Praxis CI
|
e39521d51d
|
feat(P01): SLICE-03 operator auth — argon2id + signed cookies + rate limit
- TASK-03-01 server/auth/passwords.py: argon2id via argon2-cffi
PasswordHasher (t=3, m=64MiB, p=4 — exceeds OWASP). hash/verify/
needs_rehash; verify returns False on mismatch (uniform 401 path).
- TASK-03-02 server/auth/cookies.py: get_session_middleware_kwargs()
→ Starlette SessionMiddleware (itsdangerous HMAC-SHA256, D-056).
Cookie praxis_op, httpOnly, SameSite=strict, max_age=28800 (8h).
PRAXIS_COOKIE_SECURE default true; false logs WARNING (R-AUTH-01).
G-031 reframe documented: k-anon defense-in-depth is the PRIMARY
mitigation (sniffed cookie → no PII); secure flag is SECONDARY.
- TASK-03-03 server/auth/rate_limit.py: slowapi Limiter (in-memory,
D-041), 5/minute per IP on login. reset_login_rate_limit() helper.
- TASK-03-04 server/auth/dependencies.py + models.py: current_operator
Depends — reads signed-cookie session, fetches operator from PgStore,
401 on missing/invalid/inactive (clears session), 503 if no Postgres.
Never trusts the client (D-057).
- TASK-03-05 server/auth/routes.py: APIRouter(prefix=/api/operator)
with POST /login (rate-limited, rehash-on-login), POST /logout
(auth-gated, clears session), GET /me (auth-gated, React guard).
- TASK-03-06 tests/test_auth.py: 18 unit tests (mocked PgStore) —
passwords, cookie config, rate limit, 401/503 cases, login/logout/me,
rehash-on-login.
- pyproject.toml: added itsdangerous>=2.1 (SessionMiddleware dep).
---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: security-engineer
task: 03-01,03-02,03-03,03-04,03-05,03-06
requirements:
covered: [REQ-AUTH-01, REQ-NFR-AUTH-01]
grill:
- G-031 (R-AUTH-01 reframe: k-anon primary, secure flag secondary)
---/ci---
|
2026-08-04 00:52:16 +00:00 |
|
Praxis CI
|
6ada2560ba
|
chore(P01): TASK-01-02 add asyncpg, argon2-cffi, slowapi deps
The three v0.4 pip dependencies (RESEARCH-v0.4 §new-deps):
asyncpg>=0.29 (Postgres driver, D-050), argon2-cffi>=23.1 (password
hashing, D-041), slowapi>=0.1 (rate limiting, D-041).
---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: lead-developer
task: 01-02
requirements:
covered: [REQ-MT-01, REQ-AUTH-01, REQ-NFR-AUTH-01]
---/ci---
|
2026-08-04 00:46:09 +00:00 |
|
Praxis CI
|
6cf63cb064
|
docs(P01): verify — APPROVE_WITH_NOTES, 4 P0 fixed, 18/20 REQ covered
Verification layers:
Structural: PASS (all scripts executable, syntax clean, Dockerfile valid)
Behavioral: PASS (121 bats, 77 pytest, docker build succeeds, compose valid)
Security: PASS (no secrets committed, .dockerignore excludes .env*, env_file pattern)
Quality: PASS (coreci patterns followed, no coreci refs, G-104/G-105/G-106 verified)
P0 issues found and auto-fixed:
1. docker-compose.yml: removed invalid restart_policy key, fixed env_file syntax
2. pyproject.toml: added fastapi + uvicorn deps (v0.1 gap exposed by Dockerfile)
3. timing.sh: renamed coreci_deploy_timing → praxis_deploy_timing (TASK-03-07)
4. firstboot-hook.sh: fixed idempotency check (/opt/praxis/.git not /usr/local/bin/praxis-deploy)
P1+ issues: 8 (1 fixed: lxc-config.sh default alignment, 7 noted for post-hoc review)
REQ coverage: 18/20 covered, 2 deferred (live first-boot timing + live E2E require cluster)
Must-haves: 25/28 pass, 2 partial (comment-only diffs, no Makefile), 1 deferred
---ci---
project: praxis
phase: 1
milestone: v0.2
status: verify
---/ci---
|
2026-08-03 18:37:45 +00:00 |
|