Commit Graph

4 Commits

Author SHA1 Message Date
Indiana
ed5313158d fix: address final-review hygiene items (pydantic config, cookie alias, argon2 exception scope)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 16:00:35 +00:00
Indiana
3758594896 fix: harden login/logout — secure cookie, server-side session revocation, timing-safe login
Addresses three Important-severity review findings inherited from Task 4's
plan reference code:

- login() now sets secure=True on the session cookie (safe behind the
  Cloudflare Tunnel, which terminates TLS at the edge).
- logout() looks up and deletes the matching AuthSession row before
  clearing the cookie, so a leaked raw token can no longer be replayed
  after logout.
- login() always performs exactly one verify_password call regardless of
  whether the username exists (against a module-level dummy hash for
  nonexistent users), removing the timing oracle that let unauthenticated
  requests distinguish registered from unregistered usernames.

Adds two tests: nonexistent-username login rejection, and logout revoking
the session server-side. Also adjusts two cookie-propagation touch points
in test_auth.py to manually re-inject the qm_session cookie, since
httpx's cookie jar won't auto-attach a Secure cookie to the test
transport's plain http://test base_url (a real browser talking to the
HTTPS tunnel edge wouldn't have this problem).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2026-07-20 15:34:12 +00:00
Indiana
a0723b5237 feat: add login, session cookies, and get_current_user 2026-07-20 15:26:58 +00:00
Indiana
cfffc7ff59 feat: add user model and registration endpoint 2026-07-20 15:14:31 +00:00