Make API auth mandatory, manage tokens via web UI
BREAKING CHANGE: API authentication is now always required. The PINCHFLAT_API_TOKEN env var is no longer used. Instead, tokens are stored in the database and managed via Settings → API Access. Changes: - Add api_token column to settings table (migration) - ApiAuthPlug reads from DB; returns 401 if no token configured - Add API Access section to Settings page with generate/regenerate/revoke - Add POST /settings/generate_api_token and /settings/revoke_api_token - Remove api_token from config.exs and runtime.exs - Update all API controller tests to set auth token in setup - Update auth plug tests for mandatory authentication - 1008 tests pass, zero warnings
This commit is contained in:
@@ -26,7 +26,6 @@ config :pinchflat,
|
||||
basic_auth_username: "",
|
||||
basic_auth_password: "",
|
||||
expose_feed_endpoints: false,
|
||||
api_token: "",
|
||||
file_watcher_poll_interval: 1000,
|
||||
timezone: "UTC",
|
||||
base_route_path: "/"
|
||||
|
||||
+1
-2
@@ -23,8 +23,7 @@ end
|
||||
|
||||
config :pinchflat,
|
||||
basic_auth_username: System.get_env("BASIC_AUTH_USERNAME"),
|
||||
basic_auth_password: System.get_env("BASIC_AUTH_PASSWORD"),
|
||||
api_token: System.get_env("PINCHFLAT_API_TOKEN")
|
||||
basic_auth_password: System.get_env("BASIC_AUTH_PASSWORD")
|
||||
|
||||
arch_string = to_string(:erlang.system_info(:system_architecture))
|
||||
|
||||
|
||||
@@ -12,10 +12,6 @@ config :pinchflat,
|
||||
|
||||
config :pinchflat, Oban, testing: :manual
|
||||
|
||||
# API token is not set in tests by default — allows tests to run without auth.
|
||||
# Individual tests that need auth can set it via Application.put_env.
|
||||
config :pinchflat, :api_token, nil
|
||||
|
||||
# Configure your database
|
||||
#
|
||||
# The MIX_TEST_PARTITION environment variable can be used
|
||||
|
||||
Reference in New Issue
Block a user