Use password hashes for authentication
This commit is contained in:
@@ -42,7 +42,7 @@ If port `5000` is already occupied, start through Flask's CLI without changing f
|
||||
flask --app app run --host 127.0.0.1 --port 5001
|
||||
```
|
||||
|
||||
The app uses HTTP Basic Auth. Current credentials are defined in `BETA_USERS` in `app.py`.
|
||||
The app uses HTTP Basic Auth. Current users are defined in `BETA_USERS` in `app.py` with Werkzeug password hashes.
|
||||
|
||||
## Project Layout
|
||||
|
||||
@@ -90,7 +90,22 @@ Implemented routes:
|
||||
| `/api/health` | `GET` | Basic Auth | Returns app health and version. |
|
||||
| `/api/user` | `GET` | Basic Auth | Returns current authenticated user info. |
|
||||
|
||||
Authentication is implemented with `Flask-HTTPAuth`. The current code checks `BETA_USERS` and performs direct plaintext string comparison.
|
||||
Authentication is implemented with `Flask-HTTPAuth`. The current code checks `BETA_USERS` with `werkzeug.security.check_password_hash`; plaintext passwords are not stored in the application.
|
||||
|
||||
Generate a password hash or user entry with:
|
||||
|
||||
```bash
|
||||
python scripts/manage_users.py username
|
||||
python scripts/manage_users.py username --json
|
||||
```
|
||||
|
||||
For non-interactive local maintenance only:
|
||||
|
||||
```bash
|
||||
python scripts/manage_users.py username --password 'new-password'
|
||||
```
|
||||
|
||||
Do not commit real passwords or print them in logs.
|
||||
|
||||
Access logging is handled by `log_access()`, which reads `access_log.json`, appends a record, and writes the whole file back.
|
||||
|
||||
@@ -287,11 +302,11 @@ Utility script that updates relative frontend fetch/register paths to Flask-styl
|
||||
- There are duplicated or legacy-looking files with similar names. Before editing JavaScript under `static/`, confirm it is actually referenced by the active template.
|
||||
- The documentation under `docs/` contains deployment and feature notes, but some filenames and route assumptions may not match the current app exactly.
|
||||
- The Flask dev server is used for local development only. Production should use a WSGI server.
|
||||
- Use `scripts/manage_users.py` to create password hashes when adding or rotating Basic Auth users.
|
||||
|
||||
## Known Risks and Maintenance Items
|
||||
|
||||
- Credentials are hardcoded in `app.py` and should be moved to environment variables or a secrets manager.
|
||||
- Passwords are stored in plaintext and compared directly.
|
||||
- Password hashes are currently configured in `app.py`; user configuration should eventually move to environment variables, a protected config file, or a secrets manager.
|
||||
- `access_log.json` is not safe for concurrent writes.
|
||||
- `access_log.json` grows without rotation or retention limits.
|
||||
- The custom `/static/<path:filename>` route is intended to protect static files, but Flask also creates a default static route unless disabled. Verify effective route behavior before relying on static-file protection.
|
||||
|
||||
Reference in New Issue
Block a user