e39521d51dc306cc125ed823131ebe811c322d88
- TASK-03-01 server/auth/passwords.py: argon2id via argon2-cffi
PasswordHasher (t=3, m=64MiB, p=4 — exceeds OWASP). hash/verify/
needs_rehash; verify returns False on mismatch (uniform 401 path).
- TASK-03-02 server/auth/cookies.py: get_session_middleware_kwargs()
→ Starlette SessionMiddleware (itsdangerous HMAC-SHA256, D-056).
Cookie praxis_op, httpOnly, SameSite=strict, max_age=28800 (8h).
PRAXIS_COOKIE_SECURE default true; false logs WARNING (R-AUTH-01).
G-031 reframe documented: k-anon defense-in-depth is the PRIMARY
mitigation (sniffed cookie → no PII); secure flag is SECONDARY.
- TASK-03-03 server/auth/rate_limit.py: slowapi Limiter (in-memory,
D-041), 5/minute per IP on login. reset_login_rate_limit() helper.
- TASK-03-04 server/auth/dependencies.py + models.py: current_operator
Depends — reads signed-cookie session, fetches operator from PgStore,
401 on missing/invalid/inactive (clears session), 503 if no Postgres.
Never trusts the client (D-057).
- TASK-03-05 server/auth/routes.py: APIRouter(prefix=/api/operator)
with POST /login (rate-limited, rehash-on-login), POST /logout
(auth-gated, clears session), GET /me (auth-gated, React guard).
- TASK-03-06 tests/test_auth.py: 18 unit tests (mocked PgStore) —
passwords, cookie config, rate limit, 401/503 cases, login/logout/me,
rehash-on-login.
- pyproject.toml: added itsdangerous>=2.1 (SessionMiddleware dep).
---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: security-engineer
task: 03-01,03-02,03-03,03-04,03-05,03-06
requirements:
covered: [REQ-AUTH-01, REQ-NFR-AUTH-01]
grill:
- G-031 (R-AUTH-01 reframe: k-anon primary, secure flag secondary)
---/ci---
Praxis — v0.1 Foundation
Voice-first AI apprenticeship platform. v0.1 is a tech-validation harness (per G-008) for the minimal viable voice loop: a single learner speaks to an AI tutor playing a Customer Service role-play scenario, hears a <600ms-latency response, receives an end-of-session coaching debrief, and has the session logged to SQLite.
Status
Phase 1 (minimal viable voice loop) — code-complete, pending live API keys for runtime verification.
Stack
- Orchestration: Pipecat (D-017) with Silero VAD + interruptibility
- ASR: Deepgram Nova-3 streaming (D-013)
- LLM: Ollama Cloud direct API (D-020) —
gemma4:cloud(role-play) +deepseek-v4-flash:cloudno-think (debrief) - TTS: Cartesia Sonic (primary, D-014) / Piper (self-hosted, R4 mitigation) — behind an interface
- Client: React + Vite + WebRTC (Pipecat client SDK, D-015)
- State: SQLite
praxis.db(D-007, single hardcoded learner, no auth)
Layout
server/ Pipecat pipeline, services (TTS/LLM/Guardrail interfaces), scenario runtime, adapters
client/ React + Vite + WebRTC learner surface
scenarios/ YAML scenario definitions (D-018)
db/ SQLite schema, migrations, async store
scripts/ Latency probes (R1-R4), e2e smoke
tests/ Unit + e2e
docs/ Latency report, debrief templates
Quickstart
- Copy
.env.example→.env, fill inDEEPGRAM_API_KEY,CARTESIA_API_KEY,OLLAMA_API_KEY. - Install server deps:
pip install -e ".[dev]" - Install client deps:
cd client && npm install - Run probes:
python scripts/probe_deepgram.py(etc.) - Run server:
python -m server - Run client:
cd client && npm run dev
See docs/latency-report.md for the R1-R4 spike status and TTS decision.
Description
Releases
15
Languages
Python
81.4%
Shell
13.8%
TypeScript
4.3%
CSS
0.3%
Dockerfile
0.2%