mirror of
https://github.com/blakeblackshear/frigate.git
synced 2025-12-09 06:45:40 +03:00
* jwt permissions * add old password to body req * add model and migration need to track the datetime that passwords were changed for the jwt * auth api backend changes - use os.open to create jwt secret with restrictive permissions (0o600: read/write for owner only) - add backend validation for password strength - add iat claim to jwt so the server can determine when a token was issued and reject any jwts issued before a user's password_changed_at timestamp, ensuring old tokens are invalidated after a password change - set logout route to public to avoid 401 when logging out - issue new jwt for users who change their own password so they stay logged in * improve set password dialog - add field to verify old password - add password strength requirements * frontend tweaks for password dialog * i18n * use verify endpoint for existing password verification avoid /login side effects (creating a new session) * public logout * only check if password has changed on jwt refresh * fix tests Fix migration 030 by using raw sql to select usernames (avoid ORM selecting nonexistent columns) * add multi device warning to password dialog * remove password verification endpoint Just send old_password + new password in one request, let the backend handle verification in a single operation
43 lines
1.4 KiB
Python
43 lines
1.4 KiB
Python
"""Peewee migrations -- 032_add_password_changed_at.py.
|
|
|
|
Some examples (model - class or model name)::
|
|
|
|
> Model = migrator.orm['model_name'] # Return model in current state by name
|
|
|
|
> migrator.sql(sql) # Run custom SQL
|
|
> migrator.python(func, *args, **kwargs) # Run python code
|
|
> migrator.create_model(Model) # Create a model (could be used as decorator)
|
|
> migrator.remove_model(model, cascade=True) # Remove a model
|
|
> migrator.add_fields(model, **fields) # Add fields to a model
|
|
> migrator.change_fields(model, **fields) # Change fields
|
|
> migrator.remove_fields(model, *field_names, cascade=True)
|
|
> migrator.rename_field(model, old_field_name, new_field_name)
|
|
> migrator.rename_table(model, new_table_name)
|
|
> migrator.add_index(model, *col_names, unique=False)
|
|
> migrator.drop_index(model, *col_names)
|
|
> migrator.add_not_null(model, *field_names)
|
|
> migrator.drop_not_null(model, *field_names)
|
|
> migrator.add_default(model, field_name, default)
|
|
|
|
"""
|
|
|
|
import peewee as pw
|
|
|
|
SQL = pw.SQL
|
|
|
|
|
|
def migrate(migrator, database, fake=False, **kwargs):
|
|
migrator.sql(
|
|
"""
|
|
ALTER TABLE user ADD COLUMN password_changed_at DATETIME NULL
|
|
"""
|
|
)
|
|
|
|
|
|
def rollback(migrator, database, fake=False, **kwargs):
|
|
migrator.sql(
|
|
"""
|
|
ALTER TABLE user DROP COLUMN password_changed_at
|
|
"""
|
|
)
|