e39521d51d
- TASK-03-01 server/auth/passwords.py: argon2id via argon2-cffi
PasswordHasher (t=3, m=64MiB, p=4 — exceeds OWASP). hash/verify/
needs_rehash; verify returns False on mismatch (uniform 401 path).
- TASK-03-02 server/auth/cookies.py: get_session_middleware_kwargs()
→ Starlette SessionMiddleware (itsdangerous HMAC-SHA256, D-056).
Cookie praxis_op, httpOnly, SameSite=strict, max_age=28800 (8h).
PRAXIS_COOKIE_SECURE default true; false logs WARNING (R-AUTH-01).
G-031 reframe documented: k-anon defense-in-depth is the PRIMARY
mitigation (sniffed cookie → no PII); secure flag is SECONDARY.
- TASK-03-03 server/auth/rate_limit.py: slowapi Limiter (in-memory,
D-041), 5/minute per IP on login. reset_login_rate_limit() helper.
- TASK-03-04 server/auth/dependencies.py + models.py: current_operator
Depends — reads signed-cookie session, fetches operator from PgStore,
401 on missing/invalid/inactive (clears session), 503 if no Postgres.
Never trusts the client (D-057).
- TASK-03-05 server/auth/routes.py: APIRouter(prefix=/api/operator)
with POST /login (rate-limited, rehash-on-login), POST /logout
(auth-gated, clears session), GET /me (auth-gated, React guard).
- TASK-03-06 tests/test_auth.py: 18 unit tests (mocked PgStore) —
passwords, cookie config, rate limit, 401/503 cases, login/logout/me,
rehash-on-login.
- pyproject.toml: added itsdangerous>=2.1 (SessionMiddleware dep).
---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: security-engineer
task: 03-01,03-02,03-03,03-04,03-05,03-06
requirements:
covered: [REQ-AUTH-01, REQ-NFR-AUTH-01]
grill:
- G-031 (R-AUTH-01 reframe: k-anon primary, secure flag secondary)
---/ci---
56 lines
2.0 KiB
Python
56 lines
2.0 KiB
Python
"""current_operator dependency (TASK-03-04, D-057).
|
|
|
|
Server-side auth enforcement: every `/api/operator/*` protected route uses
|
|
`Depends(current_operator)`. The dependency NEVER trusts the client (D-057)
|
|
— it reads the signed-cookie session, fetches the operator from Postgres,
|
|
and 401s on any gap (missing/invalid/expired cookie, unknown id, inactive
|
|
operator). The cookie is the authz *token*; the Postgres lookup is the
|
|
authz *decision*.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from fastapi import HTTPException, Request, status
|
|
|
|
from server.auth.models import Operator
|
|
|
|
|
|
async def current_operator(request: Request) -> Operator:
|
|
"""Resolve the authenticated operator from the signed-cookie session.
|
|
|
|
Raises 401 on: missing session, missing operator_id, no Postgres store
|
|
(503 actually — operator tier unavailable), unknown operator id, or an
|
|
inactive operator (session is cleared in the latter case so the client
|
|
cookie is invalidated).
|
|
"""
|
|
pg_store = getattr(request.app.state, "pg_store", None)
|
|
if pg_store is None:
|
|
raise HTTPException(
|
|
status_code=status.HTTP_503_SERVICE_UNAVAILABLE,
|
|
detail="operator tier unavailable (no Postgres)",
|
|
)
|
|
session = request.session
|
|
op_id = session.get("operator_id") if session else None
|
|
if not op_id:
|
|
raise HTTPException(
|
|
status_code=status.HTTP_401_UNAUTHORIZED,
|
|
detail="not authenticated",
|
|
)
|
|
row = await pg_store.get_operator_by_id(op_id)
|
|
if row is None or not row.get("is_active"):
|
|
# Inactive/unknown → clear the session so the cookie is invalidated.
|
|
if session:
|
|
session.clear()
|
|
raise HTTPException(
|
|
status_code=status.HTTP_401_UNAUTHORIZED,
|
|
detail="not authenticated",
|
|
)
|
|
return Operator(
|
|
id=str(row["id"]),
|
|
username=row["username"],
|
|
display_name=row.get("display_name"),
|
|
role=row.get("role", "operator"),
|
|
)
|
|
|
|
|
|
__all__ = ["current_operator"] |