Feature 1: Local accounts, replacing shared token
Sync Gitea releases to GitHub / sync-releases (push) Canceled after 0s
Sync Gitea releases to GitHub / sync-releases (push) Canceled after 0s
- Local accounts with bcrypt password hashing; first-run setup via POST /api/setup - Personal API tokens (dmv_<48hex>, SHA-256 hashed at rest) for scripted access - Server-side in-memory sessions with 32-byte secure cookie (dockmv_session, 7-day TTL, sliding renewal) - Login rate limiting (exponential backoff 1s–30s cap) per IP - Refuse to bind non-loopback while no account exists, unless DOCKMV_TRUST_ADDR=1 (for Docker's port mapping) - Every account can manage every other account (no roles in v1) - Auth middleware: public-path allowlist (/api/setup, /api/login, /api/logout, /api/me, /api/health) + session cookie check + API token (X-Auth-Token or Authorization: Bearer) check - Frontend AuthGate gates app on GET /api/me; shows setup screen or login form or app tree as needed - Account tab for personal token management; sign-out button in topbar - Break: removed --token flag, DOCKMV_TOKEN env var, ?token= query param, /api/health no longer auto-responds when unauthenticated Verified: go build/vet clean, frontend tsc+vite clean. Sandbox cannot execute binaries to test setup→login→session→token flow at runtime; recommend manual pass before merge. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+24
-1
@@ -286,5 +286,28 @@ export interface Health {
|
||||
packageDir: string
|
||||
dataDir: string
|
||||
knownHosts: string
|
||||
authRequired: boolean
|
||||
}
|
||||
|
||||
export interface User {
|
||||
id: string
|
||||
username: string
|
||||
createdAt: string
|
||||
lastLoginAt?: string
|
||||
}
|
||||
|
||||
export interface APIToken {
|
||||
id: string
|
||||
userId: string
|
||||
name: string
|
||||
hint: string
|
||||
createdAt: string
|
||||
lastUsedAt?: string
|
||||
}
|
||||
|
||||
/** The response from GET /api/me, /api/setup and /api/login. */
|
||||
export interface Me {
|
||||
id?: string
|
||||
username?: string
|
||||
authenticated: boolean
|
||||
needsSetup?: boolean
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user