Security hardening + bug fixes: rotate admin pw, /api/v1/dedicated/locations alias (404 fix), rate-limit login/signup, SameSite+HttpOnly session cookies, protect /dedicated/poll (403), whitelist admin.py set_field
This commit is contained in:
6
admin.py
6
admin.py
@@ -32,7 +32,13 @@ def set_country(username, country):
|
||||
print(f"OK {username} country={country}")
|
||||
|
||||
|
||||
ALLOWED_FIELDS = {"country", "city", "region", "sticky", "active", "balance_gb"}
|
||||
|
||||
|
||||
def set_field(username, field, value):
|
||||
if field not in ALLOWED_FIELDS:
|
||||
print(f"ERROR: field '{field}' not allowed (whitelist: {sorted(ALLOWED_FIELDS)})")
|
||||
return
|
||||
d = db.get_db()
|
||||
d.execute(f"UPDATE users SET {field}=? WHERE username=?", (value, username))
|
||||
d.commit()
|
||||
|
||||
Reference in New Issue
Block a user