M1.5 backend: admin role + DB-backed settings, DB-URL-only install
- users.is_admin; first registered user becomes admin; registration gated by the allow_registration setting (first account always allowed). is_admin in /api/auth/* responses; require_admin guard (live DB check). - settings table + code registry (site_name, allow_registration, session_ttl_days) with typed defaults — empty table = all defaults (rule 26). get/set/validate service; GET /api/config (public) + GET/PATCH /api/settings (admin), live session-TTL apply with no restart (rule 25). - Cookie-signing secret now persisted in the DB (before_serving load-or-create), so sessions survive restarts with no volume. Config: DATABASE_URL is the only required env; SECRET_KEY + DATA_DIR are optional break-glass items. - Migration 0003; DB-free tests for settings validation + admin guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
+33
-6
@@ -1,34 +1,61 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import secrets
|
||||
from datetime import timedelta
|
||||
|
||||
from quart import Quart, jsonify, send_from_directory
|
||||
|
||||
from . import __version__
|
||||
from .auth import bp as auth_bp
|
||||
from .config import Config
|
||||
from .db import session_scope
|
||||
from .notes import bp as notes_bp
|
||||
from .settings import get_public_config, get_setting, load_or_create_secret_key
|
||||
from .settings_api import bp as settings_bp
|
||||
|
||||
STATIC_DIR = os.path.join(os.path.dirname(__file__), "static")
|
||||
|
||||
|
||||
def create_app() -> Quart:
|
||||
# static_folder=None: the SPA catch-all below owns static serving instead of
|
||||
# Quart's default /static handler.
|
||||
# static_folder=None: the SPA catch-all below owns static serving.
|
||||
app = Quart(__name__, static_folder=None)
|
||||
app.secret_key = Config.secret_key()
|
||||
# Ephemeral/env secret so the app (and DB-free unit tests) construct without a
|
||||
# database. before_serving swaps in the real, DB-persisted key before serving.
|
||||
app.secret_key = Config.secret_key_env() or secrets.token_urlsafe(48)
|
||||
app.config["APP_VERSION"] = os.environ.get("APP_VERSION", __version__)
|
||||
app.config["SESSION_COOKIE_HTTPONLY"] = True
|
||||
app.config["SESSION_COOKIE_SAMESITE"] = "Lax"
|
||||
app.config["PERMANENT_SESSION_LIFETIME"] = timedelta(days=30)
|
||||
|
||||
app.register_blueprint(auth_bp)
|
||||
app.register_blueprint(notes_bp)
|
||||
app.register_blueprint(settings_bp)
|
||||
|
||||
@app.before_serving
|
||||
async def _bootstrap() -> None:
|
||||
# Load (or generate + persist) the real signing secret and the live session
|
||||
# lifetime from the DB, before any request is served.
|
||||
async with session_scope() as db:
|
||||
app.secret_key = await load_or_create_secret_key(db)
|
||||
try:
|
||||
days = int(await get_setting(db, "session_ttl_days"))
|
||||
app.config["PERMANENT_SESSION_LIFETIME"] = timedelta(days=days)
|
||||
except (ValueError, TypeError, KeyError):
|
||||
pass
|
||||
|
||||
@app.get("/api/health")
|
||||
async def health():
|
||||
return jsonify({"status": "ok", "version": app.config["APP_VERSION"]})
|
||||
|
||||
# Serve the built Vue SPA (baked into static/ by the Docker build) with a
|
||||
# history-fallback to index.html. In dev the Vite server proxies /api here, so
|
||||
# a missing static/ dir is expected and simply 404s the frontend.
|
||||
@app.get("/api/config")
|
||||
async def public_config():
|
||||
# Public: the login/register screen reads site name + whether signups are open.
|
||||
async with session_scope() as db:
|
||||
data = await get_public_config(db)
|
||||
data["version"] = app.config["APP_VERSION"]
|
||||
return jsonify(data)
|
||||
|
||||
@app.get("/", defaults={"path": ""})
|
||||
@app.get("/<path:path>")
|
||||
async def spa(path: str):
|
||||
|
||||
Reference in New Issue
Block a user