reset
This commit is contained in:
@@ -0,0 +1,226 @@
|
||||
# Naue Roll Calculator – Flask Beta Deployment
|
||||
|
||||
## Überblick
|
||||
|
||||
Diese Flask-Anwendung schützt den Roll Diameter Calculator mit **HTTP Basic Authentication**.
|
||||
Benutzer müssen sich mit Benutzername und Passwort anmelden, bevor sie auf die App zugreifen können.
|
||||
|
||||
---
|
||||
|
||||
## Installation & Setup
|
||||
|
||||
### 1. Abhängigkeiten installieren
|
||||
|
||||
```bash
|
||||
pip install -r requirements.txt
|
||||
```
|
||||
|
||||
### 2. HTML-Template einbinden
|
||||
|
||||
Kopiere deine ursprüngliche `roll_calculator.html` vollständig in:
|
||||
```
|
||||
templates/roll_calculator.html
|
||||
```
|
||||
|
||||
Falls du noch die statischen Dateien brauchst (JSON-Dateien, Service Worker):
|
||||
```bash
|
||||
mkdir -p static
|
||||
# Kopiere article-data.json, config.json, service-worker.js (optional) in static/
|
||||
```
|
||||
|
||||
### 3. App starten
|
||||
|
||||
```bash
|
||||
python app.py
|
||||
```
|
||||
|
||||
Server läuft dann unter: **http://localhost:5000**
|
||||
|
||||
---
|
||||
|
||||
## Test-Zugänge (Standard-Beta-Benutzer)
|
||||
|
||||
| Benutzer | Passwort | Rolle |
|
||||
|----------|----------------------|-------------|
|
||||
| `beta` | `rollcalc_beta_2026` | User |
|
||||
| `naue` | `naue_access_2026` | User |
|
||||
| `admin` | `admin_secure_pwd_2026` | Admin |
|
||||
|
||||
> ⚠️ **WICHTIG:** Vor Produktivbereitstellung **ALLE PASSWÖRTER ÄNDERN**!
|
||||
|
||||
---
|
||||
|
||||
## Authentifizierung
|
||||
|
||||
### HTTP Basic Auth
|
||||
- Browser zeigt automatisch ein Login-Popup
|
||||
- Credentials werden Base64-codiert mit jedem Request mitgesendet
|
||||
- **Nur über HTTPS verwenden!** (in Production)
|
||||
|
||||
### Neue Benutzer hinzufügen
|
||||
|
||||
In `app.py` die `BETA_USERS` oder `ADMIN_USERS` Dictionaries anpassen:
|
||||
|
||||
```python
|
||||
BETA_USERS = {
|
||||
"beta": "rollcalc_beta_2026",
|
||||
"neuer_user": "neues_passwort_hier" # ← Neu
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Features
|
||||
|
||||
✅ HTTP Basic Auth (Browser-Standard)
|
||||
✅ Audit-Logging (access_log.json)
|
||||
✅ Admin-Endpoints (/admin/logs)
|
||||
✅ Static Files Protection
|
||||
✅ CORS-ready (für zukünftige APIs)
|
||||
✅ Health Check Endpoint
|
||||
|
||||
---
|
||||
|
||||
## API-Endpunkte
|
||||
|
||||
```
|
||||
GET / → HTML-Seite (geschützt)
|
||||
GET /static/<file> → Statische Dateien (geschützt)
|
||||
GET /api/health → Health Check (geschützt)
|
||||
GET /api/user → Authentifizierter Benutzer Info (geschützt)
|
||||
GET /admin/logs → Access Logs (Admin-only)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Sicherheit für Production
|
||||
|
||||
1. **Passwörter aktualisieren**
|
||||
```python
|
||||
BETA_USERS = {"realuser": "komplexes_passwort_mindestens_16_zeichen"}
|
||||
```
|
||||
|
||||
2. **HTTPS erzwingen**
|
||||
- Reverse Proxy (nginx, Apache)
|
||||
- SSL/TLS Certificate
|
||||
|
||||
3. **Umgebungsvariablen nutzen** (statt hardcoded)
