75f75d8d19
BREAKING CHANGE: API authentication is now always required. The PINCHFLAT_API_TOKEN env var is no longer used. Instead, tokens are stored in the database and managed via Settings → API Access. Changes: - Add api_token column to settings table (migration) - ApiAuthPlug reads from DB; returns 401 if no token configured - Add API Access section to Settings page with generate/regenerate/revoke - Add POST /settings/generate_api_token and /settings/revoke_api_token - Remove api_token from config.exs and runtime.exs - Update all API controller tests to set auth token in setup - Update auth plug tests for mandatory authentication - 1008 tests pass, zero warnings
50 lines
1.3 KiB
Elixir
50 lines
1.3 KiB
Elixir
defmodule PinchflatWeb.ApiAuthPlug do
|
|
@moduledoc """
|
|
Authenticates API requests using a Bearer token.
|
|
|
|
The token is stored in the settings database and managed via the web UI.
|
|
A token must be generated before API access is possible — the API is
|
|
always authenticated, there is no open-access mode.
|
|
|
|
Clients should send the token in the Authorization header:
|
|
Authorization: Bearer <token>
|
|
"""
|
|
|
|
import Plug.Conn
|
|
alias Pinchflat.Settings
|
|
|
|
def init(opts), do: opts
|
|
|
|
def call(conn, _opts) do
|
|
expected_token = Settings.get!(:api_token)
|
|
|
|
if credential_set?(expected_token) do
|
|
case get_req_header(conn, "authorization") do
|
|
["Bearer " <> token] ->
|
|
if String.trim(token) == expected_token do
|
|
conn
|
|
else
|
|
send_unauthorized(conn)
|
|
end
|
|
|
|
_ ->
|
|
send_unauthorized(conn)
|
|
end
|
|
else
|
|
# No API token has been generated yet — deny all access
|
|
send_unauthorized(conn, "API token not configured. Generate one in Settings.")
|
|
end
|
|
end
|
|
|
|
defp credential_set?(credential) do
|
|
credential && credential != ""
|
|
end
|
|
|
|
defp send_unauthorized(conn, message \\ "Unauthorized") do
|
|
conn
|
|
|> put_resp_content_type("application/json")
|
|
|> send_resp(401, ~s({"errors":{"detail":"#{message}"}}))
|
|
|> halt()
|
|
end
|
|
end
|