网页身份改由 auth-hub 做 OAuth2 + PKCE 单点登录,本地邮箱/密码登录与注册整条链路删除 (routes/auth.py、auth.py 的密码哈希、config.py 的 ALLOW_REGISTRATION)。Garmin 账号绑定/ 同步保持完全独立、可选:routes/garmin.py 不再直接查 users 表,Garmin 邮箱回退统一走新增 的 services/garmin.py::get_remembered_email()(优先读 garmin_tokens 当前绑定,兼容早期账号 落在 users.garmin_email 的历史值),彻底把「你是谁」和「你绑没绑 Garmin」两件事拆开。 - db.py: users 表新增 auth_hub_sub/auth_hub_username,MIGRATIONS 补上这两列(此前遗漏导致 已存在的生产 MariaDB 表永远不会自动加列);同时把历史遗留的 garmin_email/ garmin_password_hash NOT NULL 约束在线迁移为可空,因为新账号不再在注册时收集这些字段。 - routes/auth.py: 修掉 /callback 路由重复拼接 /api/auth 前缀导致 404 的 bug。 - client: LoginPage 去掉本地登录/注册标签页,只保留 auth-hub 统一登录;登录成功/失败后都 用 history.replaceState 清理地址栏,修掉 Framework7 browserHistory 读取 /auth/callback?code=... 导致「找不到页面」的问题。 - 新增 test_auth_hub_client.py 锁定 find_or_create_user 按 auth_hub_sub 幂等——生产上曾经因为 这个函数在没有该测试保护时被测试触发,误建过一个空账号,靠手工核对 health_data 计数才发现。 - 生产 auth-hub 侧另行为该项目注册了正式 client(未随本次提交变更,凭证只存在服务器 .env)。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
47 lines
1.4 KiB
Python
47 lines
1.4 KiB
Python
"""
|
|
JWT signing/verification and the require_auth decorator used by route
|
|
blueprints. Accounts come from auth-hub (see services/auth_hub_client.py);
|
|
this module only handles this app's own session token.
|
|
"""
|
|
import datetime
|
|
|
|
import jwt
|
|
from flask import request, g, jsonify
|
|
from functools import wraps
|
|
|
|
from config import JWT_SECRET, JWT_EXPIRY_DAYS
|
|
|
|
|
|
def sign_token(user_id: str) -> str:
|
|
now = datetime.datetime.utcnow()
|
|
payload = {
|
|
"sub": user_id,
|
|
"iat": now,
|
|
"exp": now + datetime.timedelta(days=JWT_EXPIRY_DAYS),
|
|
}
|
|
return jwt.encode(payload, JWT_SECRET, algorithm="HS256")
|
|
|
|
|
|
def verify_token(token: str) -> dict:
|
|
payload = jwt.decode(token, JWT_SECRET, algorithms=["HS256"])
|
|
return {"user_id": payload["sub"]}
|
|
|
|
|
|
def require_auth(f):
|
|
@wraps(f)
|
|
def wrapper(*args, **kwargs):
|
|
auth = request.headers.get("Authorization", "")
|
|
if not auth.startswith("Bearer "):
|
|
return jsonify({"error": "missing or malformed Authorization header"}), 401
|
|
token = auth[7:].strip()
|
|
try:
|
|
data = verify_token(token)
|
|
except jwt.ExpiredSignatureError:
|
|
return jsonify({"error": "token expired"}), 401
|
|
except jwt.InvalidTokenError:
|
|
return jsonify({"error": "invalid token"}), 401
|
|
g.user_id = data["user_id"]
|
|
return f(*args, **kwargs)
|
|
|
|
return wrapper
|