S1: shared value helpers (parse_dt/coerce_bool) + auto-Secure session cookie
M9 hardening/DRY pass — section S1, commit 1 (the shared-toolkit foundation): - Add src/thoughtsync/common.py with parse_dt() and coerce_bool(): one home for the ISO-date and truthy-flag coercions that were duplicated across modules. notes.py adopts them and deletes _parse_iso_dt, _iso_to_dt and _truthy (rule 22 — old copies removed; callers, incl. tests, updated). - Security: the session cookie is now marked Secure automatically on any request that arrived over HTTPS (directly or via a proxy's X-Forwarded-Proto), via a SecureCookieSessionInterface override. Hardens HTTPS deployments without breaking plain-HTTP LAN installs — no config. Behavior-preserving refactor + one security hardening. The backend serialization layer, the json_error sweep, and the notes.py split follow as their own commits. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
+21
-1
@@ -5,7 +5,8 @@ import os
|
||||
import secrets
|
||||
from datetime import timedelta
|
||||
|
||||
from quart import Quart, jsonify, send_from_directory
|
||||
from quart import Quart, has_request_context, jsonify, request, send_from_directory
|
||||
from quart.sessions import SecureCookieSessionInterface
|
||||
|
||||
from . import __version__
|
||||
from .auth import bp as auth_bp
|
||||
@@ -26,6 +27,23 @@ STATIC_DIR = os.path.join(os.path.dirname(__file__), "static")
|
||||
mimetypes.add_type("application/manifest+json", ".webmanifest")
|
||||
|
||||
|
||||
class _AutoSecureSessionInterface(SecureCookieSessionInterface):
|
||||
"""Mark the session cookie `Secure` whenever the request arrived over HTTPS —
|
||||
directly, or via a TLS-terminating reverse proxy that sets X-Forwarded-Proto.
|
||||
|
||||
Auto-detecting per request (rather than a fixed SESSION_COOKIE_SECURE flag)
|
||||
hardens the cookie on HTTPS deployments without breaking a plain-HTTP install on
|
||||
a trusted LAN, where a hard-forced Secure flag would stop the browser from ever
|
||||
sending the cookie back — i.e. silently break login. No configuration required.
|
||||
"""
|
||||
|
||||
def get_cookie_secure(self, app: Quart) -> bool:
|
||||
if not has_request_context():
|
||||
return False
|
||||
forwarded = request.headers.get("X-Forwarded-Proto", "").split(",")[0].strip().lower()
|
||||
return forwarded == "https" or request.is_secure
|
||||
|
||||
|
||||
def create_app() -> Quart:
|
||||
# static_folder=None: the SPA catch-all below owns static serving.
|
||||
app = Quart(__name__, static_folder=None)
|
||||
@@ -35,6 +53,8 @@ def create_app() -> Quart:
|
||||
app.config["APP_VERSION"] = os.environ.get("APP_VERSION", __version__)
|
||||
app.config["SESSION_COOKIE_HTTPONLY"] = True
|
||||
app.config["SESSION_COOKIE_SAMESITE"] = "Lax"
|
||||
# Auto-mark the session cookie Secure on HTTPS requests (see the interface above).
|
||||
app.session_interface = _AutoSecureSessionInterface()
|
||||
app.config["PERMANENT_SESSION_LIFETIME"] = timedelta(days=30)
|
||||
# Hard request-body ceiling (any-file attachments, import zips, sync push). The
|
||||
# per-file attachment limit is the DB-backed `max_attachment_mb` setting, enforced
|
||||
|
||||
Reference in New Issue
Block a user