feat: streamline platform and secure data access
- move the relational data center to MySQL and a standalone workbench\n- add Interface Center API credentials, policies, logs, and DBeaver SSH guidance\n- harden authentication and deployment while retiring unused management surfaces
This commit is contained in:
1 parent
15368f2779
commit
3dd5731751
137 files changed
+8571
-14151
No files matched your search
+30
-4
@@ -1,17 +1,43 @@
|
||||
"""Auth endpoints — login / me."""
|
||||
from fastapi import APIRouter, Depends, HTTPException
|
||||
"""Auth endpoints — login / me with brute-force protection."""
|
||||
from fastapi import APIRouter, HTTPException, Request
|
||||
|
||||
from app.auth import authenticate, create_access_token, CurrentUser, get_current_user
|
||||
from app.config import settings
|
||||
from app.contracts import LoginRequest, TokenResponse
|
||||
from app.rate_limit import FixedWindowLimiter
|
||||
|
||||
router = APIRouter()
|
||||
_login_limiter = FixedWindowLimiter(
|
||||
limit=settings.auth_login_max_attempts,
|
||||
window_seconds=settings.auth_login_window_seconds,
|
||||
block_seconds=settings.auth_login_lock_seconds,
|
||||
)
|
||||
|
||||
|
||||
@router.post("/auth/login", response_model=TokenResponse)
|
||||
async def login(body: LoginRequest):
|
||||
user = await authenticate(body.username, body.password)
|
||||
async def login(body: LoginRequest, request: Request):
|
||||
username = body.username.strip()
|
||||
source_ip = request.client.host if request.client else "unknown"
|
||||
keys = (f"ip:{source_ip}", f"account:{username.casefold()}")
|
||||
retry_after = max([await _login_limiter.check(key) for key in keys], default=0)
|
||||
if retry_after:
|
||||
raise HTTPException(
|
||||
429,
|
||||
detail="登录尝试过多,请稍后重试",
|
||||
headers={"Retry-After": str(retry_after)},
|
||||
)
|
||||
user = await authenticate(username, body.password)
|
||||
if not user:
|
||||
retry_after = max([await _login_limiter.record(key) for key in keys], default=0)
|
||||
if retry_after:
|
||||
raise HTTPException(
|
||||
429,
|
||||
detail="登录尝试过多,请稍后重试",
|
||||
headers={"Retry-After": str(retry_after)},
|
||||
)
|
||||
raise HTTPException(401, detail="Invalid credentials")
|
||||
for key in keys:
|
||||
await _login_limiter.reset(key)
|
||||
token = create_access_token({"sub": user["username"], "roles": user.get("roles", [])})
|
||||
return TokenResponse(access_token=token)
|
||||
|
||||
|
||||
Reference in new issue
Block a user