known Technical Risks
- Hardcoded plaintext credentials in `app.py`.
- Password hashes are currently configured in `app.py`; this should eventually move to a protected external configuration or secrets mechanism.
- Basic Auth only; no sessions or role framework beyond the user dictionary.
- `access_log.json` is rewritten on every logged request and is not concurrency-safe.
- No log rotation or retention policy is implemented.