- Remove POST /api/auth/register (404); no sign-up UI; users are admin-managed - Add admin-only POST/PATCH/DELETE /api/auth/users (forced canonical roles, self-lockout + reference guards) - Unify role model in app/core/roles.py; reject unknown roles at creation and at login/JWT validation; startup normalizes unambiguous legacy aliases - Login rate limiting ~5 fails/15 min per IP+email -> 429 (in-process, tunable) - WhatsApp webhook requires X-Webhook-Secret; fail-closed when env unset; GET handshake uses constant-time verify token (403 on mismatch) - GET /api/whatsapp/mock-log now requires auth - Security headers middleware: X-Frame-Options DENY, nosniff, CSP on HTML, HSTS behind TLS - Pagination: limit alias for page_size, hard cap enforced, both -> 422
27 lines
1.3 KiB
Bash
27 lines
1.3 KiB
Bash
# Denya OneCare — runtime environment template (HARDENING.md P0.1/P1.1)
|
|
# Copy to .env and fill in real values. NEVER commit .env.
|
|
# Generate the secret with: openssl rand -hex 32
|
|
|
|
# ── Required ─────────────────────────────────────────────
|
|
SECRET_KEY=
|
|
DATABASE_URL=sqlite+aiosqlite:///./data/denya_onecare.db
|
|
# Explicit origin allow-list — "*" is rejected at startup (P0.2)
|
|
CORS_ORIGINS=http://localhost:8000
|
|
|
|
# ── Optional (WhatsApp; needed before wiring Meta) ───────
|
|
WHATSAPP_PHONE_NUMBER_ID=
|
|
WHATSAPP_ACCESS_TOKEN=
|
|
WHATSAPP_VERIFY_TOKEN=
|
|
META_GRAPH_BASE=https://graph.facebook.com/v18.0
|
|
|
|
# ── Webhook auth (P0) ──────────────────────────────────
|
|
# Shared secret for inbound WhatsApp webhook POSTs (X-Webhook-Secret header).
|
|
# FAIL-CLOSED: when unset/empty, every webhook message is rejected (403).
|
|
# Generate with: openssl rand -hex 32
|
|
WHATSAPP_WEBHOOK_SECRET=
|
|
|
|
# ── Login rate limiting (P0) ────────────────────────────
|
|
# ~5 failed login attempts per 15 minutes per IP+email → HTTP 429
|
|
LOGIN_RATE_LIMIT_MAX_ATTEMPTS=5
|
|
LOGIN_RATE_LIMIT_WINDOW_SECONDS=900
|