P0.1 — fail-closed secrets: - config.py: no default SECRET_KEY; refuses to boot when unset, a known placeholder, or <32 chars. Generate with: openssl rand -hex 32. - docker-compose.yml: literal secrets removed; runtime env now comes from a git-ignored .env via env_file. .env.example added as template. - .gitignore already covers .env (verified). P0.2 — locked CORS: - main.py: CORS_ORIGINS must be an explicit comma-separated allow-list. '*' or an empty value refuses to boot (was: silently ['*'] with allow_credentials=True). P0.3 — role-safe registration: - services/auth.py: client-supplied 'role' is IGNORED on POST /api/auth/register; self-registered users always get the least-privilege 'CS Rep' role. Unauthenticated callers can no longer mint Admin/Jerome, Admin/Wahab, or Director accounts. Tests: - conftest.py sets test SECRET_KEY/CORS_ORIGINS before app import. - New tests/test_p0_hardening.py (8 tests): role-escalation blocked for Admin/Jerome and Admin/Wahab, duplicate-email 409, and subprocess boot-validation for placeholder/short/missing secret + wildcard CORS. - Full suite: 44 passed. Redeploy note (per research): seed_units/seed_categories are insert-only, so the Aug-26 redeploy does NOT orphan historical tickets referencing units 103E/103W/105E/105W or the legacy 34-category tree. Pending Wahab: are 103E/103W/105E/105W real apartments dropped from the Excel regeneration? Optional follow-up: floor-number backfill for already- seeded units (mapping corrected floors; existing rows keep old values). Checks per HARDENING.md acceptance: - [x] starting without a real key fails loudly (subprocess-verified) - [x] compose carries no literal secret; secrets come from .env - [x] CORS_ORIGINS explicit allow-list, '*' rejected - [x] unauthenticated register cannot mint Admin/* or Director
63 lines
2.8 KiB
Python
63 lines
2.8 KiB
Python
"""Application configuration via Pydantic-settings environment variables."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from pathlib import Path
|
|
|
|
from pydantic_settings import BaseSettings, SettingsConfigDict
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
model_config = SettingsConfigDict(
|
|
env_file=".env",
|
|
env_file_encoding="utf-8",
|
|
case_sensitive=False,
|
|
extra="ignore",
|
|
)
|
|
|
|
# ── App ──────────────────────────────────────────────────────────
|
|
APP_NAME: str = "Denya OneCare"
|
|
DEBUG: bool = False
|
|
|
|
# ── Database ─────────────────────────────────────────────────────
|
|
DATABASE_URL: str = "sqlite+aiosqlite:///./denya_onecare.db"
|
|
|
|
# ── Auth ─────────────────────────────────────────────────────────
|
|
SECRET_KEY: str = ""
|
|
ALGORITHM: str = "HS256"
|
|
ACCESS_TOKEN_EXPIRE_MINUTES: int = 60 # Phase 1: raised 30 -> 60 for fewer re-logins
|
|
REFRESH_TOKEN_EXPIRE_MINUTES: int = 60 * 24 * 7 # 7 days
|
|
|
|
# ── CORS ─────────────────────────────────────────────────────────
|
|
CORS_ORIGINS: str = "*"
|
|
|
|
# ── WhatsApp ─────────────────────────────────────────────────────
|
|
WHATSAPP_PHONE_NUMBER_ID: str = ""
|
|
WHATSAPP_ACCESS_TOKEN: str = ""
|
|
WHATSAPP_VERIFY_TOKEN: str = ""
|
|
META_GRAPH_BASE: str = "https://graph.facebook.com/v18.0"
|
|
|
|
# ── Paths ────────────────────────────────────────────────────────
|
|
BASE_DIR: Path = Path(__file__).resolve().parent.parent.parent
|
|
|
|
|
|
settings = Settings()
|
|
|
|
# ── Fail-closed secret validation (HARDENING.md P0.1) ─────────────────
|
|
# Refuse to boot without a real SECRET_KEY. Devs must create a local .env
|
|
# (see .env.example); production injects it via docker-compose env_file.
|
|
_KNOWN_PLACEHOLDER_SECRETS = {
|
|
"",
|
|
"change-me-in-production",
|
|
"change-me-in-production-use-a-real-secret",
|
|
"changeme",
|
|
"secret",
|
|
}
|
|
|
|
if settings.SECRET_KEY in _KNOWN_PLACEHOLDER_SECRETS or len(settings.SECRET_KEY) < 32:
|
|
raise RuntimeError(
|
|
"SECRET_KEY is missing, a known placeholder, or shorter than 32 chars. "
|
|
"Generate one with: openssl rand -hex 32 — and set it in .env "
|
|
"(dev) or the runtime environment (prod). Refusing to start."
|
|
)
|