feat(auth): add comprehensive debug logging for local login failures
Add detailed diagnostic log statements throughout the local authentication path to help identify why valid local user logins are failing. Changes: - app/auth.py: log received username, multi_user_enabled status, LocalUser DB lookup result, is_active status, password verification outcome, and the specific failure reason (empty_username / wrong_password / no_match) at every decision point. Also log form keys and Content-Type header on empty-username failures to detect Starlette body-consumption issues. - app/middleware/csrf.py: log Content-Type, form field names, and whether the CSRF token was present in _get_submitted_token() to reveal if the middleware is consuming form data before the endpoint can read it. - app/utils/local_auth.py: verify_password() now logs DEBUG on mismatch and WARNING (with exception type) on unexpected bcrypt errors instead of silently swallowing exceptions. Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -148,10 +148,16 @@ class CSRFMiddleware(BaseHTTPMiddleware):
|
||||
|
||||
# 2. For URL-encoded form bodies only (plain HTML form submissions).
|
||||
content_type = request.headers.get("content-type", "")
|
||||
logger.debug("CSRF: content_type=%r method=%s path=%s", content_type, request.method, request.url.path)
|
||||
if "application/x-www-form-urlencoded" in content_type:
|
||||
try:
|
||||
form = await request.form()
|
||||
token = form.get("csrf_token")
|
||||
logger.debug(
|
||||
"CSRF: form_keys=%s csrf_token_present=%s",
|
||||
list(form.keys()),
|
||||
bool(token),
|
||||
)
|
||||
if token:
|
||||
return str(token)
|
||||
except Exception as exc:
|
||||
|
||||
Reference in New Issue
Block a user