Make API auth mandatory, manage tokens via web UI
Nix Flake Check / Nix Flake Check (push) Successful in 1m55s
Build and Test / Build and Test (push) Successful in 8m25s

BREAKING CHANGE: API authentication is now always required. The
PINCHFLAT_API_TOKEN env var is no longer used. Instead, tokens are
stored in the database and managed via Settings → API Access.

Changes:
- Add api_token column to settings table (migration)
- ApiAuthPlug reads from DB; returns 401 if no token configured
- Add API Access section to Settings page with generate/regenerate/revoke
- Add POST /settings/generate_api_token and /settings/revoke_api_token
- Remove api_token from config.exs and runtime.exs
- Update all API controller tests to set auth token in setup
- Update auth plug tests for mandatory authentication
- 1008 tests pass, zero warnings
This commit is contained in:
2026-07-04 11:51:40 +00:00
parent 7ec48045ce
commit 75f75d8d19
16 changed files with 164 additions and 34 deletions
+3 -1
View File
@@ -17,7 +17,8 @@ defmodule Pinchflat.Settings.Setting do
:youtube_api_key,
:extractor_sleep_interval_seconds,
:download_throughput_limit,
:restrict_filenames
:restrict_filenames,
:api_token
]
@required_fields [
@@ -40,6 +41,7 @@ defmodule Pinchflat.Settings.Setting do
# This is a string because it accepts values like "100K" or "4.2M"
field :download_throughput_limit, :string
field :restrict_filenames, :boolean, default: false
field :api_token, :string
field :video_codec_preference, :string
field :audio_codec_preference, :string
+9 -9
View File
@@ -2,21 +2,21 @@ defmodule PinchflatWeb.ApiAuthPlug do
@moduledoc """
Authenticates API requests using a Bearer token.
The token is read from the `PINCHFLAT_API_TOKEN` environment variable.
If the environment variable is not set, API authentication is disabled
(useful for development and testing). In production, you should always
set this to a secure value.
The token is stored in the settings database and managed via the web UI.
A token must be generated before API access is possible — the API is
always authenticated, there is no open-access mode.
Clients should send the token in the Authorization header:
Authorization: Bearer <token>
"""
import Plug.Conn
alias Pinchflat.Settings
def init(opts), do: opts
def call(conn, _opts) do
expected_token = Application.get_env(:pinchflat, :api_token)
expected_token = Settings.get!(:api_token)
if credential_set?(expected_token) do
case get_req_header(conn, "authorization") do
@@ -31,8 +31,8 @@ defmodule PinchflatWeb.ApiAuthPlug do
send_unauthorized(conn)
end
else
# No API token configured — allow access (dev/test mode)
conn
# No API token has been generated yet — deny all access
send_unauthorized(conn, "API token not configured. Generate one in Settings.")
end
end
@@ -40,10 +40,10 @@ defmodule PinchflatWeb.ApiAuthPlug do
credential && credential != ""
end
defp send_unauthorized(conn) do
defp send_unauthorized(conn, message \\ "Unauthorized") do
conn
|> put_resp_content_type("application/json")
|> send_resp(401, ~s({"errors":{"detail":"Unauthorized"}}))
|> send_resp(401, ~s({"errors":{"detail":"#{message}"}}))
|> halt()
end
end
@@ -28,6 +28,36 @@ defmodule PinchflatWeb.Settings.SettingController do
render(conn, "app_info.html")
end
def generate_api_token(conn, _params) do
token = :crypto.strong_rand_bytes(32) |> Base.url_encode64(padding: false)
case Settings.set(api_token: token) do
{:ok, _} ->
conn
|> put_flash(:info, "API token generated successfully.")
|> redirect(to: ~p"/settings")
{:error, _} ->
conn
|> put_flash(:error, "Failed to generate API token.")
|> redirect(to: ~p"/settings")
end
end
def revoke_api_token(conn, _params) do
case Settings.set(api_token: nil) do
{:ok, _} ->
conn
|> put_flash(:info, "API token revoked.")
|> redirect(to: ~p"/settings")
{:error, _} ->
conn
|> put_flash(:error, "Failed to revoke API token.")
|> redirect(to: ~p"/settings")
end
end
def download_logs(conn, _params) do
log_path = Application.get_env(:pinchflat, :log_path)
@@ -26,6 +26,44 @@
)}
</section>
<section class="mt-8">
<h3 class="text-2xl text-black dark:text-white">
API Access
</h3>
<p class="text-sm mt-2 max-w-prose text-bodydark2">
Generate a token to authenticate requests to the <code class="font-mono">/api/v1</code> REST API.
Required for MCP server integration and other programmatic clients.
Send it as <code class="font-mono">Authorization: Bearer &lt;token&gt;</code>.
</p>
<div class="mt-4">
<%= if Settings.get!(:api_token) do %>
<div class="flex items-center gap-3 flex-wrap">
<code class="font-mono text-sm bg-meta-2 dark:bg-meta-4 px-3 py-2 rounded break-all">
{String.slice(Settings.get!(:api_token), 0, 12)}••••••••
</code>
<.link href={~p"/settings/generate_api_token"} method="post">
<.button rounding="rounded-lg" class="bg-warning hover:bg-warning/80">Regenerate Token</.button>
</.link>
<.link
href={~p"/settings/revoke_api_token"}
method="post"
data-confirm="Are you sure? This will immediately disable all API access."
>
<.button rounding="rounded-lg" class="bg-danger hover:bg-danger/80">Revoke Token</.button>
</.link>
</div>
<% else %>
<p class="text-sm text-danger mb-3">
No API token configured. The API is currently inaccessible.
</p>
<.link href={~p"/settings/generate_api_token"} method="post">
<.button rounding="rounded-lg" class="bg-primary hover:bg-primary/80">Generate API Token</.button>
</.link>
<% end %>
</div>
</section>
<section class="mt-8">
<section>
<h3 class="text-2xl text-black dark:text-white">
+2
View File
@@ -52,6 +52,8 @@ defmodule PinchflatWeb.Router do
resources "/search", Searches.SearchController, only: [:show], singleton: true
resources "/settings", Settings.SettingController, only: [:show, :update], singleton: true
post "/settings/generate_api_token", Settings.SettingController, :generate_api_token
post "/settings/revoke_api_token", Settings.SettingController, :revoke_api_token
get "/app_info", Settings.SettingController, :app_info
get "/download_logs", Settings.SettingController, :download_logs