feat: session auth + per-user/persona UI at /{user}/{persona}
Replaces nginx basic auth with a proper per-user session system:
- auth_utils.py: bcrypt password hashing, JWT cookie creation/decode
- auth_middleware.py: validates JWT cookie on all routes except /login,
/health, /static/, and webhook endpoints (/channels/, /webhook/)
- routers/ui.py: GET /login, POST /login, POST /logout,
GET /{username}/{persona} — serves index.html with CORTEX_CONFIG injected
- static/login.html: minimal login form (dark theme, matches UI)
- main.py: registers SessionAuthMiddleware + ui.router
- config.py: jwt_secret, jwt_expire_days settings
- manage_passwords.py: CLI tool to set/check/list user passwords
- app.js: reads window.CORTEX_CONFIG (user + persona), sends both on
every /chat and /orchestrate request; persona name shown in header;
logout button (⏏) added to header
- requirements.txt: bcrypt, PyJWT, python-multipart
- .env.default: JWT_SECRET, JWT_EXPIRE_DAYS documented
- tests: client fixture injects JWT cookie; security test assertions
updated for URL-normalized path traversal paths (still secure, codes differ)
All 80 tests pass.
Setup for a new user:
python manage_passwords.py set scott
python manage_passwords.py set holly
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -66,7 +66,11 @@ def _make_persona(root: Path, username: str, persona: str,
|
||||
|
||||
@pytest_asyncio.fixture
|
||||
async def client(home_root, tmp_path):
|
||||
"""HTTPX async test client against the live ASGI app with patched paths."""
|
||||
"""
|
||||
HTTPX async test client with a valid session cookie for 'scott'.
|
||||
The auth middleware is active but a JWT cookie is pre-set so API tests
|
||||
don't need to go through the login flow.
|
||||
"""
|
||||
import config
|
||||
import persona as persona_mod
|
||||
|
||||
@@ -76,15 +80,20 @@ async def client(home_root, tmp_path):
|
||||
with (
|
||||
patch.object(config.settings, "home_dir", home_root),
|
||||
patch.object(config.settings, "sessions_dir", sessions_dir),
|
||||
patch.object(config.settings, "jwt_secret", "test-secret-key-xxxxxxxxxxxxxxxx"),
|
||||
patch("scheduler.start"), # don't run APScheduler in tests
|
||||
patch("scheduler.stop"),
|
||||
):
|
||||
persona_mod.set_context("scott", "inara")
|
||||
|
||||
from main import app
|
||||
from auth_utils import create_token
|
||||
token = create_token("scott")
|
||||
|
||||
async with httpx.AsyncClient(
|
||||
transport=ASGITransport(app=app),
|
||||
base_url="http://test",
|
||||
cookies={"cortex_session": token},
|
||||
) as c:
|
||||
yield c
|
||||
|
||||
|
||||
Reference in New Issue
Block a user