Files
pinchflat/lib/pinchflat_web/api_auth_plug.ex
T
hermes-agent 75f75d8d19
Nix Flake Check / Nix Flake Check (push) Successful in 1m55s
Build and Test / Build and Test (push) Successful in 8m25s
Make API auth mandatory, manage tokens via web UI
BREAKING CHANGE: API authentication is now always required. The
PINCHFLAT_API_TOKEN env var is no longer used. Instead, tokens are
stored in the database and managed via Settings → API Access.

Changes:
- Add api_token column to settings table (migration)
- ApiAuthPlug reads from DB; returns 401 if no token configured
- Add API Access section to Settings page with generate/regenerate/revoke
- Add POST /settings/generate_api_token and /settings/revoke_api_token
- Remove api_token from config.exs and runtime.exs
- Update all API controller tests to set auth token in setup
- Update auth plug tests for mandatory authentication
- 1008 tests pass, zero warnings
2026-07-04 11:51:40 +00:00

50 lines
1.3 KiB
Elixir

defmodule PinchflatWeb.ApiAuthPlug do
@moduledoc """
Authenticates API requests using a Bearer token.
The token is stored in the settings database and managed via the web UI.
A token must be generated before API access is possible — the API is
always authenticated, there is no open-access mode.
Clients should send the token in the Authorization header:
Authorization: Bearer <token>
"""
import Plug.Conn
alias Pinchflat.Settings
def init(opts), do: opts
def call(conn, _opts) do
expected_token = Settings.get!(:api_token)
if credential_set?(expected_token) do
case get_req_header(conn, "authorization") do
["Bearer " <> token] ->
if String.trim(token) == expected_token do
conn
else
send_unauthorized(conn)
end
_ ->
send_unauthorized(conn)
end
else
# No API token has been generated yet — deny all access
send_unauthorized(conn, "API token not configured. Generate one in Settings.")
end
end
defp credential_set?(credential) do
credential && credential != ""
end
defp send_unauthorized(conn, message \\ "Unauthorized") do
conn
|> put_resp_content_type("application/json")
|> send_resp(401, ~s({"errors":{"detail":"#{message}"}}))
|> halt()
end
end