Use password hashes for authentication
This commit is contained in:
+20
-2
@@ -14,7 +14,7 @@ Backend:
|
||||
|
||||
- `app.py` creates the Flask app.
|
||||
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
|
||||
- Users are currently hardcoded in `BETA_USERS`.
|
||||
- Users are currently configured in `BETA_USERS` with Werkzeug password hashes.
|
||||
- `/` renders the active calculator template.
|
||||
- `/static/<path:filename>` is intended to serve static files behind Basic Auth.
|
||||
- `/api/health` returns health/version information.
|
||||
@@ -50,6 +50,24 @@ If `build_info.json` is missing, malformed, or does not contain a usable value,
|
||||
|
||||
The data is loaded centrally in `app.py` and made available to every template as `build_info`.
|
||||
|
||||
## Authentication
|
||||
|
||||
RollCalc uses HTTP Basic Auth. User entries in `BETA_USERS` have this shape:
|
||||
|
||||
```python
|
||||
"username": {
|
||||
"password_hash": "..."
|
||||
}
|
||||
```
|
||||
|
||||
Password verification uses `werkzeug.security.check_password_hash`. New hashes or config snippets can be generated with:
|
||||
|
||||
```bash
|
||||
python scripts/manage_users.py username
|
||||
```
|
||||
|
||||
Passwords and hashes must not be logged.
|
||||
|
||||
## Roll Geometry
|
||||
|
||||
Calculations assume an ideal cylindrical winding.
|
||||
@@ -210,7 +228,7 @@ Login/access logging remains part of RollCalc, but log viewing and article-data
|
||||
|
||||
## Known Technical Risks
|
||||
|
||||
- Hardcoded plaintext credentials in `app.py`.
|
||||
- Password hashes are currently configured in `app.py`; this should eventually move to a protected external configuration or secrets mechanism.
|
||||
- Basic Auth only; no sessions or role framework beyond the user dictionary.
|
||||
- `access_log.json` is rewritten on every logged request and is not concurrency-safe.
|
||||
- No log rotation or retention policy is implemented.
|
||||
|
||||
Reference in New Issue
Block a user