add auth system and split backend into two-image CI/CD build
Some checks failed
Build and Push / build (push) Failing after 17s
Some checks failed
Build and Push / build (push) Failing after 17s
Backend:
- password hashing via hashlib.scrypt
- stateless HMAC-SHA256 tokens (7-day expiry)
- POST /api/auth/login, /api/auth/register (admin), /api/auth/reset-password
- admin user created from NAT20_ADMIN_USERNAME/PASSWORD on first startup
- users table, campaign_shares table, created_by on campaigns
- require_user dependency on all routes except auth
- campaign sharing: GET/POST/DELETE /api/campaigns/{id}/shares
Frontend:
- AuthContext: user/token state, login/logout, global fetch Auth header
- Login page, Users page (admin user management)
- route protection, sidebar user info/sign out
Docker/CI:
- split backend/Dockerfile into thin app-only image
- backend/Dockerfile.deps builds the heavy WhisperX/PyTorch base
- CI builds deps only when requirements.txt changes
- docker compose pull now fetches ~100KB app layer instead of 3.5GB
This commit is contained in:
@@ -28,6 +28,11 @@ def campaign_transcript_dir(campaign_id: str) -> Path:
|
||||
def campaign_notes_dir(campaign_id: str) -> Path:
|
||||
return campaign_dir(campaign_id) / "notes"
|
||||
|
||||
# Auth config
|
||||
JWT_SECRET = os.environ.get("NAT20_JWT_SECRET", os.urandom(32).hex())
|
||||
ADMIN_USERNAME = os.environ.get("NAT20_ADMIN_USERNAME", "admin")
|
||||
ADMIN_PASSWORD = os.environ.get("NAT20_ADMIN_PASSWORD", "admin")
|
||||
|
||||
for d in (UPLOAD_DIR, AUDIO_DIR, TRANSCRIPT_DIR, NOTES_DIR):
|
||||
d.mkdir(parents=True, exist_ok=True)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user