|
||||
```python
|
||||
import os
|
||||
BETA_USERS = {
|
||||
"beta": os.getenv("BETA_PASSWORD", "default")
|
||||
}
|
||||
```
|
||||
|
||||
4. **Debug deaktivieren**
|
||||
```python
|
||||
app.run(debug=False) # In Production
|
||||
```
|
||||
|
||||
5. **Rate Limiting hinzufügen**
|
||||
```bash
|
||||
pip install Flask-Limiter
|
||||
```
|
||||
|
||||
6. **Access Logs regelmäßig archivieren**
|
||||
```bash
|
||||
gzip access_log.json
|
||||
rm access_log.json
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Dateistruktur
|
||||
|
||||
```
|
||||
project/
|
||||
├── app.py # Flask-Applikation (mit HTTP Basic Auth)
|
||||
├── requirements.txt # Python Dependencies
|
||||
├── access_log.json # Auto-generiert (Audit Trail)
|
||||
├── templates/
|
||||
│ └── roll_calculator.html # ← HTML-Template hier einfügen
|
||||
├── static/
|
||||
│ ├── article-data.json # (optional)
|
||||
│ ├── config.json # (optional)
|
||||
│ └── service-worker.js # (optional)
|
||||
└── README.md # Diese Datei
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### "401 Unauthorized" beim Öffnen von http://localhost:5000
|
||||
|
||||
✓ Das ist normal! Browser zeigt automatisch ein Auth-Dialog.
|
||||
✓ Gib Benutzername/Passwort ein (z.B. `beta` / `rollcalc_beta_2026`)
|
||||
|
||||
### "template not found"
|
||||
|
||||
✓ Stelle sicher, dass `templates/roll_calculator.html` existiert
|
||||
✓ HTML-Datei muss vollständig sein (mit allen Scripts)
|
||||
|
||||
### "404 Not Found" bei article-data.json
|
||||
|
||||
✓ Ist optional. Falls benötigt:
|
||||
- Kopiere `article-data.json` in `static/`
|
||||
- Oder erweitere den /static-Route in app.py
|
||||
|
||||
---
|
||||
|
||||
## Logging
|
||||
|
||||
Alle erfolgreichen und fehlgeschlagenen Login-Versuche werden in `access_log.json` geloggt:
|
||||
|
||||
```json
|
||||
[
|
||||
{
|
||||
"timestamp": "2026-05-28T12:16:41.123456",
|
||||
"username": "beta",
|
||||
"endpoint": "/",
|
||||
"method": "GET",
|
||||
"status": 200
|
||||
}
|
||||
]
|
||||
```
|
||||
|
||||
Admin-Benutzer können Logs ansehen unter `/admin/logs` (JSON-Format).
|
||||
|
||||
---
|
||||
|
||||
## Deployment-Optionen
|
||||
|
||||
### Option 1: Docker
|
||||
```dockerfile
|
||||
FROM python:3.11-slim
|
||||
WORKDIR /app
|
||||
COPY requirements.txt .
|
||||
RUN pip install -r requirements.txt
|
||||
COPY . .
|
||||
CMD ["python", "app.py"]
|
||||
```
|
||||
|
||||
### Option 2: Systemd Service (Linux)
|
||||
```ini
|
||||
[Service]
|
||||
ExecStart=/usr/bin/python3 /path/to/app.py
|
||||
Restart=always
|
||||
WorkingDirectory=/path/to/
|
||||
```
|
||||
|
||||
### Option 3: Gunicorn (Production)
|
||||
```bash
|
||||
pip install gunicorn
|
||||
gunicorn -w 4 -b 0.0.0.0:5000 app:app
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Fragen?
|
||||
|
||||
Kontakt: Produktionsplanung / Logistik / Produktmanagement
|
||||
|
||||
---
|
||||
|
||||
**Naue GmbH & Co. KG**
|
||||
Roll Diameter Calculator – Beta Phase 2026
|
||||
Reference in New Issue
Block a user