feat: add AUTH_DISABLED no-auth fallback mode
- config.py: AUTH_DISABLED: bool = False setting - middleware/auth.py: bypass all checks when AUTH_DISABLED=True - security.py: require_admin_auth returns synthetic context when disabled - endpoints/auth.py: /me returns synthetic admin; /sign-out → / when disabled - main.py: startup WARNING when disabled; pass auth_disabled to login.html - templates/login.html: info banner with Go to dashboard link when disabled - templates/setup.html: document AUTH_DISABLED option with security warning - tests/test_auth.py: 4 new AUTH_DISABLED tests (445 total, all pass) Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/18f41bf2-0b68-4b7d-afb5-d2894c212a8f Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -300,6 +300,18 @@ def create_app() -> FastAPI:
|
||||
# Ensure all tables exist (no-op if already present)
|
||||
Base.metadata.create_all(bind=engine)
|
||||
|
||||
# Warn loudly when authentication is completely disabled
|
||||
if settings.AUTH_DISABLED:
|
||||
logger.warning(
|
||||
"%s\n"
|
||||
"⚠️ AUTH_DISABLED=true — authentication is turned OFF.\n"
|
||||
"All requests have unrestricted admin access.\n"
|
||||
"Do NOT expose this instance directly to the internet.\n"
|
||||
"%s",
|
||||
"=" * 80,
|
||||
"=" * 80,
|
||||
)
|
||||
|
||||
# Load or generate the admin API key
|
||||
if settings.ADMIN_API_KEY:
|
||||
api_key = settings.ADMIN_API_KEY
|
||||
@@ -373,6 +385,7 @@ async def login(request: Request, next: str = "/"):
|
||||
{
|
||||
"app_name": settings.PROJECT_NAME,
|
||||
"logto_configured": settings.logto_configured,
|
||||
"auth_disabled": settings.AUTH_DISABLED,
|
||||
"next": next,
|
||||
},
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user