Security hardening + bug fixes: rotate admin pw, /api/v1/dedicated/locations alias (404 fix), rate-limit login/signup, SameSite+HttpOnly session cookies, protect /dedicated/poll (403), whitelist admin.py set_field

This commit is contained in:
drjones
2026-09-20 12:18:05 -07:00
parent 0cb80be87f
commit e94c5cfd0c
2 changed files with 28 additions and 2 deletions

View File

@@ -32,7 +32,13 @@ def set_country(username, country):
print(f"OK {username} country={country}")
ALLOWED_FIELDS = {"country", "city", "region", "sticky", "active", "balance_gb"}
def set_field(username, field, value):
if field not in ALLOWED_FIELDS:
print(f"ERROR: field '{field}' not allowed (whitelist: {sorted(ALLOWED_FIELDS)})")
return
d = db.get_db()
d.execute(f"UPDATE users SET {field}=? WHERE username=?", (value, username))
d.commit()