Fix all 7 launch blockers from security/QA review
SEC-16: Add frontend ports mapping (80:80) to docker-compose.yml UI-01: Add routes for Welcome, SettingsIntegrations, MealPlan in App.jsx SEC-01: Remove traceback leak from auth error responses SEC-02: Fix require_admin to use is_admin column (was undefined ADMIN_USERNAME) SEC-03: Add API_TOKEN auth for MCP connector -> backend communication SEC-04: OAuth state now uses signed JWT tokens (was raw user UUID) OS-01: First registered user gets admin immediately during registration 10 files changed, 97 insertions(+), 25 deletions(-)
This commit is contained in:
parent
50eae17c34
commit
69320e1e82
10 changed files with 97 additions and 25 deletions
|
|
@ -24,7 +24,6 @@ from app.config import settings
|
|||
logger = logging.getLogger(__name__)
|
||||
router = APIRouter(prefix="/api/support", tags=["support"])
|
||||
|
||||
# Admin check uses is_admin column on User model (first registered user gets admin=True)
|
||||
MAX_MESSAGES_PER_DAY = 10
|
||||
|
||||
|
||||
|
|
@ -279,8 +278,8 @@ async def get_unread_count(
|
|||
# ── Admin Endpoints ────────────────────────────────────────────────────────
|
||||
|
||||
def require_admin(user: User):
|
||||
"""Check that the user is the admin."""
|
||||
if user.username != ADMIN_USERNAME:
|
||||
"""Check that the user has admin privileges."""
|
||||
if not getattr(user, "is_admin", False):
|
||||
raise HTTPException(status_code=403, detail="Admin access required")
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue