Remove legacy admin UI from RollCalc

This commit is contained in:
2026-07-07 12:20:09 +02:00
parent ac6840c759
commit ffa34815cd
6 changed files with 38 additions and 634 deletions
+1 -25
View File
@@ -27,11 +27,6 @@ BETA_USERS = {
"controlling": "beta2026" # ⚠️ ÄNDERN!
}
# Optional: Admin-Features (z.B. Logs, Stats)
ADMIN_USERS = {
"admin": "admin_secure_pwd_2026" # ⚠️ ÄNDERN!
}
# Logging für Auditing
LOG_FILE = "access_log.json"
@@ -42,8 +37,7 @@ LOG_FILE = "access_log.json"
@auth.verify_password
def verify_password(username, password):
"""Verify HTTP Basic Auth credentials"""
all_users = {**BETA_USERS, **ADMIN_USERS}
if username in all_users and all_users[username] == password:
if username in BETA_USERS and BETA_USERS[username] == password:
return username
return None
@@ -96,30 +90,12 @@ def health_check():
def get_user():
"""Get current authenticated user info"""
user = auth.current_user()
is_admin = user in ADMIN_USERS
return jsonify({
"username": user,
"authenticated": True,
"is_admin": is_admin,
"timestamp": datetime.now().isoformat()
}), 200
@app.route("/admin/logs", methods=["GET"])
@auth.login_required
def get_logs():
"""View access logs - admin only"""
user = auth.current_user()
if user not in ADMIN_USERS:
log_access(user, "/admin/logs", "GET", 403)
return jsonify({"error": "Unauthorized"}), 403
log_access(user, "/admin/logs", "GET")
logs = []
if os.path.exists(LOG_FILE):
with open(LOG_FILE, "r") as f:
logs = json.load(f)
return jsonify({"logs": logs}), 200
# ============================================================================
# ERROR HANDLERS
# ============================================================================