Odstranil jsem hardcoded IP fallbacky z portálového Python kódu:
DEFAULT_APPFACTORY_HOST = "192.168.66.130" je pryč z config.py (line 10). DEFAULT_GITEA_URL = "http://192.168.66.130:3000" je pryč z auth.py (line 24). Doplněné chování: APPFACTORY_HOST se odvozuje přes helper: env APPFACTORY_HOST, potom APPFACTORY_PORTAL_PUBLIC_URL, potom request host. Gitea browser redirect používá jen explicitní veřejnou URL z GITEA_URL nebo GITEA_ROOT_URL. Server-side Gitea token/userinfo requesty používají GITEA_URL, potom GITEA_ROOT_URL, jinak interní Docker URL http://appfactory-gitea:3000. Gitea login tlačítko se zobrazí jen při kompletní konfiguraci: public URL, client id, client secret a redirect URI. Přímý Gitea login bez kompletní konfigurace vrací čitelnou chybu.
This commit is contained in:
+25
-13
@@ -10,12 +10,19 @@ from fastapi import APIRouter, Form, Request
|
||||
from fastapi.responses import HTMLResponse, RedirectResponse
|
||||
|
||||
from app.auth import authenticate_user, current_user, find_or_create_oauth_user
|
||||
from app.config import get_google_redirect_uri, is_google_oauth_button_enabled, read_env_value
|
||||
from app.config import (
|
||||
get_gitea_public_url,
|
||||
get_gitea_redirect_uri,
|
||||
get_gitea_server_url,
|
||||
get_google_redirect_uri,
|
||||
is_gitea_oauth_button_enabled,
|
||||
is_google_oauth_button_enabled,
|
||||
read_env_value,
|
||||
)
|
||||
from app.db.audit import log_audit_event
|
||||
from app.templates.layout import page
|
||||
|
||||
router = APIRouter()
|
||||
DEFAULT_GITEA_URL = "http://192.168.66.130:3000"
|
||||
GOOGLE_AUTH_URL = "https://accounts.google.com/o/oauth2/v2/auth"
|
||||
GOOGLE_TOKEN_URL = "https://oauth2.googleapis.com/token"
|
||||
GOOGLE_USERINFO_URL = "https://openidconnect.googleapis.com/v1/userinfo"
|
||||
@@ -54,12 +61,13 @@ def gitea_login(request: Request):
|
||||
if current_user(request):
|
||||
return RedirectResponse(url="/portal/operations", status_code=303)
|
||||
|
||||
gitea_url = read_env_value("GITEA_URL", DEFAULT_GITEA_URL).rstrip("/")
|
||||
gitea_url = get_gitea_public_url()
|
||||
client_id = read_env_value("GITEA_OAUTH_CLIENT_ID", "")
|
||||
redirect_uri = read_env_value("GITEA_OAUTH_REDIRECT_URI", "")
|
||||
if not client_id or not redirect_uri:
|
||||
client_secret = read_env_value("GITEA_OAUTH_CLIENT_SECRET", "")
|
||||
redirect_uri = get_gitea_redirect_uri()
|
||||
if not gitea_url or not client_id or not client_secret or not redirect_uri:
|
||||
_log_gitea_failure("missing_oauth_config")
|
||||
return _render_login("Přihlášení přes Gitea není správně nastavené.")
|
||||
return _render_login("Gitea login is not fully configured.")
|
||||
|
||||
state = secrets.token_urlsafe(32)
|
||||
request.session["gitea_oauth_state"] = state
|
||||
@@ -227,10 +235,10 @@ def logout(request: Request):
|
||||
|
||||
|
||||
def _exchange_gitea_code(code: str) -> str:
|
||||
gitea_url = read_env_value("GITEA_URL", DEFAULT_GITEA_URL).rstrip("/")
|
||||
gitea_url = get_gitea_server_url()
|
||||
client_id = read_env_value("GITEA_OAUTH_CLIENT_ID", "")
|
||||
client_secret = read_env_value("GITEA_OAUTH_CLIENT_SECRET", "")
|
||||
redirect_uri = read_env_value("GITEA_OAUTH_REDIRECT_URI", "")
|
||||
redirect_uri = get_gitea_redirect_uri()
|
||||
if not client_id or not client_secret or not redirect_uri:
|
||||
raise RuntimeError("Missing Gitea OAuth configuration")
|
||||
|
||||
@@ -260,7 +268,7 @@ def _exchange_gitea_code(code: str) -> str:
|
||||
|
||||
|
||||
def _fetch_gitea_user(access_token: str) -> dict:
|
||||
gitea_url = read_env_value("GITEA_URL", DEFAULT_GITEA_URL).rstrip("/")
|
||||
gitea_url = get_gitea_server_url()
|
||||
request = UrlRequest(
|
||||
f"{gitea_url}/api/v1/user",
|
||||
headers={
|
||||
@@ -350,6 +358,13 @@ def _render_login(error: str | None = None) -> str:
|
||||
error_html = ""
|
||||
if error:
|
||||
error_html = f'<p class="alert alert-danger">{html.escape(error)}</p>'
|
||||
gitea_login_html = ""
|
||||
if is_gitea_oauth_button_enabled():
|
||||
gitea_login_html = """
|
||||
<p>
|
||||
<a class="btn" href="/portal/auth/gitea/login">Sign in with Gitea</a>
|
||||
</p>
|
||||
"""
|
||||
google_login_html = ""
|
||||
if is_google_oauth_button_enabled():
|
||||
google_login_html = """
|
||||
@@ -365,10 +380,7 @@ def _render_login(error: str | None = None) -> str:
|
||||
<h2>CSBot Services Portal</h2>
|
||||
<p class="muted">Doporučené přihlášení je přes Gitea. Lokální účet slouží pouze jako nouzový administrátorský přístup.</p>
|
||||
{error_html}
|
||||
|
||||
<p>
|
||||
<a class="btn" href="/portal/auth/gitea/login">Přihlásit přes Gitea</a>
|
||||
</p>
|
||||
{gitea_login_html}
|
||||
|
||||
{google_login_html}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user