Addresses three Important-severity review findings inherited from Task 4's plan reference code: - login() now sets secure=True on the session cookie (safe behind the Cloudflare Tunnel, which terminates TLS at the edge). - logout() looks up and deletes the matching AuthSession row before clearing the cookie, so a leaked raw token can no longer be replayed after logout. - login() always performs exactly one verify_password call regardless of whether the username exists (against a module-level dummy hash for nonexistent users), removing the timing oracle that let unauthenticated requests distinguish registered from unregistered usernames. Adds two tests: nonexistent-username login rejection, and logout revoking the session server-side. Also adjusts two cookie-propagation touch points in test_auth.py to manually re-inject the qm_session cookie, since httpx's cookie jar won't auto-attach a Secure cookie to the test transport's plain http://test base_url (a real browser talking to the HTTPS tunnel edge wouldn't have this problem). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
2.9 KiB
2.9 KiB