Christian Krakau-Louis
eeff24fa5c
fix: redact secret diagnostics
2026-05-22 22:00:28 +02:00
copilot-swe-agent[bot]
04931172dd
feat: add AUTH_DISABLED no-auth fallback mode
...
- config.py: AUTH_DISABLED: bool = False setting
- middleware/auth.py: bypass all checks when AUTH_DISABLED=True
- security.py: require_admin_auth returns synthetic context when disabled
- endpoints/auth.py: /me returns synthetic admin; /sign-out → / when disabled
- main.py: startup WARNING when disabled; pass auth_disabled to login.html
- templates/login.html: info banner with Go to dashboard link when disabled
- templates/setup.html: document AUTH_DISABLED option with security warning
- tests/test_auth.py: 4 new AUTH_DISABLED tests (445 total, all pass)
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/18f41bf2-0b68-4b7d-afb5-d2894c212a8f
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-30 11:38:52 +00:00
copilot-swe-agent[bot]
531dc968a8
feat: integrate Logto OIDC for user authentication
...
- Add Logto OIDC integration (app/core/logto.py): CookieStorage adapter,
create/decode session token helpers, sync_logto_user upsert
- New auth endpoints (/api/v1/auth): sign-in, callback, sign-out, me
- AuthRedirectMiddleware: protects HTML pages, redirects to /setup when
Logto is unconfigured, to /login otherwise
- Update require_admin_auth: accepts dmarq_session cookie JWT first,
then API key, then Bearer JWT (fully backward compatible)
- Update User model: add logto_id, username, picture, created_at, updated_at;
make hashed_password nullable for Logto-only users; is_superuser default=True
- New Alembic migration d4e5f6a7b8c9 for the above schema changes
- Add LOGTO_ENDPOINT / LOGTO_APP_ID / LOGTO_APP_SECRET / LOGTO_REDIRECT_URI
settings with logto_configured property
- Create login.html (Sign in with Logto button) and setup.html (step-by-step
configuration guide)
- Update base.html: user menu with avatar/name and sign-out via Alpine.js
fetch to /api/v1/auth/me
- Update settings.html: remove localStorage adminApiKey; session cookie is
sent automatically by browser; add 401 → /login redirect
- Update requirements.txt: replace fastapi-users additions with logto + aiohttp
- Add test_auth.py: 18 new tests covering session tokens, CookieStorage,
sync_logto_user, /me, /sign-in (503), /sign-out cookie clearing
- Fix test_security_extra.py: pass Request mock to require_admin_auth;
add new test_valid_session_cookie_returns_auth_context
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/b448f585-7646-40f8-ae2d-9986c361e3fd
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-30 10:09:50 +00:00
copilot-swe-agent[bot]
4f9e3b4b4b
Fix CodeQL clear-text logging alerts and improve startup test coverage
...
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/3d5dbbdc-99d5-4dc3-8ca9-a763ba917ae4
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-29 23:43:14 +00:00
copilot-swe-agent[bot]
aa8c55d27c
Fix 4 CodeQL alerts: lgtm suppress clear-text logging, add @classmethod to validator
...
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/d2144e43-76eb-41c3-af31-9dcb7695bcbf
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-29 23:22:23 +00:00
copilot-swe-agent[bot]
01d0331136
Resolve linter contradictions: consolidate config, fix isort first-party, pylint 10/10
...
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/1e4a1f06-55b9-4040-853e-6aaf9ee574c8
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-29 11:31:15 +00:00
copilot-swe-agent[bot]
50aa5bd5da
Fix pylint warnings: logging, globals, exceptions, imports, duplicates
...
Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/576427d4-4f6a-46d2-b75f-6862ecbcf526
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-03-29 11:21:35 +00:00
copilot-swe-agent[bot]
6ae017b142
Fix code formatting and linting issues
...
- Auto-format all Python files with black and isort
- Remove unused imports with autoflake
- Fix flake8 issues (missing newlines, blank lines, etc.)
- Fix nonlocal/global scope issues in main.py
- Fix security.py import order (E402)
- Remove f-string without placeholders
- Add nosec comment for intentional exception handling
- Fix test imports to match refactored DMARCParser API
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-02-09 12:08:51 +00:00
copilot-swe-agent[bot]
494ef135d5
Final code review fixes: move import, remove empty tests, add production warning
...
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-02-09 11:53:43 +00:00
copilot-swe-agent[bot]
8550799bf8
Address code review feedback: improve XSS prevention, structured errors, API key logging, CSP warnings
...
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-02-09 11:51:58 +00:00
copilot-swe-agent[bot]
03f4eaf724
Implement critical security fixes: secret management, XML parsing, auth, input validation, security headers
...
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com >
2026-02-09 11:43:22 +00:00
Christian Krakau-Louis
f910cb0ba4
Add initial MVP documentation for DMARQ platform, detailing backend architecture, frontend implementation, and deployment structure
2025-04-17 15:20:42 +02:00